DNS report
groupelip.com
Complete DNS, mail, web and security analysis.
DNS cache tools
If you have recently made DNS changes and they are not yet reflected in the report, you can try to flush the DNS cache of these public resolvers: The domain name will be copied to your clipboard automatically when clicking on a button
| Category | Status | Test | Details | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
WHOIS0.1 ms |
Domain Status |
Source: WHOIS (port 43) whois.ovh.com
Registrar lock enabled The domain exposes a transfer lock status, such as clientTransferProhibited or serverTransferProhibited. |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
PARENT0.0 ms |
Domain NS records |
Nameserver records returned by the parent servers are:
dns108.ovh.net [5.196.41.157, 2001:41d0:d01:200::2] (NO GLUE) [TTL=172800] ns108.ovh.net [5.135.66.229, 2001:41d0:b00:fc00::2] (NO GLUE) [TTL=172800] h.gtld-servers.net was kind enough to give us that information. |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| TLD Parent Check |
h.gtld-servers.net has information for your TLD.
This is a good thing as there are some other domain extensions like "co.us" for example that are missing a direct check. |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Your nameservers are listed |
h.gtld-servers.net has your nameservers listed.
This is a must if you want to be found as anyone that does not know your DNS servers will first ask the parent nameservers. |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| DNS Parent sent Glue |
0 of 2 nameservers sent GLUE.
The parent nameserver a.gtld-servers.net is not sending out GLUE for every nameserver listed, meaning it is sending your nameserver hostnames without their corresponding A records. This is acceptable, but it requires an extra A record lookup, which may slightly delay DNS resolution. This often occurs when nameservers are on a different TLD (e.g., domain.com with nameserver ns.otherdomain.com). |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Nameservers A records |
Every nameserver listed has A records.
This is a must if you want to be found. |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
NS3018.1 ms |
NS records from your NameServers |
NS records returned by the currently delegated nameservers are:
All NS records have the same TTL: 3600 seconds. |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Public Resolver |
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Mismatched NS records |
The NS records at all your nameservers are identical to those listed by the parent.
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| DNS servers responded |
All nameservers listed at the parent server responded.
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Name of nameservers are valid |
All of the NS records that your nameservers report seem valid.
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Multiple Nameservers |
You have 2 nameservers. This is acceptable, but having 3 or more is recommended according to RFC2182 section 5.
Having 2 nameservers is ok by me. |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Missing nameservers reported by parent |
All NS records are the same at the parent and at your nameservers.
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Missing nameservers reported by your nameservers |
All nameservers returned by the parent server are the same as the ones reported by your nameservers.
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Domain CNAMEs |
OK. RFC1912 2.4 and RFC2181 10.3 state that there should be no CNAMEs if an NS (or any other) record is present.
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| NSs CNAME check |
OK. RFC1912 2.4 and RFC2181 10.3 state that there should be no CNAMEs if an NS (or any other) record is present.
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Different subnets |
You have nameservers on different subnets.
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Recursive Queries |
ns108.ovh.net → ✅ does not allow recursion (good)
dns108.ovh.net → ✅ does not allow recursion (good) |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Same Glue |
Mismatch between parent GLUE and zone A records:
dns108.ovh.net → Parent: 5.196.41.157, 2001:41d0:d01:200::2 | Zone: 5.196.41.157 ns108.ovh.net → Parent: 5.135.66.229, 2001:41d0:b00:fc00::2 | Zone: 5.135.66.229 Make sure both match to comply with DNS best practices. |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| NS Self-IP Consistency |
All nameservers return consistent IP addresses with what they declare in the zone.
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Glue for NS records |
GLUE was not sent when I asked your nameservers for your NS records.
This is ok but you should know that in this case an extra A record lookup is required. The nameservers without glue are: 5.135.66.229 5.196.41.157 You can fix this by adding A records to your nameservers. |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Nameservers are lame |
All the nameservers listed at the parent servers answer authoritatively for your domain.
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| IPs of nameservers are public |
Ok. Looks like the IP addresses of your nameservers are public.
This is a good thing because it will prevent DNS delays and other problems. |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| DNS servers allow TCP connection |
OK. Seems all your DNS servers allow TCP connections.
This is a good thing and useful even if UDP connections are used by default. |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Different autonomous systems |
All authoritative name servers appear to be in the same autonomous system: AS16276.
