DNS report
boucherierossignol.ca
Complete DNS, mail, web and security analysis.
DNS cache tools
If you have recently made DNS changes and they are not yet reflected in the report, you can try to flush the DNS cache of these public resolvers: The domain name will be copied to your clipboard automatically when clicking on a button
| Category | Status | Test | Details | ||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
WHOIS0.1 ms |
Domain Status |
Source: WHOIS (port 43) whois.ca.fury.ca
Registrar lock enabled The domain exposes a transfer lock status, such as clientTransferProhibited or serverTransferProhibited. |
|||||||||||||||||||||||||||||||||||||
|
PARENT0.0 ms |
Domain NS records |
Nameserver records returned by the parent servers are:
ns2-cpam4.likuid.com [142.44.247.131] (NO GLUE) [TTL=86400] ns1-cpam4.likuid.com [67.215.9.186] (NO GLUE) [TTL=86400] any.ca-servers.ca was kind enough to give us that information. |
|||||||||||||||||||||||||||||||||||||
| TLD Parent Check |
any.ca-servers.ca has information for your TLD.
This is a good thing as there are some other domain extensions like "co.us" for example that are missing a direct check. |
||||||||||||||||||||||||||||||||||||||
| Your nameservers are listed |
Mismatch between parent and domain NS.
|
||||||||||||||||||||||||||||||||||||||
| DNS Parent sent Glue |
0 of 2 nameservers sent GLUE.
The parent nameserver a.gtld-servers.net is not sending out GLUE for every nameserver listed, meaning it is sending your nameserver hostnames without their corresponding A records. This is acceptable, but it requires an extra A record lookup, which may slightly delay DNS resolution. This often occurs when nameservers are on a different TLD (e.g., domain.com with nameserver ns.otherdomain.com). |
||||||||||||||||||||||||||||||||||||||
| Nameservers A records |
Every nameserver listed has A records.
This is a must if you want to be found. |
||||||||||||||||||||||||||||||||||||||
|
NS3327.0 ms |
NS records from your NameServers |
NS records returned by the currently delegated nameservers are:
All NS records have the same TTL: 300 seconds. |
|||||||||||||||||||||||||||||||||||||
| Public Resolver |
|
||||||||||||||||||||||||||||||||||||||
| Mismatched NS records |
Mismatch detected between parent and zone NS records.
Parent NS: ns1-cpam4.likuid.com ns2-cpam4.likuid.com Zone NS: ns1am.service-dns.net ns2am.service-dns.net ns3am.service-dns.net |
||||||||||||||||||||||||||||||||||||||
| DNS servers responded |
All nameservers listed at the parent server responded.
|
||||||||||||||||||||||||||||||||||||||
| Name of nameservers are valid |
All of the NS records that your nameservers report seem valid.
|
||||||||||||||||||||||||||||||||||||||
| Multiple Nameservers |
You have 3 nameservers. According to RFC2182 section 5, this is recommended.
|
||||||||||||||||||||||||||||||||||||||
| Missing nameservers reported by parent |
FAIL: The following nameservers are listed at your nameservers as nameservers for your domain, but are not listed at the parent nameservers (see RFC2181 5.4.1).
The missing NS records at the parent are: ns3am.service-dns.net ns1am.service-dns.net ns2am.service-dns.net You need to make sure that these nameservers are working. If they are not working correctly, you may experience problems. |
||||||||||||||||||||||||||||||||||||||
| Missing nameservers reported by your nameservers |
ERROR: One or more of the nameservers listed at the parent servers are not listed as NS records at your nameservers.
The problem NS records are: ns2-cpam4.likuid.com ns1-cpam4.likuid.com This is listed as an ERROR because there are some cases where nasty problems can occur (if the TTLs vary from the NS records at the root servers and the NS records point to your own domain, for example). |
||||||||||||||||||||||||||||||||||||||
| Domain CNAMEs |
OK. RFC1912 2.4 and RFC2181 10.3 state that there should be no CNAMEs if an NS (or any other) record is present.
|
||||||||||||||||||||||||||||||||||||||
| NSs CNAME check |
OK. RFC1912 2.4 and RFC2181 10.3 state that there should be no CNAMEs if an NS (or any other) record is present.
|
||||||||||||||||||||||||||||||||||||||
| Different subnets |
You have nameservers on different subnets.
|
||||||||||||||||||||||||||||||||||||||
| Recursive Queries |
ns3am.service-dns.net → ✅ does not allow recursion (good)
ns1am.service-dns.net → ✅ does not allow recursion (good) ns2am.service-dns.net → ✅ does not allow recursion (good) |
||||||||||||||||||||||||||||||||||||||
| Same Glue |
Mismatch between parent GLUE and zone A records:
ns2-cpam4.likuid.com → Parent: 142.44.247.131 | Zone: ns1-cpam4.likuid.com → Parent: 67.215.9.186 | Zone: Make sure both match to comply with DNS best practices. |
||||||||||||||||||||||||||||||||||||||
| NS Self-IP Consistency |
All nameservers return consistent IP addresses with what they declare in the zone.
|
||||||||||||||||||||||||||||||||||||||
| Glue for NS records |
GLUE was not sent when I asked your nameservers for your NS records.
