| Parent | pass | NS records at parent servers | Your NS records at the parent servers are: inet2.telecel.com.py. inet3.telecel.com.py. [These were obtained from sce.cnc.una.py.] |
| warn | Glue at parent nameservers | WARNING. The parent servers (I checked withsce.cnc.una.py.) are not providing glue for all your nameservers. This means that they are supplying the NS records (host.example.com), but not supplying the A records That may cause some extra miliseconds in DNS. This will usually occur if your DNS servers are not in the same TLD as your domain | |
| NS | info | NS records at your nameservers | Your NS records at your nameservers are: At 200.85.32.2 inet3.telecel.com.py. [200.85.32.3 ] ns3.telecel.com.py. [200.85.32.4 ] inet2.telecel.com.py. [200.85.32.2 ] At 200.85.32.3 inet2.telecel.com.py. [200.85.32.2 ] inet3.telecel.com.py. [200.85.32.3 ] ns3.telecel.com.py. [200.85.32.4 ] |
| skip | Mismatched glue | Skip comparing the glue provided by the parent servers and that provided by your authoritative DNS servers, as root servers do not provide glue | |
| pass | No NS A records at nameservers | OK. Your nameservers do include corresponding A records when asked for your NS records. This ensures that your DNS servers know the A records corresponding to all your NS records. | |
| fail | All nameservers report identical NS records | ERROR. The NS records at all your nameservers are different, check the info above for details. | |
| pass | All nameservers respond | OK. All of your nameservers listed at the parent nameservers responded. | |
| pass | Nameserver name validity | OK. All of the NS records that your nameservers report seem valid (no IPs or partial domain names). | |
| pass | Number of nameservers | OK. You have 2 nameservers. You must have at least 2 nameservers (RFC2182 section 5 recommends at least 3 nameservers), and preferably no more than 7. | |
| pass | Lame nameservers | OK. All the nameservers listed at the parent servers answer authoritatively for your domain. | |
| fail | Missing (stealth) nameservers | ERROR: stealth nameservers (nameservers what does not exist at root servers , but exist at your nameservers) ns3.telecel.com.py. at inet2.telecel.com.py. [200.85.32.2] ns3.telecel.com.py. at inet3.telecel.com.py. [200.85.32.3] | |
| pass | Missing nameservers 2 | OK. All of the nameservers listed at the parent nameservers are also listed as NS records at your nameservers. | |
| fail | Nameservers on separate class C's | ERROR: some nameservers are in the same network inet2.telecel.com.py.[200.85.32.2] and inet3.telecel.com.py.[200.85.32.3] inet3.telecel.com.py.[200.85.32.3] and inet2.telecel.com.py.[200.85.32.2] | |
| pass | All NS IPs public | OK. All of your NS records appear to use public IPs. If there were any private IPs, they would not be reachable, causing DNS delays. | |
| SOA | info | SOA record | Your SOA record is: Primary nameserver: inet2.telecel.com.py. Hostmaster E-mail address: admin.inet2.telecel.com.py. Serial #: 2012081017 Refresh: 7200 Retry: 3600 Expire: 604800 Default TTL:10800 |
| pass | NS agreement on SOA Serial # | OK. All your nameservers agree that your SOA serial number is 2012081017. That means that all your nameservers are using the same data. | |
| pass | SOA MNAME Check | OK. Your SOA (Start of Authority) record states that your master (primary) name server is: inet2.telecel.com.py. That server is listed at the parent servers, which is correct. | |
| pass | SOA Serial Number | OK. Your SOA serial number is: 2012081017. This appears to be in the recommended format of YYYYMMDDnn, where 'nn' is the revision. This number must be incremented every time you make a DNS change. | |
| pass | SOA REFRESH value | Your SOA REFRESH interval is : 7200 seconds. This seems normal (about 3600-7200 seconds is good if not using DNS NOTIFY; RFC1912 2.2 recommends a value between 1200 to 43200 seconds (20 minutes to 12 hours)). This value determines how often secondary/slave nameservers check with the master for updates. | |
| pass | SOA RETRY value | Your SOA RETRY interval is : 3600 seconds. This seems normal (about 120-7200 seconds is good). The retry value is the amount of time your secondary/slave nameservers will wait to contact the master nameserver again if the last attempt failed. | |
| pass | SOA EXPIRE value | Your SOA EXPIRE time is : 604800 seconds. This seems normal (about 1209600 to 2419200 seconds (2-4 weeks) is good). RFC1912 suggests 2-4 weeks. This is how long a secondary/slave nameserver will wait before considering its DNS data stale if it can't reach the primary nameserver. | |
| pass | SOA MINIMUM TTL value | Your SOA MINIMUM TTL is : 10800 seconds. This seems normal (about 3,600 to 86400 seconds or 1-24 hours is good). RFC2308 suggests a value of 1-3 hours. This value used to determine the default (technically, minimum) TTL (time-to-live) for DNS entries, but now is used for negative caching. | |