Domain: sitemap.xml
| Category | Status | Test name | Information | Standards / RFC |
|---|---|---|---|---|
| Parent | Warning | Domain NS records |
Could not retrieve NS delegation details for this zone.
|
Standard: Delegation model
|
| Warning | TLD Parent Check |
Could not find parent nameservers for xml.
|
Standard: Delegation availability
|
|
| Fail | Your nameservers are listed |
No delegated nameservers were returned by the parent lookup.
|
Standard: MUST (delegation data required for discoverability)
|
|
| Info | DNS Parent sent Glue |
Skipped because delegation records were not available.
|
Standard: Glue behavior
|
|
| Warning | Nameservers A records |
No nameservers were found, so A/AAAA checks could not run.
|
Standard: SHOULD (NS targets need reachable address records)
|
|
| NS | Warning | NS records from your nameservers |
Could not retrieve NS records from your nameservers.
|
Standard: Authoritative data visibility
|
| Pass | Recursive Queries |
OK. Nameservers do not appear to allow recursive queries for everyone.
|
Standard: Best current practice (avoid open recursion)
|
|
| Pass | Same Glue |
The GLUE records from parent and child NS checks are consistent.
|
Standard: Consistency check
|
|
| Pass | Glue for NS records |
Child nameservers returned GLUE for NS records.
|
Standard: Glue behavior
|
|
| Pass | Mismatched NS records |
OK. NS records are identical across responding nameservers.
|
Standard: SHOULD (authoritative servers should serve consistent zone data)
|
|
| Warning | DNS servers responded |
Could not query nameservers because no NS IPs were available.
|
Standard: Availability best practice
|
|
| Pass | Name of nameservers are valid |
OK. NS hostnames look valid.
|
Standard: MUST (hostname syntax)
|
|
| Warning | Multiple Nameservers |
Only one nameserver was detected. Multiple nameservers are recommended.
|
Standard: SHOULD (multiple authoritative servers)
|
|
| Pass | Nameservers are lame |
OK. Nameservers answered authoritatively for your domain.
|
Standard: SHOULD (authoritative NS should answer authoritatively)
|
|
| Pass | Missing nameservers reported by parent |
OK. Child nameservers include all parent-listed NS records.
|
Standard: SHOULD (parent/child NS set consistency)
|
|
| Pass | Missing nameservers reported by your nameservers |
OK. Parent and child nameservers report the same NS set.
|
Standard: SHOULD (parent/child NS set consistency)
|
|
| Pass | Domain CNAMEs |
OK. No CNAME found at the zone apex.
|
Standard: MUST NOT (CNAME and other data at same owner name)
|
|
| Pass | NSs CNAME check |
OK. Nameserver hostnames are not CNAME records.
|
Standard: MUST NOT (NS target must not be an alias)
|
|
| Info | Different subnets |
Not enough IPv4 NS addresses were found to compare subnets.
|
Standard: SHOULD (topological diversity)
|
|
| Pass | IPs of nameservers are public |
OK. Nameserver IP addresses appear to be public.
|
Standard: Operational best practice
|
|
| Pass | DNS servers allow TCP connection |
OK. All tested nameservers accepted TCP DNS queries.
|
Standard: MUST/SHOULD support DNS over TCP
|
|
| Info | Different autonomous systems |
ASN data could not be determined for nameserver IPs.
|
Standard: Operational resiliency best practice (network/topology diversity)
|
|
| Pass | Stealth NS records sent |
OK. No stealth NS records were detected.
|
Standard: SHOULD (consistent delegation set)
|
|
| SOA | Fail | SOA record |
Could not retrieve an SOA record.
|
Standard: MUST (zone apex SOA record)
|
| Info | NSs have same SOA serial |
Could not compare SOA serials across nameservers.
|
Standard: SHOULD (zone consistency across authoritative servers)
|
|
| Info | SOA MNAME entry |
Skipped because SOA could not be read.
|
Standard: SOA semantics
|
|
| Info | SOA Serial |
Skipped because SOA could not be read.
|
Standard: Serial arithmetic semantics (format is operational convention)
|
|
| Info | SOA REFRESH |
Skipped because SOA is unavailable.
|
Standard: SOA timer semantics
|
|
| Info | SOA RETRY |
Skipped because SOA is unavailable.
|
Standard: SOA timer semantics
|
|
| Info | SOA EXPIRE |
Skipped because SOA is unavailable.
|
Standard: SOA timer semantics
|
|
| Info | SOA MINIMUM TTL |
Skipped because SOA is unavailable.
|
Standard: Negative caching semantics
|
|
| MX | Info | MX Records |
No MX records were found.
|
Standard: Mail routing records
|
| Info | Different MX records at nameservers |
Could not compare MX sets across nameservers.
|
Standard: SHOULD (authoritative consistency)
|
|
| Pass | MX name validity |
OK. No invalid MX hostnames were detected.
|
Standard: MUST (MX exchange must be a domain name with valid syntax)
|
|
| Info | MX IPs are public |
Skipped because no MX hosts were found.
|
Standard: Operational best practice
|
|
| Pass | MX CNAME Check |
OK. No problems detected.
|
Standard: MUST NOT (MX exchange must not be an alias)
|
|
| Pass | MX A request returns CNAME |
OK. No CNAME returned for MX A lookups.
|
Standard: MUST NOT (MX exchange must not resolve through CNAME)
|
|
| Pass | MX is not IP |
OK. All MX records are hostnames.
|
Standard: MUST (MX must reference a domain name, not literal address)
|
|
| Info | Number of MX records |
No MX records were found for this zone.
|
Standard: Operational resiliency best practice (multiple MX targets recommended)
|
|
| Pass | Mismatched MX A |
OK. No differing MX A/AAAA results were detected.
|
Standard: Operational consistency check
|
|
| Pass | Duplicate MX A records |
OK. No duplicate MX target IPs were found.
|
Standard: Operational diversity best practice
|
|
| Info | Reverse MX A records (PTR) |
Could not verify PTR records for MX IPs.
|
Standard: Mail operations best practice
|
|
| WWW | Info | WWW A Record |
No A/AAAA records detected for www.sitemap.xml.
|
Standard: Operational endpoint check
|
| Info | IPs are public |
Skipped because WWW A/AAAA records were not found.
|
Standard: Operational best practice
|
|
| Pass | WWW CNAME |
OK. No CNAME.
|
Standard: Operational endpoint check
|