DNSSEC Check Record: Ans3.hinet.tw

Let's check if the DNSSEC extension is enabled for the domain Ans3.hinet.tw by reviewing all zones, record types, counts, and propagation times. The test is fast, reliable, and concise.

If you are the domain owner of Ans3.hinet.tw and haven't enabled DNSSEC yet, now is the perfect time to do so and protect your domain from hijacking, spoofing, hackers and create an extra layer of cyber security.




Website Server Overview
Website: Ans3.hinet.tw
Server IP: 34.81.176.250
Resolved Hostname: 250.176.81.34.bc.googleusercontent.com
Domain Extension:tw

Website Server Location
DNSSEC

-------------------------------------------

Zone: (Root zone) - 0.01 seconds
Record TypeCountDetails
DNSKEY ❌0None
DS ✔️1iS0lhSHkmT9fMJlz+TH8JOQ9JOewrg/B84eGyGxLdSM6
RRSIG ✔️3. 83578 IN NSEC aaa. NS SOA RRSIG NSEC DNSKEY TYPE63
. 83578 IN RRSIG SOA 8 0 86400 20250706170000 (
. 83578 IN RRSIG NSEC 8 0 86400 20250706170000 (
NSEC ✔️2. 83578 IN NSEC aaa. NS SOA RRSIG NSEC DNSKEY TYPE63
. 83578 IN RRSIG NSEC 8 0 86400 20250706170000 (
NSEC3 ❌0None
Delegation is secure with DS records.
RRSIG Analysis:
Latest Expiration: 2025-07-06 17:00:00
DNSSEC is active for this zone.

-------------------------------------------

Zone: tw (TLD) - 0.16 seconds
Record TypeCountDetails
DNSKEY ❌0None
DS ✔️16mdWmVhzUahI9ezKUCb2+o7ASH0NDt+Aeka/+jVl7dSl
RRSIG ✔️35CS12GGF7OBDDUPJP7K0D74HG6IU0G5U.tw. 900 IN NSEC3 1 1 0 - 5CV5H40UUKARFGRHOJ6NC0PRVF3J5I8E NS SOA RRSIG DNSKEY NSEC3PARAM
tw. 900 IN RRSIG SOA 8 1 900 20250723185457 (
5CS12GGF7OBDDUPJP7K0D74HG6IU0G5U.tw. 900 IN RRSIG NSEC3 8 2 900 20250723170107 (
NSEC ❌0None
NSEC3 ✔️25CS12GGF7OBDDUPJP7K0D74HG6IU0G5U.tw. 900 IN NSEC3 1 1 0 - 5CV5H40UUKARFGRHOJ6NC0PRVF3J5I8E NS SOA RRSIG DNSKEY NSEC3PARAM
5CS12GGF7OBDDUPJP7K0D74HG6IU0G5U.tw. 900 IN RRSIG NSEC3 8 2 900 20250723170107 (
Delegation is secure with DS records.
RRSIG Analysis:
Latest Expiration: 2025-07-23 18:54:57
DNSSEC is active for this zone.

-------------------------------------------

Zone: Ans3.hinet.tw (Domain) - 0.42 seconds
Record TypeCountDetails
DNSKEY ❌0None
DS ❌0None
RRSIG ✔️1Ans3.hinet.tw. 181 IN RRSIG A 8 3 600 20250801000000 (
NSEC ❌0None
NSEC3 ❌0None
No delegation security found.
RRSIG Analysis:
Latest Expiration: 2025-08-01 00:00:00
DNSSEC is active for this zone.
-------------------------------------------
Propagation Time for Each Zone (in seconds):
  • (Root zone) - 0.01 seconds
  • tw: 0.16 seconds
  • Ans3.hinet.tw: 0.42 seconds
Global Conclusion: DNSSEC is enabled at the domain level.
DNSSEC Elements Legend:
  1. DNSKEY (DNS Key Record)
    • Contains the public key used to verify the signed DNS records.
    • Forms the foundation for verifying the authenticity of data in the DNSSEC system.
  2. DS (Delegation Signer Record)
    • Links subdomains to the parent domain.
    • Used to transfer the cryptographic chain of trust between the parent and child DNS zones.
  3. RRSIG (Resource Record Signature)
    • A digital signature for a specific DNS record.
    • Ensures the record has not been altered during transit and allows authenticity verification.
  4. NSEC (Next Secure Record)
    • Verifies that a specific record does not exist in the DNS zone.
    • Lists the next records in the zone file, ensuring integrity verification.
  5. NSEC3 (Next Secure Record, Version 3)
    • An improved version of NSEC that uses hash values to hide record names.
    • Offers improved privacy while enabling verification of missing records.