DNS report
quark.ammocan.dev
Complete DNS, mail, web and security analysis.
DNS cache tools
If you have recently made DNS changes and they are not yet reflected in the report, you can try to flush the DNS cache of these public resolvers: The domain name will be copied to your clipboard automatically when clicking on a button
| Category | Status | Test | Details | ||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
WHOIS0.0 ms |
Domain Status |
Unable to retrieve WHOIS information for quark.ammocan.dev.
Retry, this time it might work! Reason: empty whois/rdap response |
|||||||||||||||||||||||||
|
PARENT0.0 ms |
Domain NS records |
No NS records found from ns1079.ui-dns.de.
dig: dig NS 'quark.ammocan.dev' @'8.8.8.8' +time=2 +tries=1 +noall +answer +authority +additional 2>/dev/null |
|||||||||||||||||||||||||
| TLD Parent Check |
The parent server did not return any information for this TLD.
|
||||||||||||||||||||||||||
| Your nameservers are listed |
Mismatch between parent and domain NS.
|
||||||||||||||||||||||||||
| DNS Parent sent Glue |
0 of 0 nameservers sent GLUE.
The parent nameserver a.gtld-servers.net sent GLUE, meaning it sent your nameservers as well as the IPs of your nameservers. Glue records are A records that are associated with NS records to provide "bootstrapping" information to the nameserver. (See RFC 1912 section 2.3) |
||||||||||||||||||||||||||
| Nameservers A records |
Every nameserver listed has A records.
This is a must if you want to be found. |
||||||||||||||||||||||||||
|
NS961.2 ms |
NS records from your NameServers |
NS records returned by the currently delegated nameservers are:
Oops! I could not get any nameservers from your nameservers. Please verify that the nameservers listed at the parent are not lame and are configured properly. Nameservers with no NS response: ingress.bot-hosting.cloud |
|||||||||||||||||||||||||
| Public Resolver |
|
||||||||||||||||||||||||||
| Mismatched NS records |
Mismatch detected between parent and zone NS records.
Parent NS: Zone NS: ingress.bot-hosting.cloud WARNING: One or more of your nameservers did not return any of your NS records. |
||||||||||||||||||||||||||
| DNS servers responded |
The following NS did not respond to a basic query:
ingress.bot-hosting.cloud ❌ These nameservers did not respond to a standard non-recursive A query. This may indicate filtering, timeouts, or misconfiguration. |
||||||||||||||||||||||||||
| Name of nameservers are valid |
All of the NS records that your nameservers report seem valid.
|
||||||||||||||||||||||||||
| Multiple Nameservers |
You only have 1 nameserver(s). RFC2182 recommends at least 2, ideally 3 or more.
|
||||||||||||||||||||||||||
| Missing nameservers reported by parent |
FAIL: The following nameservers are listed at your nameservers as nameservers for your domain, but are not listed at the parent nameservers (see RFC2181 5.4.1).
The missing NS records at the parent are: ingress.bot-hosting.cloud You need to make sure that these nameservers are working. If they are not working correctly, you may experience problems. |
||||||||||||||||||||||||||
| Missing nameservers reported by your nameservers |
All nameservers returned by the parent server are the same as the ones reported by your nameservers.
|
||||||||||||||||||||||||||
| Domain CNAMEs |
A CNAME record exists at the zone apex while other records are also present. This is invalid DNS configuration.
|
||||||||||||||||||||||||||
| NSs CNAME check |
OK. RFC1912 2.4 and RFC2181 10.3 state that there should be no CNAMEs if an NS (or any other) record is present.
|
||||||||||||||||||||||||||
| Different subnets |
All nameservers are on the same subnet (can be a risk).
|
||||||||||||||||||||||||||
| Recursive Queries |
ingress.bot-hosting.cloud → ❌ This DNS server allows recursion, which may pose a security risk (it responds to out-of-zone queries).
|
||||||||||||||||||||||||||
| Same Glue |
I do not consider this an error because no authoritative nameserver returned NS records for this domain.
|
||||||||||||||||||||||||||
| NS Self-IP Consistency |
Test skipped because no authoritative nameserver responded well enough to perform this check.
|
||||||||||||||||||||||||||
| Glue for NS records |
The delegated nameservers did not return NS records for this domain, so DNSprobe cannot verify child-side glue. This is treated as a pass because the main delegation problem has already been reported.
|
||||||||||||||||||||||||||
| Nameservers are lame |
OK. The nameservers listed at the parent are the delegated nameservers for this domain. No additional lame nameserver condition was detected beyond the response issue already reported above.
|
||||||||||||||||||||||||||
| IPs of nameservers are public |
Ok. Looks like the IP addresses of your nameservers are public.
This is a good thing because it will prevent DNS delays and other problems. |
||||||||||||||||||||||||||
| DNS servers allow TCP connection |
Some authoritative name servers do not respond over TCP:
ingress.bot-hosting.cloud (178.105.112.237) TCP support is important for large DNS replies (DNSSEC, long responses, truncation fallback). |
||||||||||||||||||||||||||
| Different autonomous systems |
Only one nameserver found or unable to determine ASN for comparison.
|
||||||||||||||||||||||||||
| Stealth NS records sent |
The following name servers are configured in your zone but not reported by the parent (stealth NS):
ingress.bot-hosting.cloud Stealth name servers can cause inconsistent DNS answers and complicate troubleshooting. Make sure all authoritative NS are correctly published at the registry/parent level. |
||||||||||||||||||||||||||
|
DNSSEC365.1 ms |
Zone signed |
DNSSEC: signedDelegation
RRSIG record present. The zone appears to be DNSSEC-signed. |
|||||||||||||||||||||||||
| DNSKEY records |
quark.ammocan.dev. 60 IN CNAME ingress.bot-hosting.cloud.
|
||||||||||||||||||||||||||
| DS record in parent |
quark.ammocan.dev. 60 IN CNAME ingress.bot-hosting.cloud.
|
||||||||||||||||||||||||||
| NSEC/NSEC3 record |
No NSEC or NSEC3 record found when querying a non-existent subdomain.
This may indicate a misconfiguration or lack of proper DNSSEC denial-of-existence support. |
||||||||||||||||||||||||||
| Changing nameservers while DNSSEC is active |
⚠️ Your domain is currently signed with DNSSEC.
Before changing your nameservers (NS), you must disable DNSSEC at your registrar. Otherwise, your domain may become unreachable due to missing or invalid signatures on the new servers. |
||||||||||||||||||||||||||
|
SOA127.0 ms |
SOA Record |
The SOA (Start of Authority) record is:
Primary nameserver: — Hostmaster E-mail address: — Serial #: — Refresh: — Retry: — Expire: — Default TTL: — |
|||||||||||||||||||||||||
| NSs have same SOA serial |
Inconsistent SOA serials returned by your nameservers:
|
||||||||||||||||||||||||||
| SOA MNAME entry |
is NOT listed at the parent level. This could cause issues with zone transfer or delegation.
|
||||||||||||||||||||||||||
| SOA Serial |
Your SOA serial number is: —. This does not match the recommended YYYYMMDDnn format.
|
||||||||||||||||||||||||||
| SOA REFRESH |
Your SOA REFRESH interval is: —. OK.
|
||||||||||||||||||||||||||
| SOA RETRY |
Your SOA RETRY value is: —. OK.
|
||||||||||||||||||||||||||
| SOA EXPIRE |
Your SOA EXPIRE number is: —. Looks OK.
|
||||||||||||||||||||||||||
| SOA MINIMUM TTL |
Your SOA MINIMUM TTL is: —. This is fine
|
||||||||||||||||||||||||||
|
MX ... |
MX Records |
|
|||||||||||||||||||||||||
|
TXT0.1 ms |
TXT Records |
|
|||||||||||||||||||||||||
|
DMARC81.9 ms |
DMARC Record |
No valid DMARC record was found at _dmarc.quark.ammocan.dev.
|
|||||||||||||||||||||||||
|
MTA-STS / TLS-RPT230.9 ms |
Mail TLS security |
MTA-STS score 0/5 Recommendations:
|
|||||||||||||||||||||||||
|
DKIM ... |
DKIM Records Detected |
|
|||||||||||||||||||||||||
|
BIMI103.7 ms |
BIMI Record |
No BIMI record found at: default._bimi.quark.ammocan.dev.
|
|||||||||||||||||||||||||
|
SSL ... |
SSL Certificate Summary |
|
|||||||||||||||||||||||||
|
CAA ... |
CAA Records |
|
|||||||||||||||||||||||||
|
HSTS ... |
HSTS |
|
|||||||||||||||||||||||||
|
HTTPS ... |
HTTPS |
|
|||||||||||||||||||||||||
|
HTTPS (DNS) ... |
HTTPS DNS record |
|
|||||||||||||||||||||||||
|
WWW ... |
A Record |
|
|||||||||||||||||||||||||
|
AXFR (Zone Transfer)335.7 ms |
AXFR status for the zone |
AXFR is refused by the authoritative nameservers for quark.ammocan.dev.
Nameservers tested: ingress.bot-hosting.cloud |
|||||||||||||||||||||||||
| Security note |
Zone transfers (AXFR) should be disabled in production unless explicitly required and restricted.
Leaving AXFR open allows anyone to enumerate your entire DNS zone (subdomains, MX, TXT, internal hosts, etc.). |
||||||||||||||||||||||||||
|
PORTS ... |
Open ports detected (178.105.112.237) |
|
|||||||||||||||||||||||||
|
REPUTATION ... |
IP in blacklists (178.105.112.237) |
|
|||||||||||||||||||||||||
|
DNS found ... |
|
||||||||||||||||||||||||||
| Test | Details | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
Website Preview0.0 ms
|
Snapshot is generated through DNSprobe's rendering proxy and may be served from a short cache.
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Security Headers643.9 ms
|
Score: 11/100 (F) Failing, very weak or absent security headers
Other detected headers Additional headers returned by the server. Shown for information only and not included in the score.
Recommended starter configuration (.htaccess) Starter configuration to copy and adapt. CSP, CORS and cookie rewriting are intentionally commented because they can break some sites if enabled blindly. |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| WHOIS |
Unable to retrieve registration data for quark.ammocan.dev.
|
Processed in 0.01 seconds.
Made with with PHP and a bit of JS.
Made with with PHP and a bit of JS.
Lines of code: 20,351