hardenize / hardenize-public

11 stars 0 forks source link

DNSSEC check error #44

Closed Tributh closed 6 years ago

Tributh commented 6 years ago

Hi, actually the DNSSEC check shows errors, while all other reference sites are not showing it. Sample: https://www.hardenize.com/report/samel.de/1539953926#domain_dnssec

Maybe you have not changed to the new DNSSEC-root key ?

Cheers Torsten

ivanr commented 6 years ago

After refreshing the report, the DNSSEC section is now green. Unfortunately, our test is currently very limited. We only try to resolve hosts with and without DNSSEC. So when you see red, that means that resolution with DNSSEC failed. Because we don't do any diagnostics, we don't at this point know why it failed. It wasn't about the new key, and we also didn't have problems with other sites.

There is good news, however. We've recently began working on new DNS tests, and those will include DNSSEC diagnostics!