DNS & IP Record Check for Myshopify.com

This tool gives you a detailed look at Myshopify.com DNS setup. It checks various parts of the DNS records to ensure everything is functioning smoothly and securely.

DNS Record Group Breakdown:

Our DNS & IP record check is organized into 6 main groups, each focusing on different aspects of your domain's DNS configuration. Each group tests key components to ensure optimal domain performance:

  1. DNS Parent Group - 5 tests
  2. NS (Nameserver) - 17 tests
  3. SOA (Start of Authority) - 9 tests
  4. MX (Mail Exchanger) - 12 tests
  5. MAIL (Email) - 4 tests
  6. WWW (World Wide Web) - 24 tests
Test Status Summary:

To help you better understand the results, our team has categorized the outcomes into four statuses:

  1. PASS - No issues found in the DNS record.
  2. FAIL - We detected a DNS record error that needs your attention.
  3. WARN - A minor DNS record issue was found.
  4. INFO - Informational data about the DNS record with no errors detected.

To ensure the integrity and security of Myshopify.com DNS data, use our DNSSEC check tool. This test provides a deeper analysis, focusing on digital signatures, security, and integrity of the DNS records.


Below is an overview of the results from our comprehensive DNS lookup for the domain Myshopify.com:

DNS Group DNS Check DNS Record Type DNS Data Information
PARENT
PASS Missing Direct Parent check OK. Your direct parent zone exists, SOA of parent zone com is a.gtld-servers.net which is good. Some domains (usually third or fourth level domains, such as example.co.us or subdomain.example.co.us) do not have a direct parent zone ('co.us' in this example), which is legal but can cause confusion.
FAIL Glue at parent nameservers The parent servers do not have glue for your nameservers
INFO NS records at parent servers Your NS record at parent servers are:
ns1.dnsimple.com[IP Address=162.159.24.4][TTL=172800]
ns2.dnsimple.com[IP Address=199.247.153.53][TTL=172800]
ns3.dnsimple.com[IP Address=162.159.26.4][TTL=172800]
ns4.dnsimple.com[IP Address=199.247.155.53][TTL=172800]

These were obtained from g.gtld-servers.net. However these were obtained from authority section and not answer section. It is better if they were obtained from answer section.
PASS DNS servers have A records OK. All your DNS servers either have A records at the zone parent servers
FAIL Parent nameservers have your nameservers listed Your nameservers not listed in parent servers: blue.foundationdns.com, blue.foundationdns.org
DNS Group DNS Status DNS Record Type DNS Data Information
NS
INFO NS records at your nameservers Your NS records at your nameservers are:
ns1.dnsimple.com[IP Address=162.159.24.4][TTL=3600]
ns2.dnsimple.com[IP Address=199.247.153.53][TTL=3600]
ns3.dnsimple.com[IP Address=162.159.26.4][TTL=3600]
ns4.dnsimple.com[IP Address=199.247.155.53][TTL=3600]
PASS Mismatched NS records OK. NS records at all your nameservers are identical.
PASS All nameservers respond All your nameservers responding.
PASS Recursive queries None of your nameservers allow recursive queries
PASS Zone Transfer Zone transfer not allowed by any of your nameservers
PASS No NS A records at nameservers OK. Your nameservers do include corresponding A records when asked for your NS records. This ensures that your DNS servers know the A records corresponding to all your NS records.
PASS Nameserver name validity OK. All of the NS records that your nameservers report seem valid (no IPs or partial domain names).
PASS Number of nameservers You have 5 nameservers. You must have at least 2 nameservers (RFC2182 section 5 recommends at least 3 nameservers), and preferably no more than 7.
PASS Lame nameservers OK. All the nameservers listed at the parent servers answer authoritatively for your domain.
PASS Missing (stealth) nameservers You have no stealth servers.
FAIL Missing nameservers 2 ERROR: One or more of the nameservers listed at the parent servers are not listed as NS records at your nameservers. The problem NS records are:
blue.foundationdns.net
PASS No CNAMEs for domain OK. There are no CNAMEs for Myshopify.com. RFC1912 2.4 and RFC2181 10.3 state that there should be no CNAMEs if an NS (or any other) record is present.
PASS TCP Allowed All your nameservers allow TCP connection
PASS Stealth NS record leakage Your DNS servers doesn't leak NS record in non-NS request.
PASS Nameservers on separate class C's OK. You have nameservers on different Class C (technically, /24) IP ranges. You must have nameservers at geographically and topologically dispersed locations. RFC2182 3.1 goes into more detail about secondary nameserver location.
PASS All NS IPs public OK. All of your NS records appear to use public IPs. If there were any private IPs, they would not be reachable, causing DNS delays.
PASS Glue for NS record OK. When we asked your nameservers for your NS records they also returned the A records for the NS records. This is a good thing as it will spare an extra A lookup needed to find those A records.
DNS Group DNS Status DNS Record Type DNS Data Information
SOA
INFO SOA record Your SOA record [TTL=3600] is:
Primary Name server: ns1.dnsimple.com
Hostmaster E-mail address: admin.dnsimple.com
Serial #:1477078327
Refresh: 86400
Retry: 7200
Expire: 604800
Default: 300
PASS SOA MNAME entry SOA MNAME ns1.dnsimple.com is listed as a primary nameserver at your parent nameserver
PASS SOA RNAME entry OK. Your SOA (Start of Authority) record states that your DNS contact E-mail address is: [email protected] (techie note: we have changed the initial '.' to an '@' for display purposes).
FAIL NS agreement on SOA Serial # Some of your nameservers don't agree on SOA serial number. Serial numbers found : 2370313406,1477078327,1477078327,1477078327,1477078327
FAIL SOA Serial Your SOA serial number is: 1477078327. This doesn't appears to be in the recommended format of YYYYMMDDnn.
WARN SOA REFRESH Your SOA REFRESH interval is: 86400 which is higher than recommended. RFC 1912 recommends 1200 to 43200 seconds, low (1200) if the data is volatile or 43200 (12 hours) if it's not. If you are using NOTIFY you can set for much higher values, for instance, 1 or more days (> 86400 seconds).
WARN SOA RETRY OK. Your SOA RETRY interval is: 7200. Typical values would be 180 (3 minutes) to 900 (15 minutes) or higher.
WARN SOA EXPIRE OK. Your SOA EXPIRE interval is: 604800 .RFC 1912 recommends 1209600 to 2419200 seconds (2-4 weeks) to allow for major outages of the zone master.
PASS SOA MINIMUM TTL OK. Your SOA MINIMUM TTL is: 300. That is OK
DNS Group DNS Status DNS Record Type DNS Data Information
MX
FAIL MX Record No MX records found. You may ignore results of any other MX tests.
FAIL Reverse MX A records (PTR) There are no A records for your MXs, so the test cannot be performed.
DNS Group DNS Status DNS Record Type DNS Data Information
MAIL
PASS SPF record 3pd0b2jrw466c2yt9n91fqzb0dddxt32
ca3-6e76b0c8b6354461bd49bdcaa2a68759
ca3-955daa84b0544e9f9bfefb7348b0f17e
facebook-domain-verification=2fkm7xuqgm7qxmurz186uv6hqf8xej
google-site-verification=cpnlhp0hXCCAPw6t_0CgQQOd8rhMyfZ8bA6k1D8__Gc
rkvq4wdzjcp4s4yyqk331zqymy2chf8t
v=spf1 -all
this domain never sends out email
WARN Sender ID record(spfv2.0) SenderID framework not implemented
WARN Domain Key Test Domain keys not implemenetd for _domainkey.Myshopify.com. Separate domainkey records may exist for subdomains and selectors under this domain. this cannot be tested.
PASS DMARC v=DMARC1; p=reject; fo=1; pct=100; rua=mailto:[email protected]; ruf=mailto:[email protected]
DNS Group DNS Status DNS Record Type DNS Data Information
WWW
INFO WWW A record Your WWW A record is:
www.Myshopify.com > shops.Myshopify.com. Resolved IP: 23.227.38.74
Your WWW is CNAME record and your CNAME entry returns A record which is good.
WA & DA Score for shops.Myshopify.com
PASS IPs are public OK. All of your WWW IP addresses appear to be public IP addresses.
PASS HTTP Service OK: We can connect to http service on port 80.
INFO Server http service on port 80 returns server information as
Cloudflare
PASS Server Header http response header returns information about server as:
Cloudflare
PASS Connection http connection header return connection as: Keep-alive
WARN Secure Header HSTS The server did not implement the HSTS (HTTP Strict Transport Security) policy. The header over the HTTPS connection was not found.
PASS Secure Header X-Frame-Options XFO response header that protects against clickjacking is found as: DENY
XFO enables content to be found or not within iframes via the browser.
PASS Secure Header X-Content-Type-Options The secure X-Content-Type-Options header is set as: Nosniff
The browser must interpret the file exactly as it is specified in the Content-Type HTTP header
PASS Secure Header Content-Security-Policy The return secure header sends feedback that the CSP has been found and specified. CSP is defined in the policy as: Frame-ancestors 'none';
CSP prevents various types of attacks, such as cross-site scripting and other types of cross-site injection
PASS Secure Header X-Permitted-Cross-Domain-Policies X-Permitted-Cross-Domain-Policies is found in the response header as: None
X-Permitted-Cross-Domain-Policies is an XML file that gives a web client permission to handle data across domains.
WARN Secure Header Referrer-Policy The Referrer-Policy HTTP header is not set, as it is not in the Referrer header.
INFO Secure Header Clear-Site-Data Clear-Site-Data was not found in the response header
INFO Secure Header Cross-Origin-Embedder-Policy COEP response header was not found in the HTTP request
INFO Secure Header Cross-Origin-Opener-Policy COOP response header was not found in the HTTP request
WARN Secure Header Cross-Origin-Resource-Policy CORP policy not found in response header
WARN Secure Header Cache-Control Cache-Control policy header not found in HTTP responses
WARN Secure Header Permissions-Policy Permissions-Policy header was not found in the HTTP responses.
INFO Secure Header Feature-Policy Feature-Policy header was not found in the HTTP responses.
PASS Secure Header X-XSS-Protection (Deprecated) X-XSS-Protection header is found in the HTTP response.as: 1; mode=block
X-XSS-Protection sets up a scripting filter in your browser.
INFO Secure Header HTTP Public Key Pinning (Deprecated) HPKP header was not found in the HTTP responses.
INFO Secure Header Expect-CT (Deprecated) Expect-CT header was not found in the HTTP responses.
PASS SSL / HTTPS Protocol Domain use encrypted SSL / HTTPS connection on port 443.
View SSL Certificate: Myshopify.com.
FAIL IPv6 Your domain has no IPv6 support

Click below to copy URL to clipboard for easy sharing of results: