DNS & IP Record Check for Tsohost.com

This tool gives you a detailed look at Tsohost.com DNS setup. It checks various parts of the DNS records to ensure everything is functioning smoothly and securely.

DNS Record Group Breakdown:

Our DNS & IP record check is organized into 6 main groups, each focusing on different aspects of your domain's DNS configuration. Each group tests key components to ensure optimal domain performance:

  1. DNS Parent Group - 5 tests
  2. NS (Nameserver) - 17 tests
  3. SOA (Start of Authority) - 9 tests
  4. MX (Mail Exchanger) - 12 tests
  5. MAIL (Email) - 4 tests
  6. WWW (World Wide Web) - 24 tests
Test Status Summary:

To help you better understand the results, our team has categorized the outcomes into four statuses:

  1. PASS - No issues found in the DNS record.
  2. FAIL - We detected a DNS record error that needs your attention.
  3. WARN - A minor DNS record issue was found.
  4. INFO - Informational data about the DNS record with no errors detected.

To ensure the integrity and security of Tsohost.com DNS data, use our DNSSEC check tool. This test provides a deeper analysis, focusing on digital signatures, security, and integrity of the DNS records.


Below is an overview of the results from our comprehensive DNS lookup for the domain Tsohost.com:

DNS Group DNS Check DNS Record Type DNS Data Information
PARENT
PASS Missing Direct Parent check OK. Your direct parent zone exists, SOA of parent zone com is a.gtld-servers.net which is good. Some domains (usually third or fourth level domains, such as example.co.us or subdomain.example.co.us) do not have a direct parent zone ('co.us' in this example), which is legal but can cause confusion.
FAIL Glue at parent nameservers The parent servers do not have glue for your nameserversa9-67.akam.net, a8-67.akam.net, a1-245.akam.net, a20-65.akam.net, a11-64.akam.net, a6-66.akam.net
INFO NS records at parent servers Your NS record at parent servers are:
a9-67.akam.net
a8-67.akam.net
a1-245.akam.net
a20-65.akam.net
a11-64.akam.net
a6-66.akam.net

These were obtained from a.gtld-servers.net. However these were obtained from authority section and not answer section. It is better if they were obtained from answer section.
PASS DNS servers have A records OK. All your DNS servers either have A records at the zone parent servers
FAIL Parent nameservers have your nameservers listed Your nameservers not listed in parent servers: cns4.secureserver.net, cns3.secureserver.net
DNS Group DNS Status DNS Record Type DNS Data Information
NS
INFO NS records at your nameservers Your NS records at your nameservers are:
cns3.secureserver.net[TTL=600]
cns4.secureserver.net[TTL=600]
PASS Mismatched NS records OK. NS records at all your nameservers are identical.
PASS All nameservers respond All your nameservers responding.
PASS Recursive queries None of your nameservers allow recursive queries
PASS Zone Transfer Zone transfer not allowed by any of your nameservers
PASS No NS A records at nameservers OK. Your nameservers do include corresponding A records when asked for your NS records. This ensures that your DNS servers know the A records corresponding to all your NS records.
PASS Nameserver name validity OK. All of the NS records that your nameservers report seem valid (no IPs or partial domain names).
PASS Number of nameservers You have 6 nameservers. You must have at least 2 nameservers (RFC2182 section 5 recommends at least 3 nameservers), and preferably no more than 7.
PASS Lame nameservers OK. All the nameservers listed at the parent servers answer authoritatively for your domain.
FAIL Missing (stealth) nameservers FAIL: You have one or more missing (stealth) nameservers. The following nameserver(s) are listed (at your nameservers) as nameservers for your domain, but are not listed at the parent nameservers (therefore, they may or may not get used, depending on whether your DNS servers return them in the authority section for other requests, per RFC2181 5.4.1). You need to make sure that these stealth nameservers are working; if they are not responding, you may have serious problems! The report will not query these servers, so you need to be very careful that they are working properly.
cns3.secureserver.net
cns4.secureserver.net
FAIL Missing nameservers 2 ERROR: One or more of the nameservers listed at the parent servers are not listed as NS records at your nameservers. The problem NS records are:
a9-67.akam.net, a8-67.akam.net, a1-245.akam.net, a20-65.akam.net, a11-64.akam.net, a6-66.akam.net
PASS Same Glue The A records (the GLUE) got from the parent zone check are the same as the ones got from your nameservers. You have to make sure your parent server has the same NS records for your zone as you do according to the RFC. This DNS record tests only nameservers that are common at the parent and at your nameservers.
PASS No CNAMEs for domain OK. There are no CNAMEs for Tsohost.com. RFC1912 2.4 and RFC2181 10.3 state that there should be no CNAMEs if an NS (or any other) record is present.
PASS TCP Allowed All your nameservers allow TCP connection
PASS Stealth NS record leakage Your DNS servers doesn't leak NS record in non-NS request.
PASS Nameservers on separate class C's OK. You have nameservers on different Class C (technically, /24) IP ranges. You must have nameservers at geographically and topologically dispersed locations. RFC2182 3.1 goes into more detail about secondary nameserver location.
PASS All NS IPs public OK. All of your NS records appear to use public IPs. If there were any private IPs, they would not be reachable, causing DNS delays.
FAIL Glue for NS record Your nameservers for your NS records didn't return the A records for the NS records.
DNS Group DNS Status DNS Record Type DNS Data Information
SOA
INFO SOA record Your SOA record [TTL=600] is:
Primary Name server: cns3.secureserver.net
Hostmaster E-mail address: domains.tsohost.co.uk
Serial #:2025031101
Refresh: 7200
Retry: 7200
Expire: 360000
Default: 1800
FAIL SOA MNAME entry SOA MNAME cns3.secureserver.net is not listed as a primary nameserver at your parent nameserver
PASS SOA RNAME entry OK. Your SOA (Start of Authority) record states that your DNS contact E-mail address is: [email protected] (techie note: we have changed the initial '.' to an '@' for display purposes).
PASS NS agreement on SOA Serial # OK. All your nameservers agree that your SOA serial number is 2009050102. That means that all your nameservers are using the same data (unless you have different sets of data with the same serial number, which would be very bad)! Note that the DNS report only checks the NS records listed at the parent servers (not any stealth servers).
PASS SOA Serial Your SOA serial number is: 2025031101. This appears to be in the recommended format of YYYYMMDDnn.
INFO SOA REFRESH OK. Your SOA REFRESH interval is: 7200. RFC 1912 recommends 1200 to 43200 seconds, low (1200) if the data is volatile or 43200 (12 hours) if it's not. If you are using NOTIFY you can set for much higher values, for instance, 1 or more days (> 86400 seconds).
WARN SOA RETRY OK. Your SOA RETRY interval is: 7200. Typical values would be 180 (3 minutes) to 900 (15 minutes) or higher.
WARN SOA EXPIRE OK. Your SOA EXPIRE interval is: 360000 .RFC 1912 recommends 1209600 to 2419200 seconds (2-4 weeks) to allow for major outages of the zone master.
PASS SOA MINIMUM TTL OK. Your SOA MINIMUM TTL is: 1800. That is OK
DNS Group DNS Status DNS Record Type DNS Data Information
MX
FAIL MX Glue MX record look up did not send glue record for atleast 1 MX server:
tsohost-com.mail.protection.outlook.com
PASS MX records are not CNAMEs OK. Looking up your MX record did not just return a CNAME. If an MX record query returns a CNAME, extra processing is required, and some mail servers may not be able to handle it.
PASS MX name validity Good. We did not detect any invalid chars in hostnames for your MX records.
PASS MX is host name, not IP OK. All of your MX records are host names (as opposed to IP addresses, which are not allowed in MX records).
PASS Different MX records at nameservers Good. Looks like all your nameservers have the same set of MX records. This tests to see if there are any MX records not reported by all your nameservers
FAIL MX Glues match MX Glue returned by nameserver for MX record doesn't match with A record of MX hostname
tsohost-com.mail.protection.outlook.com > 52.101.11.15;///// X
PASS Duplicate MX records OK. You do not have any duplicate MX records (pointing to the same IP). Although technically valid, duplicate MX records can cause a lot of confusion, and waste resources.
PASS MX A lookups have no CNAMEs OK. There appear to be no CNAMEs returned for A records lookups from your MX records (CNAMEs are prohibited in MX records, according to RFC974, RFC1034 3.6.2, RFC1912 2.4, and RFC2181 10.3).
INFO MX Record Your 1 records:
0    tsohost-com.mail.protection.outlook.com    [IP Address=52.101.11.15]  [TTL=600]
FAIL Multiple MX records You need to have multiple MX records so that if one is down or unreachable, the other(s) will be able to accept mail for you.
PASS Reverse MX A records (PTR) The reverse (PTR) record for your MX records:
52.101.11.15 -> mail-sa9pr02cu00207.inbound.protection.outlook.com
PASS All MX IPs public OK. All of your MX records appear to use public IPs. If there were any private IPs, they would not be reachable, causing slight mail delays, extra resource usage, and possibly bounced mail.
DNS Group DNS Status DNS Record Type DNS Data Information
MAIL
PASS SPF record v6dne7adu53j76hfo4uisoedfj
facebook-domain-verification=vdbgsh92tvt56mscuvu91us1a3s2ws
5fe870ab-e98b-4578-8c3b-a8c86c1e676c
guqilvm3ms2sog68kak1i6694h
MS=ms43314156
google-site-verification=jzjzsGf50uTIBFVI0VcVYeZd7pRhK7HBJMAWYKddvD8
hagjh5jti1m47ctgum1vkkbji4
MS=ms98363338
v=spf1 a mx include:cmail1.com include:spf.em.secureserver.net ip4:185.52.25.1 ip4:185.24.99.18 ip4:195.62.28.35 ip4:195.62.28.191 ip4:188.65.118.131 include:spf.protection.outlook.com -all
okk308ipikp84fs1fqhae6g7ai
0admlliy75lkobaefbtpqfufqf2tepnj
this domain sends email from following domains/subdomains:cmail1.com, spf.em.secureserver.net, spf.protection.outlook.com
domain sends mail through its MX servers
this domain is used to send mail
this domain sends email from following IP/Range: 185.52.25.1, 185.24.99.18, 195.62.28.35, 195.62.28.191, 188.65.118.131
WARN Sender ID record(spfv2.0) SenderID framework not implemented
PASS Domain Key Test o=~
The interim sending domain policy
this domain may sign some email with DomainKeys available under selectors
  • The public key certificate is not tested
  • Separate domainkey records may exist for subdomains and selectors under this domain. this cannot be tested.
  • PASS DMARC v=DMARC1;p=reject;sp=none;adkim=r;aspf=r;pct=100;fo=1;rf=afrf;ri=7200;rua=mailto:[email protected];ruf=mailto:[email protected]
    DNS Group DNS Status DNS Record Type DNS Data Information
    WWW
    INFO WWW A record Your WWW A record is:
    www.Tsohost.com. Resolved IP: 23.34.205.232
    You have separate A record for www.
    WA & DA Score for www.Tsohost.com
    PASS IPs are public OK. All of your WWW IP addresses appear to be public IP addresses.
    PASS HTTP Service OK: We can connect to http service on port 80.
    FAIL Server http service on port 80 didn't return server information.
    INFO Server Header http response header didn't return any server information
    INFO Connection http connection header didn't return any information about HTTP connection
    WARN Secure Header HSTS The server did not implement the HSTS (HTTP Strict Transport Security) policy. The header over the HTTPS connection was not found.
    WARN Secure Header X-Frame-Options XFO clickjacking protection response header was not found. XFO enables content to be found or not within iframes via the browser.
    WARN Secure Header X-Content-Type-Options The X-Content-Type-Options secure header is not set
    WARN Secure Header Content-Security-Policy CSP is not defined in the policy. The return secure header does not send any feedback that the CSP has been set
    WARN Secure Header X-Permitted-Cross-Domain-Policies X-Permitted-Cross-Domain-Policies was not found in the response header
    WARN Secure Header Referrer-Policy The Referrer-Policy HTTP header is not set, as it is not in the Referrer header.
    INFO Secure Header Clear-Site-Data Clear-Site-Data was not found in the response header
    INFO Secure Header Cross-Origin-Embedder-Policy COEP response header was not found in the HTTP request
    INFO Secure Header Cross-Origin-Opener-Policy COOP response header was not found in the HTTP request
    WARN Secure Header Cross-Origin-Resource-Policy CORP policy not found in response header
    WARN Secure Header Cache-Control Cache-Control policy header not found in HTTP responses
    WARN Secure Header Permissions-Policy Permissions-Policy header was not found in the HTTP responses.
    INFO Secure Header Feature-Policy Feature-Policy header was not found in the HTTP responses.
    INFO Secure Header X-XSS-Protection (Deprecated) X-XSS-Protection header was not found in the HTTP responses.
    INFO Secure Header HTTP Public Key Pinning (Deprecated) HPKP header was not found in the HTTP responses.
    INFO Secure Header Expect-CT (Deprecated) Expect-CT header was not found in the HTTP responses.
    PASS SSL / HTTPS Protocol Domain use encrypted SSL / HTTPS connection on port 443.
    View SSL Certificate: Tsohost.com.
    INFO IPv6 Your domain has IPv6 support.
    IPv6 address is: 2600:1403:c400:1386::2146

    Click below to copy URL to clipboard for easy sharing of results: