DNS & IP Record Check for Fosterandpartners.com
This tool gives you a detailed look at Fosterandpartners.com DNS setup. It checks various parts of the DNS records to ensure everything is functioning smoothly and securely.
Our DNS & IP record check is organized into 6 main groups, each focusing on different aspects of your domain's DNS configuration. Each group tests key components to ensure optimal domain performance:
- DNS Parent Group - 5 tests
- NS (Nameserver) - 17 tests
- SOA (Start of Authority) - 9 tests
- MX (Mail Exchanger) - 12 tests
- MAIL (Email) - 4 tests
- WWW (World Wide Web) - 24 tests
To help you better understand the results, our team has categorized the outcomes into four statuses:
- PASS - No issues found in the DNS record.
- FAIL - We detected a DNS record error that needs your attention.
- WARN - A minor DNS record issue was found.
- INFO - Informational data about the DNS record with no errors detected.
To ensure the integrity and security of Fosterandpartners.com DNS data, use our DNSSEC check tool. This test provides a deeper analysis, focusing on digital signatures, security, and integrity of the DNS records.
|
Below is an overview of the results from our comprehensive DNS lookup for the domain Fosterandpartners.com:
DNS Group | DNS Check | DNS Record Type | DNS Data Information | |||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
PARENT | ||||||||||||||||||||
PASS | Missing Direct Parent check | OK. Your direct parent zone exists, SOA of parent zone com is a.gtld-servers.net which is good. Some domains (usually third or fourth level domains, such as example.co.us or subdomain.example.co.us) do not have a direct parent zone ('co.us' in this example), which is legal but can cause confusion. | ||||||||||||||||||
FAIL | Glue at parent nameservers | The parent servers do not have glue for your nameservers | ||||||||||||||||||
INFO | NS records at parent servers | Your NS record at parent servers are:
These were obtained from g.gtld-servers.net. However these were obtained from authority section and not answer section. It is better if they were obtained from answer section. |
||||||||||||||||||
PASS | DNS servers have A records | OK. All your DNS servers either have A records at the zone parent servers | ||||||||||||||||||
PASS | Parent nameservers have your nameservers listed | OK. When someone uses DNS to look up your domain, the first step (if it doesn't already know about your domain) is to go to the parent servers. If you aren't listed there, you can't be found. But you are listed there. |
DNS Group | DNS Status | DNS Record Type | DNS Data Information | |||||
---|---|---|---|---|---|---|---|---|
NS | ||||||||
INFO | NS records at your nameservers | Your NS records at your nameservers are:
|
||||||
PASS | Mismatched NS records | OK. NS records at all your nameservers are identical. | ||||||
PASS | All nameservers respond | All your nameservers responding. | ||||||
PASS | Recursive queries | None of your nameservers allow recursive queries | ||||||
PASS | Zone Transfer | Zone transfer not allowed by any of your nameservers | ||||||
PASS | No NS A records at nameservers | OK. Your nameservers do include corresponding A records when asked for your NS records. This ensures that your DNS servers know the A records corresponding to all your NS records. | ||||||
PASS | Nameserver name validity | OK. All of the NS records that your nameservers report seem valid (no IPs or partial domain names). | ||||||
PASS | Number of nameservers | You have 2 nameservers. You must have at least 2 nameservers (RFC2182 section 5 recommends at least 3 nameservers), and preferably no more than 7. | ||||||
PASS | Lame nameservers | OK. All the nameservers listed at the parent servers answer authoritatively for your domain. | ||||||
PASS | Missing (stealth) nameservers | You have no stealth servers. | ||||||
PASS | Missing nameservers 2 | All nameservers listed at parent servers are listed as NS records at your nameservers | ||||||
FAIL | Same Glue | Glue provided by parent servers different from that provided by nameservers for these NS records: carrera.ns.cloudflare.com at parent 172.64.34.231 dns query: 108.162.194.231 kolton.ns.cloudflare.com at parent 172.64.35.25 dns query: 108.162.195.25 |
||||||
PASS | No CNAMEs for domain | OK. There are no CNAMEs for Fosterandpartners.com. RFC1912 2.4 and RFC2181 10.3 state that there should be no CNAMEs if an NS (or any other) record is present. | ||||||
PASS | TCP Allowed | All your nameservers allow TCP connection | ||||||
PASS | Stealth NS record leakage | Your DNS servers doesn't leak NS record in non-NS request. | ||||||
PASS | Nameservers on separate class C's | OK. You have nameservers on different Class C (technically, /24) IP ranges. You must have nameservers at geographically and topologically dispersed locations. RFC2182 3.1 goes into more detail about secondary nameserver location. | ||||||
PASS | All NS IPs public | OK. All of your NS records appear to use public IPs. If there were any private IPs, they would not be reachable, causing DNS delays. | ||||||
FAIL | Glue for NS record | Your nameservers for your NS records didn't return the A records for the NS records. |
DNS Group | DNS Status | DNS Record Type | DNS Data Information |
---|---|---|---|
SOA | |||
INFO | SOA record | Your SOA record [TTL=1800] is: Primary Name server: carrera.ns.cloudflare.com Hostmaster E-mail address: dns.cloudflare.com Serial #:2371510795 Refresh: 10000 Retry: 2400 Expire: 604800 Default: 1800 |
|
PASS | SOA MNAME entry | SOA MNAME carrera.ns.cloudflare.com is listed as a primary nameserver at your parent nameserver | |
PASS | SOA RNAME entry | OK. Your SOA (Start of Authority) record states that your DNS contact E-mail address is: [email protected] (techie note: we have changed the initial '.' to an '@' for display purposes). | |
PASS | NS agreement on SOA Serial # | OK. All your nameservers agree that your SOA serial number is 2009050102. That means that all your nameservers are using the same data (unless you have different sets of data with the same serial number, which would be very bad)! Note that the DNS report only checks the NS records listed at the parent servers (not any stealth servers). | |
FAIL | SOA Serial | Your SOA serial number is: 2371510795. This doesn't appears to be in the recommended format of YYYYMMDDnn. | |
INFO | SOA REFRESH | OK. Your SOA REFRESH interval is: 10000. RFC 1912 recommends 1200 to 43200 seconds, low (1200) if the data is volatile or 43200 (12 hours) if it's not. If you are using NOTIFY you can set for much higher values, for instance, 1 or more days (> 86400 seconds). | |
WARN | SOA RETRY | OK. Your SOA RETRY interval is: 2400. Typical values would be 180 (3 minutes) to 900 (15 minutes) or higher. | |
WARN | SOA EXPIRE | OK. Your SOA EXPIRE interval is: 604800 .RFC 1912 recommends 1209600 to 2419200 seconds (2-4 weeks) to allow for major outages of the zone master. | |
PASS | SOA MINIMUM TTL | OK. Your SOA MINIMUM TTL is: 1800. That is OK |
DNS Group | DNS Status | DNS Record Type | DNS Data Information |
---|---|---|---|
MX | |||
FAIL | MX Glue | MX record look up did not send glue record for atleast 1 MX server: eu-smtp-inbound-1.mimecast.com, eu-smtp-inbound-2.mimecast.com |
|
PASS | MX records are not CNAMEs | OK. Looking up your MX record did not just return a CNAME. If an MX record query returns a CNAME, extra processing is required, and some mail servers may not be able to handle it. | |
PASS | MX name validity | Good. We did not detect any invalid chars in hostnames for your MX records. | |
PASS | MX is host name, not IP | OK. All of your MX records are host names (as opposed to IP addresses, which are not allowed in MX records). | |
PASS | Different MX records at nameservers | Good. Looks like all your nameservers have the same set of MX records. This tests to see if there are any MX records not reported by all your nameservers | |
FAIL | MX Glues match | MX Glue returned by nameserver for MX record doesn't match with A record of MX hostname eu-smtp-inbound-1.mimecast.com > 195.130.217.241;///// X eu-smtp-inbound-2.mimecast.com > 91.220.42.211;///// X |
|
PASS | Duplicate MX records | OK. You do not have any duplicate MX records (pointing to the same IP). Although technically valid, duplicate MX records can cause a lot of confusion, and waste resources. | |
PASS | MX A lookups have no CNAMEs | OK. There appear to be no CNAMEs returned for A records lookups from your MX records (CNAMEs are prohibited in MX records, according to RFC974, RFC1034 3.6.2, RFC1912 2.4, and RFC2181 10.3). | |
INFO | MX Record | Your 2 records: 10 eu-smtp-inbound-1.mimecast.com [IP Address=195.130.217.241] [TTL=300] 10 eu-smtp-inbound-2.mimecast.com [IP Address=91.220.42.211] [TTL=300] |
|
PASS | Multiple MX records | OK. You have multiple MX records. This means that if one is down or unreachable, the other(s) will be able to accept mail for you. | |
PASS | Reverse MX A records (PTR) | The reverse (PTR) record for your MX records: 195.130.217.241 -> eu-smtp-inbound-1.mimecast.com 91.220.42.211 -> eu-smtp-inbound-1.mimecast.com |
|
PASS | All MX IPs public | OK. All of your MX records appear to use public IPs. If there were any private IPs, they would not be reachable, causing slight mail delays, extra resource usage, and possibly bounced mail. |
DNS Group | DNS Status | DNS Record Type | DNS Data Information |
---|---|---|---|
PASS | SPF record | v=spf1 redirect=5q208o94._spf._d.mim.ec | |
PASS | TXT record | docusign=94be05e3-624b-4aed-890e-ab7fadd33bb2 | |
PASS | TXT record | docusign=a4f6efea-fe0f-4396-a168-6d3cae306906 | |
PASS | TXT record | jamf-site-verification=-3Fv0FLkY1Reod-O5jSgEw | |
PASS | TXT record | miro-verification=cbffbe63db369aab712dc8d7dcd1da3ac83d5fe8 | |
PASS | TXT record | ms-domain-verification=4b9011bb-ae3d-455f-9240-98c4b1ed5135 | |
PASS | TXT record | webexdomainverification.EO31=939b4450-82aa-4107-8535-8187d368ea2d | |
PASS | TXT record | apple-domain-verification=NiUuS9LjAjJtY8rc | |
PASS | TXT record | beWtPmIBTFkgbcz/wGfDC0ByRI/ocMG0mSYpZW0tpfO9rmCeKH7erBW5MM8kObaRf1dKb9hcqDYug4Ig+c9Xaw== | |
PASS | TXT record | bw=5D5iM7YRxTmi2UxRW7WpYuuMbEAyAW1BMa1XygCRWggP | |
PASS | TXT record | cisco-ci-domain-verification=b25fa020bff35bd2da23704ab395f729ae8efa59a5c5e4f26f25512308d0a6a | |
WARN | Sender ID record(spfv2.0) | SenderID framework not implemented | |
WARN | Domain Key Test | Domain keys not implemenetd for _domainkey.Fosterandpartners.com. Separate domainkey records may exist for subdomains and selectors under this domain. this cannot be tested. | |
PASS | DMARC | v=DMARC1; p=quarantine; rua=mailto:[email protected]; ruf=mailto:[email protected]; fo=1; |
DNS Group | DNS Status | DNS Record Type | DNS Data Information |
---|---|---|---|
WWW | |||
INFO | WWW A record | Your WWW A record is: shed.dual-low.s-part-0013.t-0009.t-msedge.net > s-part-0013.t-0009.t-msedge.net. Resolved IP: 13.107.246.41 Your WWW is CNAME record and your CNAME entry returns A record which is good. WA & DA Score for s-part-0013.t-0009.t-msedge.net |
|
PASS | IPs are public | OK. All of your WWW IP addresses appear to be public IP addresses. | |
PASS | HTTP Service | OK: We can connect to http service on port 80. | |
FAIL | Server | http service on port 80 didn't return server information. | |
INFO | Server Header | http response header didn't return any server information | |
PASS | Connection | http connection header return connection as: Keep-alive | |
WARN | Secure Header HSTS | The server did not implement the HSTS (HTTP Strict Transport Security) policy. The header over the HTTPS connection was not found. | |
WARN | Secure Header X-Frame-Options | XFO clickjacking protection response header was not found. XFO enables content to be found or not within iframes via the browser. | |
WARN | Secure Header X-Content-Type-Options | The X-Content-Type-Options secure header is not set | |
WARN | Secure Header Content-Security-Policy | CSP is not defined in the policy. The return secure header does not send any feedback that the CSP has been set | |
WARN | Secure Header X-Permitted-Cross-Domain-Policies | X-Permitted-Cross-Domain-Policies was not found in the response header | |
WARN | Secure Header Referrer-Policy | The Referrer-Policy HTTP header is not set, as it is not in the Referrer header. | |
INFO | Secure Header Clear-Site-Data | Clear-Site-Data was not found in the response header | |
INFO | Secure Header Cross-Origin-Embedder-Policy | COEP response header was not found in the HTTP request | |
INFO | Secure Header Cross-Origin-Opener-Policy | COOP response header was not found in the HTTP request | |
WARN | Secure Header Cross-Origin-Resource-Policy | CORP policy not found in response header | |
WARN | Secure Header Cache-Control | Cache-Control policy header not found in HTTP responses | |
WARN | Secure Header Permissions-Policy | Permissions-Policy header was not found in the HTTP responses. | |
INFO | Secure Header Feature-Policy | Feature-Policy header was not found in the HTTP responses. | |
INFO | Secure Header X-XSS-Protection (Deprecated) | X-XSS-Protection header was not found in the HTTP responses. | |
INFO | Secure Header HTTP Public Key Pinning (Deprecated) | HPKP header was not found in the HTTP responses. | |
INFO | Secure Header Expect-CT (Deprecated) | Expect-CT header was not found in the HTTP responses. | |
PASS | SSL / HTTPS Protocol | Domain use encrypted SSL / HTTPS connection on port 443. View SSL Certificate: Fosterandpartners.com. |
|
FAIL | IPv6 | Your domain has no IPv6 support |