Using a single AS reduces resiliency and increases the blast radius of network incidents. Consider hosting your NS records across multiple autonomous systems. WARNING: Single point of failure. |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Stealth NS records sent |
Ok. No stealth NS records are sent
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
DNSSEC709.9 ms |
Zone signed |
DNSSEC: signedDelegation
RRSIG record present. The zone appears to be DNSSEC-signed. |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| DNSKEY records |
groupelip.com. 3600 IN DNSKEY 257 3 8 AwEAAaZxNHXJPhIZKEWQ1y7mEbyD1vZQ24YN5pppz8lCohQ1GzLdou8K B1jnZCP5Oyu7z5/ho4DvY4FQeyIZlVpT3fx8SdaFJLjum2t0tbRnaJ6M 8INGJf26SoUoXrdfV+wRyfESbnxCidPm3pFrYf5BJuxGU37EUNOLe6Ds Nf2snKoDyM1OdoH4NE+rO7W6Tvb12mTySahFBSsx8dum3VMkSTDxJExN 8ZrICPqm2nfDYWsiefqeyKJm90TE8m/W+d5oOWsCbAhwSWE59osp+ELK LG6Ol1VoWSIlT/I57GeC8ra2V8kSBrJkxqSN6dh7IFrA8NkzCZE9ABsn pfDoOntRLz0=
groupelip.com. 3600 IN DNSKEY 256 3 8 AwEAAbZolR0Zy/IEI3zS50UtShUDYykqYALTDEL/4OXrJvY/UFvBZWq6 VQT3pts269YPJw2ms0Mu2hxj3WsQtjyUpaSrDAkUaIsLELKbP7ONspIj HeyowlrLXNtHylazN0kJLv1tgt6/KhbrqCReilUbBp0oQWzkS3W5OCta 7Dams+hV |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| DS record in parent |
groupelip.com. 21600 IN DS 46201 8 2 CB19AD3F1A75FCF6D5921CC2266073351C66B11BE3210C087916BF58 1AEF249F
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| NSEC/NSEC3 record |
No NSEC or NSEC3 record found when querying a non-existent subdomain.
This may indicate a misconfiguration or lack of proper DNSSEC denial-of-existence support. |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Changing nameservers while DNSSEC is active |
⚠️ Your domain is currently signed with DNSSEC.
Before changing your nameservers (NS), you must disable DNSSEC at your registrar. Otherwise, your domain may become unreachable due to missing or invalid signatures on the new servers. |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
SOA0.1 ms |
SOA Record |
The SOA (Start of Authority) record is:
Primary nameserver: dns108.ovh.net Hostmaster E-mail address: tech@ovh@net Serial #: 2087776969 Refresh: 86400 Retry: 3600 Expire: 3600000 Default TTL: 300 |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| NSs have same SOA serial |
OK. All your nameservers agree that your SOA serial number is 2087776969.
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| SOA MNAME entry |
OK. dns108.ovh.net is listed at the parent servers.
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| SOA Serial |
Your SOA serial number is: 2087776969. This appears to follow the recommended YYYYMMDDnn format.
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| SOA REFRESH |
Your SOA REFRESH interval is: 86400. OK.
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| SOA RETRY |
Your SOA RETRY value is: 3600. OK.
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| SOA EXPIRE |
Your SOA EXPIRE number is: 3600000. Looks OK.
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| SOA MINIMUM TTL |
Minimum TTL is low (300). Recommended: 1h+ (3600).
A low minimum TTL results in more frequent DNS queries, which can increase server load. A higher value improves cache efficiency. |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
MX ... |
MX Records |
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
TXT0.1 ms |
TXT Records |
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Duplicate TXT records |
Multiple TXT records were found for the same host/selector. This can break email authentication.
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
SPF ... |
SPF Analysis |
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
DMARC127.0 ms |
DMARC Configuration |
DMARC Record was found:
v=DMARC1;p=reject;sp=reject;rua=mailto:[email protected];ri=86400;pct=100;aspf=r;adkim=r Policy summary:
v=DMARC1; p=reject; sp=reject; rua=mailto:[email protected]; ruf=none; fo=0; pct=100; adkim=r; aspf=r; ri=86400; rf=afrf; DMARC Evaluation Score: 3/3 ✅ Excellent: Your DMARC configuration is optimal. |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
MTA-STS / TLS-RPT551.7 ms |
Mail TLS security |
MTA-STS score 0/5 Recommendations:
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
DKIM ... |
DKIM Records Detected |
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
BIMI227.2 ms |
BIMI Record |
No BIMI record found at: default._bimi.groupelip.com.
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
SSL ... |
SSL Certificate Summary |
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
CAA ... |
CAA Records |
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
HSTS ... |
HSTS |
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
HTTPS ... |
HTTPS |
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
HTTPS (DNS) ... |
HTTPS DNS record |
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
WWW ... |
A Record |
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
AXFR (Zone Transfer)679.2 ms |
AXFR status for the zone |
AXFR is refused by the authoritative nameservers for groupelip.com.
Nameservers tested: ns108.ovh.net, dns108.ovh.net |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Security note |
Zone transfers (AXFR) should be disabled in production unless explicitly required and restricted.
Leaving AXFR open allows anyone to enumerate your entire DNS zone (subdomains, MX, TXT, internal hosts, etc.). |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
PORTS ... |
Open ports detected (199.60.103.35) |
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
PORTS ... |
Open ports detected (199.60.103.135) |
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| PORTS | Open ports detected (2001:41d0:301::100) |
IPv6 scan skipped: this DNSprobe server does not currently have outbound IPv6 connectivity. |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
REPUTATION ... |
IP in blacklists (199.60.103.35) |
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
REPUTATION ... |
IP in blacklists (199.60.103.135) |
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
REPUTATION ... |
IP in blacklists (2001:41d0:301::100) |
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
DNS found ... |
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Test | Details | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
Website Preview0.0 ms
|
Snapshot is generated through DNSprobe's rendering proxy and may be served from a short cache.
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Security Headers535.5 ms
|
Score: 84/100 (B) Good security, some improvements possible
Other detected headers Additional headers returned by the server. Shown for information only and not included in the score.
Recommended starter configuration (.htaccess) Starter configuration to copy and adapt. CSP, CORS and cookie rewriting are intentionally commented because they can break some sites if enabled blindly. |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
WHOIS143.2 ms
|
Source: WHOIS (port 43) whois.ovh.com
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
RDAP 142.6 ms
|
Source: RDAP rdap.org → rdap.verisign.com → rdap.ovh.com
Registrar
RDAP JSON (raw){
"objectClassName": "domain",
"handle": "2131534725_DOMAIN_COM-VRSN",
"ldhName": "GROUPELIP.COM",
"links": [
{
"value": "https://rdap.verisign.com/com/v1/domain/groupelip.com",
"rel": "self",
"href": "https://rdap.verisign.com/com/v1/domain/groupelip.com",
"type": "application/rdap+json"
},
{
"value": "https://rdap.verisign.com/com/v1/domain/groupelip.com",
"rel": "related",
"href": "https://rdap.ovh.com/domain/GROUPELIP.COM",
"type": "application/rdap+json"
}
],
"status": [
"client delete prohibited",
"client transfer prohibited"
],
"entities": [
{
"objectClassName": "entity",
"handle": "433",
"roles": [
"registrar"
],
"links": [
{
"href": "http://www.ovh.com",
"type": "text/html",
"value": "https://rdap.ovh.com/",
"rel": "about"
}
],
"publicIds": [
{
"type": "IANA Registrar ID",
"identifier": "433"
}
],
"vcardArray": [
"vcard",
[
[
"version",
[],
"text",
"4.0"
],
[
"fn",
[],
"text",
"OVH sas"
]
]
],
"entities": [
{
"objectClassName": "entity",
"roles": [
"abuse"
],
"vcardArray": [
"vcard",
[
[
"version",
[],
"text",
"4.0"
],
[
"fn",
[],
"text",
""
],
[
"tel",
{
"type": "voice"
},
"uri",
"tel:+33.972101007"
],
[
"email",
[],
"text",
"[email protected]"
]
]
]
}
]
}
],
"events": [
{
"eventAction": "registration",
"eventDate": "2017-06-07T14:52:14Z"
},
{
"eventAction": "expiration",
"eventDate": "2027-06-07T14:52:14Z"
},
{
"eventAction": "last changed",
"eventDate": "2026-06-08T08:23:11Z"
},
{
"eventAction": "last update of RDAP database",
"eventDate": "2026-09-20T00:33:36Z"
}
],
"secureDNS": {
"delegationSigned": true,
"dsData": [
{
"keyTag": 46201,
"algorithm": 8,
"digestType": 2,
"digest": "CB19AD3F1A75FCF6D5921CC2266073351C66B11BE3210C087916BF581AEF249F"
}
]
},
"nameservers": [
{
"objectClassName": "nameserver",
"ldhName": "DNS108.OVH.NET"
},
{
"objectClassName": "nameserver",
"ldhName": "NS108.OVH.NET"
}
],
"rdapConformance": [
"rdap_level_0",
"icann_rdap_technical_implementation_guide_1",
"icann_rdap_response_profile_1"
],
"notices": [
{
"title": "Terms of Service",
"description": [
"Service subject to Terms of Use."
],
"links": [
{
"href": "https://www.verisign.com/domain-names/registration-data-access-protocol/terms-service/index.xhtml",
"type": "text/html",
"value": "https://rdap.verisign.com/com/v1/domain/groupelip.com",
"rel": "terms-of-service"
}
]
},
{
"title": "Status Codes",
"description": [
"For more information on domain status codes, please visit https://icann.org/epp"
],
"links": [
{
"href": "https://icann.org/epp",
"type": "text/html",
"value": "https://rdap.verisign.com/com/v1/domain/groupelip.com",
"rel": "glossary"
}
]
},
{
"title": "RDDS Inaccuracy Complaint Form",
"description": [
"URL of the ICANN RDDS Inaccuracy Complaint Form: https://icann.org/wicf"
],
"links": [
{
"href": "https://icann.org/wicf",
"type": "text/html",
"value": "https://rdap.verisign.com/com/v1/domain/groupelip.com",
"rel": "help"
}
]
}
]
} |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Processed in 0.01 seconds.
Made with with PHP and a bit of JS.
Made with with PHP and a bit of JS.
Lines of code: 20,351