This is ok but you should know that in this case an extra A record lookup is required. The nameservers without glue are: 151.80.78.25 67.215.9.186 142.44.247.131 You can fix this by adding A records to your nameservers. |
||||||||||||||||||||||||||||||||||||||
| Nameservers are lame |
All the nameservers listed at the parent servers answer authoritatively for your domain.
|
||||||||||||||||||||||||||||||||||||||
| IPs of nameservers are public |
Ok. Looks like the IP addresses of your nameservers are public.
This is a good thing because it will prevent DNS delays and other problems. |
||||||||||||||||||||||||||||||||||||||
| DNS servers allow TCP connection |
OK. Seems all your DNS servers allow TCP connections.
This is a good thing and useful even if UDP connections are used by default. |
||||||||||||||||||||||||||||||||||||||
| Different autonomous systems |
Authoritative name servers are spread across multiple autonomous systems:
ns3am.service-dns.net → AS16276 ns1am.service-dns.net → AS36666 ns2am.service-dns.net → AS16276 |
||||||||||||||||||||||||||||||||||||||
| Stealth NS records sent |
The following name servers are configured in your zone but not reported by the parent (stealth NS):
ns3am.service-dns.net ns1am.service-dns.net ns2am.service-dns.net Stealth name servers can cause inconsistent DNS answers and complicate troubleshooting. Make sure all authoritative NS are correctly published at the registry/parent level. |
||||||||||||||||||||||||||||||||||||||
|
DNSSEC163.2 ms |
Zone signed |
DNSSEC: Unsigned
No RRSIG record found. The zone is not signed with DNSSEC. |
|||||||||||||||||||||||||||||||||||||
| DNSKEY records |
No DNSKEY records found.
|
||||||||||||||||||||||||||||||||||||||
| DS record in parent |
No DS record found in the parent zone.
|
||||||||||||||||||||||||||||||||||||||
| NSEC/NSEC3 record |
No NSEC or NSEC3 record found when querying a non-existent subdomain.
This may indicate a misconfiguration or lack of proper DNSSEC denial-of-existence support. |
||||||||||||||||||||||||||||||||||||||
|
SOA0.1 ms |
SOA Record |
The SOA (Start of Authority) record is:
Primary nameserver: ns1am.service-dns.net Hostmaster E-mail address: alertes@likuid@com Serial #: 2026091112 Refresh: 3600 Retry: 1800 Expire: 1209600 Default TTL: 86400 |
|||||||||||||||||||||||||||||||||||||
| NSs have same SOA serial |
OK. All your nameservers agree that your SOA serial number is 2026091112.
|
||||||||||||||||||||||||||||||||||||||
| SOA MNAME entry |
ns1am.service-dns.net is NOT listed at the parent level. This could cause issues with zone transfer or delegation.
|
||||||||||||||||||||||||||||||||||||||
| SOA Serial |
Your SOA serial number is: 2026091112. This appears to follow the recommended YYYYMMDDnn format.
|
||||||||||||||||||||||||||||||||||||||
| SOA REFRESH |
Your SOA REFRESH interval is: 3600. OK.
|
||||||||||||||||||||||||||||||||||||||
| SOA RETRY |
Your SOA RETRY value is: 1800. OK.
|
||||||||||||||||||||||||||||||||||||||
| SOA EXPIRE |
Your SOA EXPIRE number is: 1209600. Looks OK.
|
||||||||||||||||||||||||||||||||||||||
| SOA MINIMUM TTL |
Your SOA MINIMUM TTL is: 86400. This is fine
|
||||||||||||||||||||||||||||||||||||||
|
MX ... |
MX Records |
|
|||||||||||||||||||||||||||||||||||||
|
TXT0.1 ms |
TXT Records |
|
|||||||||||||||||||||||||||||||||||||
|
SPF ... |
SPF Analysis |
|
|||||||||||||||||||||||||||||||||||||
|
DMARC32.0 ms |
DMARC Configuration |
DMARC Record was found:
v=DMARC1; p=quarantine; sp=none; rf=afrf; pct=100; ri=86400 Policy summary:
v=DMARC1; p=quarantine; sp=none; rua=none; ruf=none; fo=0; pct=100; adkim=r; aspf=r; ri=86400; rf=afrf; DMARC Evaluation Score: 0.5/3 To improve your score:
|
|||||||||||||||||||||||||||||||||||||
|
MTA-STS / TLS-RPT91.6 ms |
Mail TLS security |
MTA-STS score 0/5 Recommendations:
|
|||||||||||||||||||||||||||||||||||||
|
DKIM ... |
DKIM Records Detected |
|
|||||||||||||||||||||||||||||||||||||
|
BIMI33.3 ms |
BIMI Record |
No BIMI record found at: default._bimi.boucherierossignol.ca.
|
|||||||||||||||||||||||||||||||||||||
|
SSL ... |
SSL Certificate Summary |
|
|||||||||||||||||||||||||||||||||||||
|
CAA ... |
CAA Records |
|
|||||||||||||||||||||||||||||||||||||
|
HSTS ... |
HSTS |
|
|||||||||||||||||||||||||||||||||||||
|
HTTPS ... |
HTTPS |
|
|||||||||||||||||||||||||||||||||||||
|
HTTPS (DNS) ... |
HTTPS DNS record |
|
|||||||||||||||||||||||||||||||||||||
|
WWW ... |
A Record |
|
|||||||||||||||||||||||||||||||||||||
|
AXFR (Zone Transfer)281.1 ms |
AXFR status for the zone |
AXFR is refused by the authoritative nameservers for boucherierossignol.ca.
Nameservers tested: ns3am.service-dns.net, ns1am.service-dns.net, ns2am.service-dns.net |
|||||||||||||||||||||||||||||||||||||
| Security note |
Zone transfers (AXFR) should be disabled in production unless explicitly required and restricted.
Leaving AXFR open allows anyone to enumerate your entire DNS zone (subdomains, MX, TXT, internal hosts, etc.). |
||||||||||||||||||||||||||||||||||||||
|
PORTS ... |
Open ports detected (72.10.173.203) |
|
|||||||||||||||||||||||||||||||||||||
|
REPUTATION ... |
IP in blacklists (72.10.173.203) |
|
|||||||||||||||||||||||||||||||||||||
|
DNS found ... |
|
||||||||||||||||||||||||||||||||||||||
| Test | Details | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
Website Preview0.0 ms
|
Snapshot is generated through DNSprobe's rendering proxy and may be served from a short cache.
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Security Headers1704.1 ms
|
Score: 14/100 (F) Failing, very weak or absent security headers
Other detected headers Additional headers returned by the server. Shown for information only and not included in the score.
Recommended starter configuration (.htaccess) Starter configuration to copy and adapt. CSP, CORS and cookie rewriting are intentionally commented because they can break some sites if enabled blindly. |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
WHOIS105.3 ms
|
Source: WHOIS (port 43) whois.ca.fury.ca
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
RDAP 104.3 ms
|
Source: RDAP rdap.org → rdap.ca.fury.ca
Registrar
RDAP JSON (raw){
"entities": [
{
"entities": [
{
"handle": "not applicable",
"objectClassName": "entity",
"roles": [
"abuse"
],
"vcardArray": [
"vcard",
[
[
"version",
[],
"text",
"4.0"
],
[
"fn",
[],
"text",
"Abuse Contact"
],
[
"kind",
[],
"text",
"individual"
],
[
"role",
[],
"text",
"abuse"
],
[
"adr",
[],
"text",
[
"",
"",
"",
"",
"",
"",
""
]
],
[
"tel",
{
"type": [
"voice"
]
},
"uri",
"tel:+49.68949396;ext=850"
],
[
"email",
[],
"text",
"[email protected]"
],
[
"url",
{
"type": "home"
},
"uri",
"www.hexonet.net"
]
]
]
}
],
"handle": "not applicable",
"objectClassName": "entity",
"roles": [
"registrar"
],
"vcardArray": [
"vcard",
[
[
"version",
[],
"text",
"4.0"
],
[
"fn",
[],
"text",
"CENTRALNIC CANADA INC"
],
[
"kind",
[],
"text",
"org"
],
[
"role",
[],
"text",
"registrar"
],
[
"adr",
[],
"text",
[
"",
"",
"",
"",
"",
"",
""
]
],
[
"url",
{
"type": "home"
},
"uri",
"www.hexonet.net"
]
]
]
},
{
"objectClassName": "entity",
"roles": [
"registrant"
],
"vcardArray": [
"vcard",
[
[
"version",
[],
"text",
"4.0"
],
[
"fn",
[],
"text",
""
],
[
"kind",
[],
"text",
"individual"
],
[
"role",
[],
"text",
"registrant"
],
[
"adr",
[],
"text",
[
"",
"",
"",
"",
"",
"",
""
]
]
]
]
},
{
"objectClassName": "entity",
"roles": [
"technical"
],
"vcardArray": [
"vcard",
[
[
"version",
[],
"text",
"4.0"
],
[
"fn",
[],
"text",
""
],
[
"kind",
[],
"text",
"individual"
],
[
"role",
[],
"text",
"technical"
],
[
"adr",
[],
"text",
[
"",
"",
"",
"",
"",
"",
""
]
]
]
]
}
],
"events": [
{
"eventAction": "registration",
"eventDate": "2016-04-13T01:39:02Z"
},
{
"eventAction": "expiration",
"eventDate": "2027-04-13T01:39:02Z"
},
{
"eventAction": "last changed",
"eventDate": "2026-05-28T01:45:20Z"
},
{
"eventAction": "last update of RDAP database",
"eventDate": "2026-09-19T19:23:15Z"
}
],
"handle": "28089538-CIRA",
"ldhName": "boucherierossignol.ca",
"links": [
{
"href": "https://rdap.ca.fury.ca/rdap/domain/boucherierossignol.ca",
"rel": "self",
"title": "Authoritative URL for this resource",
"type": "application/rdap+json",
"value": "https://rdap.ca.fury.ca/rdap/domain/boucherierossignol.ca"
}
],
"nameservers": [
{
"ldhName": "ns1-cpam4.likuid.com",
"objectClassName": "nameserver"
},
{
"ldhName": "ns2-cpam4.likuid.com",
"objectClassName": "nameserver"
}
],
"notices": [
{
"description": [
"For more information on domain status codes, please visit https://icann.org/epp"
],
"links": [
{
"href": "https://icann.org/epp",
"rel": "glossary",
"type": "text/html",
"value": "https://rdap.ca.fury.ca/rdap/domain/boucherierossignol.ca"
}
],
"title": "Status Codes"
},
{
"description": [
"Service subject to Terms of Use."
],
"links": [
{
"href": "https://www.cira.ca/en/resources/documents/about/website-terms-use",
"rel": "terms-of-service",
"type": "text/html",
"value": "https://rdap.ca.fury.ca/rdap/domain/boucherierossignol.ca"
}
],
"title": "Terms of Service"
},
{
"description": [
"URL of the ICANN RDDS Inaccuracy Complaint Form: https://icann.org/wicf"
],
"links": [
{
"href": "https://icann.org/wicf",
"rel": "help",
"type": "text/html",
"value": "https://rdap.ca.fury.ca/rdap/domain/boucherierossignol.ca"
}
],
"title": "RDDS Inaccuracy Complaint Form"
},
{
"description": [
"\nUse of CIRA's WHOIS service is governed by the Terms of Use in its Legal\nNotice, available at https://www.cira.ca/en/resources/documents/about/website-terms-use\n\n(c) 2026 Canadian Internet Registration Authority, (http://www.cira.ca/)"
],
"links": [
{
"href": "https://www.cira.ca/en/resources/documents/about/website-terms-use",
"rel": "help",
"type": "text/html",
"value": "https://rdap.ca.fury.ca/rdap/domain/boucherierossignol.ca"
}
],
"title": "Legal Notice"
}
],
"objectClassName": "domain",
"port43": "whois.ca.fury.ca",
"rdapConformance": [
"icann_rdap_response_profile_1",
"icann_rdap_technical_implementation_guide_1",
"rdap_level_0",
"redacted"
],
"redacted": [
{
"name": {
"description": "Administrative Contact"
},
"method": "removal"
},
{
"name": {
"description": "Billing Contact"
},
"method": "removal"
},
{
"name": {
"type": "Registry Registrant ID"
},
"method": "removal"
},
{
"name": {
"type": "Registrant Name"
},
"method": "emptyValue",
"postPath": "$.entities[?(@.roles[0]=='registrant')].vcardArray[1][?(@[0]=='fn')][3]"
},
{
"name": {
"type": "Registrant Organization"
},
"method": "removal"
},
{
"name": {
"type": "Registrant Street"
},
"method": "emptyValue",
"postPath": "$.entities[?(@.roles[0]=='registrant')].vcardArray[1][?(@[0]=='adr')][3][2]"
},
{
"name": {
"type": "Registrant City"
},
"method": "emptyValue",
"postPath": "$.entities[?(@.roles[0]=='registrant')].vcardArray[1][?(@[0]=='adr')][3][3]"
},
{
"name": {
"description": "Registrant Region"
},
"method": "emptyValue",
"postPath": "$.entities[?(@.roles[0]=='registrant')].vcardArray[1][?(@[0]=='adr')][3][4]"
},
{
"name": {
"type": "Registrant Postal Code"
},
"method": "emptyValue",
"postPath": "$.entities[?(@.roles[0]=='registrant')].vcardArray[1][?(@[0]=='adr')][3][5]"
},
{
"name": {
"description": "Registrant Country"
},
"method": "removal"
},
{
"name": {
"type": "Registrant Phone"
},
"method": "removal"
},
{
"name": {
"type": "Registrant Phone Ext"
},
"method": "removal"
},
{
"name": {
"type": "Registrant Fax"
},
"method": "removal"
},
{
"name": {
"type": "Registrant Fax Ext"
},
"method": "removal"
},
{
"name": {
"type": "Registrant Email"
},
"method": "removal"
},
{
"name": {
"description": "Registrant Url"
},
"method": "removal"
},
{
"name": {
"type": "Registry Tech ID"
},
"method": "removal"
},
{
"name": {
"type": "Tech Name"
},
"method": "emptyValue",
"postPath": "$.entities[?(@.roles[0]=='technical')].vcardArray[1][?(@[0]=='fn')][3]"
},
{
"name": {
"description": "Tech Organization"
},
"method": "removal"
},
{
"name": {
"description": "Tech Street"
},
"method": "emptyValue",
"postPath": "$.entities[?(@.roles[0]=='technical')].vcardArray[1][?(@[0]=='adr')][3][2]"
},
{
"name": {
"description": "Tech City"
},
"method": "emptyValue",
"postPath": "$.entities[?(@.roles[0]=='technical')].vcardArray[1][?(@[0]=='adr')][3][3]"
},
{
"name": {
"description": "Tech Region"
},
"method": "emptyValue",
"postPath": "$.entities[?(@.roles[0]=='technical')].vcardArray[1][?(@[0]=='adr')][3][4]"
},
{
"name": {
"description": "Tech Postal Code"
},
"method": "emptyValue",
"postPath": "$.entities[?(@.roles[0]=='technical')].vcardArray[1][?(@[0]=='adr')][3][5]"
},
{
"name": {
"description": "Tech Country"
},
"method": "removal"
},
{
"name": {
"type": "Tech Phone"
},
"method": "removal"
},
{
"name": {
"type": "Tech Phone Ext"
},
"method": "removal"
},
{
"name": {
"description": "Tech Fax"
},
"method": "removal"
},
{
"name": {
"description": "Tech Fax Ext"
},
"method": "removal"
},
{
"name": {
"type": "Tech Email"
},
"method": "removal"
},
{
"name": {
"description": "Tech Url"
},
"method": "removal"
},
{
"name": {
"description": "Reseller Street"
},
"method": "emptyValue",
"postPath": "$.entities[?(@.roles[0]=='reseller')].vcardArray[1][?(@[0]=='adr')][3][2]"
},
{
"name": {
"description": "Reseller City"
},
"method": "emptyValue",
"postPath": "$.entities[?(@.roles[0]=='reseller')].vcardArray[1][?(@[0]=='adr')][3][3]"
},
{
"name": {
"description": "Reseller Region"
},
"method": "emptyValue",
"postPath": "$.entities[?(@.roles[0]=='reseller')].vcardArray[1][?(@[0]=='adr')][3][4]"
},
{
"name": {
"description": "Reseller Postal Code"
},
"method": "emptyValue",
"postPath": "$.entities[?(@.roles[0]=='reseller')].vcardArray[1][?(@[0]=='adr')][3][5]"
},
{
"name": {
"description": "Reseller Country"
},
"method": "removal"
},
{
"name": {
"description": "Reseller Phone"
},
"method": "removal"
},
{
"name": {
"description": "Reseller Phone Ext"
},
"method": "removal"
},
{
"name": {
"description": "Reseller Fax"
},
"method": "removal"
},
{
"name": {
"description": "Reseller Fax Ext"
},
"method": "removal"
},
{
"name": {
"description": "Reseller Email"
},
"method": "removal"
},
{
"name": {
"description": "Reseller Url"
},
"method": "removal"
}
],
"secureDNS": {
"delegationSigned": false
},
"status": [
"client transfer prohibited"
],
"unicodeName": "boucherierossignol.ca",
"variants": []
} |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Processed in 0.014 seconds.
Made with with PHP and a bit of JS.
Made with with PHP and a bit of JS.
Lines of code: 20,351