DNSSEC Check Record: Ads.ma

Let's check if the DNSSEC extension is enabled for the domain Ads.ma by reviewing all zones, record types, counts, and propagation times. The test is fast, reliable, and concise.

If you are the domain owner of Ads.ma and haven't enabled DNSSEC yet, now is the perfect time to do so and protect your domain from hijacking, spoofing, hackers and create an extra layer of cyber security.




Website Server Overview
Website: Ads.ma
Server IP: 192.64.117.14
Resolved Hostname: server316-2.web-hosting.com
Domain Extension:ma

Website Server Location
DNSSEC

-------------------------------------------

Zone: (Root zone) - 0.02 seconds
Record TypeCountDetails
DNSKEY ❌0None
DS ✔️1LFDse2BFkSU6QDK+fZv6J4v/DRE62zXIGpIZeJC2dlC2
RRSIG ✔️3. 84424 IN NSEC aaa. NS SOA RRSIG NSEC DNSKEY TYPE63
. 84424 IN RRSIG SOA 8 0 86400 20250707170000 (
. 84424 IN RRSIG NSEC 8 0 86400 20250707170000 (
NSEC ✔️2. 84424 IN NSEC aaa. NS SOA RRSIG NSEC DNSKEY TYPE63
. 84424 IN RRSIG NSEC 8 0 86400 20250707170000 (
NSEC3 ❌0None
Delegation is secure with DS records.
RRSIG Analysis:
Latest Expiration: 2025-07-07 17:00:00
DNSSEC is active for this zone.

-------------------------------------------

Zone: ma (TLD) - 0.15 seconds
Record TypeCountDetails
DNSKEY ❌0None
DS ✔️190 ; retry (1 minute 30 seconds)
RRSIG ✔️3T2MFQMQET91K45F6A2FA51DNK7H4TKDT.ma. 1800 IN NSEC3 1 0 10 55AB T2MGQVVOFPSN403H4CM287580NII6F42 NS SOA RRSIG DNSKEY NSEC3PARAM
ma. 1800 IN RRSIG SOA 8 1 108000 20250724195325 (
T2MFQMQET91K45F6A2FA51DNK7H4TKDT.ma. 1800 IN RRSIG NSEC3 8 2 1800 20250724041017 (
NSEC ❌0None
NSEC3 ✔️2T2MFQMQET91K45F6A2FA51DNK7H4TKDT.ma. 1800 IN NSEC3 1 0 10 55AB T2MGQVVOFPSN403H4CM287580NII6F42 NS SOA RRSIG DNSKEY NSEC3PARAM
T2MFQMQET91K45F6A2FA51DNK7H4TKDT.ma. 1800 IN RRSIG NSEC3 8 2 1800 20250724041017 (
Delegation is secure with DS records.
RRSIG Analysis:
Latest Expiration: 2025-07-24 19:53:25
DNSSEC is active for this zone.

-------------------------------------------

Zone: Ads.ma (Domain) - 1.32 seconds
Record TypeCountDetails
DNSKEY ❌0None
DS ✔️3; <<>> DiG 9.8.2rc1-RedHat-9.8.2-0.68.rc1.el6_10.8 <<>> +dnssec +multi Ads.ma
;Ads.ma. IN A
Ads.ma. 86400 IN A 192.64.117.14
RRSIG ❌0None
NSEC ❌0None
NSEC3 ❌0None
Delegation is secure with DS records.
DNSSEC is active for this zone.
-------------------------------------------
Propagation Time for Each Zone (in seconds):
  • (Root zone) - 0.02 seconds
  • ma: 0.15 seconds
  • Ads.ma: 1.32 seconds
Global Conclusion: DNSSEC is enabled at the domain level.
DNSSEC Elements Legend:
  1. DNSKEY (DNS Key Record)
    • Contains the public key used to verify the signed DNS records.
    • Forms the foundation for verifying the authenticity of data in the DNSSEC system.
  2. DS (Delegation Signer Record)
    • Links subdomains to the parent domain.
    • Used to transfer the cryptographic chain of trust between the parent and child DNS zones.
  3. RRSIG (Resource Record Signature)
    • A digital signature for a specific DNS record.
    • Ensures the record has not been altered during transit and allows authenticity verification.
  4. NSEC (Next Secure Record)
    • Verifies that a specific record does not exist in the DNS zone.
    • Lists the next records in the zone file, ensuring integrity verification.
  5. NSEC3 (Next Secure Record, Version 3)
    • An improved version of NSEC that uses hash values to hide record names.
    • Offers improved privacy while enabling verification of missing records.