The parent servers are not providing glue for all your nameservers. This means that they are supplying the NS records (host.example.com), but not supplying the A records.
That may cause some extra milliseconds in DNS. This will usually occur if your DNS servers are not in the same TLD as your domain
Skip glue checking. Make sure the nameservers domain is good standing
Nameservers A records
Nameservers do include corresponding A records when asked for your NS records. This ensures that your DNS servers know the A records corresponding to all your NS records.
Nameservers report identical NS records
The NS records at all your nameservers are identical.
All of your nameservers listed at the parent nameservers responded.
Nameserver name validity
All of the NS records that your nameservers report are valid (no IPs or partial domain names).
Number of nameservers
You have 2 nameservers. You must have at least 2 nameservers (RFC2182 section 5 recommends at least 3 nameservers), and preferably no more than 7.
Missing (stealth) nameservers
All your nameservers are also listed at the parent servers.
Root missing nameservers
There are nameservers not listed at your nameservers:
Nameservers on separate class C's
Nameservers are in a different networks.
All of your NS records appear to use public IPs.
SOA record is:
All your nameservers agree that your SOA serial number is That means that all your nameservers are using the same data.
SOA (Start of Authority) record states that your master (primary) name server is: , but that server is not listed at the parent servers.
SOA serial number is: This not appears to be in the recommended format of YYYYMMDDnn, where 'nn' is the revision. This number must be incremented every time you make a DNS change.
SOA Retry interval is : seconds. This seems too small. (Values about 3600-7200 seconds is good if not using DNS NOTIFY; RFC1912 2.2 recommends a value between 1200 to 43200 seconds (20 minutes to 12 hours)). This value determines how often secondary/slave nameservers check with the master for updates.
SOA Retry interval is : seconds. This seems too small. (Values about 120-7200 seconds is good). The retry value is the amount of time your secondary/slave nameservers will wait to contact the master nameserver again if the last attempt failed.
SOA Expire time is : seconds. This seems too small. (Values 604800 to 2419200 seconds (1-4 weeks) is good). RFC1912 suggests 2-4 weeks. This is how long a secondary/slave nameserver will wait before considering its DNS data stale if it can't reach the primary nameserver.
SOA Expire time is : seconds. This seems too small. (about 300 to 86400 seconds or 5 min - 24 hours is good). RFC2308 suggests a value of 1-3 hours. This value used to determine the default (technically, minimum) TTL (time-to-live) for DNS entries, but now is used for negative caching.
Trace to cloudcom.ca
lookup cloudcom.ca at A.ROOT-SERVERS.NET(22.214.171.124) 76 ms
A.ROOT-SERVERS.NET(126.96.36.199) refer to any.ca-servers.ca(188.8.131.52)
lookup cloudcom.ca at any.ca-servers.ca(184.108.40.206) 14 ms
any.ca-servers.ca(220.127.116.11) refer to ns2.domainbrothers.com(unknow IP)
extra IP lookup for ns2.domainbrothers.com at root server A.ROOT-SERVERS.NET(18.104.22.168)
lookup ns2.domainbrothers.com at A.ROOT-SERVERS.NET(22.214.171.124) 77 ms
A.ROOT-SERVERS.NET(126.96.36.199) refer to a.gtld-servers.net(188.8.131.52)
lookup ns2.domainbrothers.com at a.gtld-servers.net(184.108.40.206) 80 ms
a.gtld-servers.net(220.127.116.11) refer to ns3.netcluescloud.com(18.104.22.168)
lookup ns2.domainbrothers.com at ns3.netcluescloud.com(22.214.171.124) 54 ms
got A record 'ns2.domainbrothers.com IN A 126.96.36.199' from ns2.domainbrothers.com(188.8.131.52)
lookup cloudcom.ca at ns2.domainbrothers.com(184.108.40.206) 2 ms
got A record 'cloudcom.ca IN A 220.127.116.11' from cloudcom.ca(18.104.22.168)