Parent nameservers know A records for your domain, Very good !
The glue provided by the root servers does not match glue that provided by your authoritative DNS servers.
(ns1.zonerisq.ca. 86400 IN A 188.8.131.52) present at Parent, missing at (184.108.40.206, 220.127.116.11)
(ns2.zonerisq.ca. 86400 IN A 18.104.22.168) present at Parent, missing at (22.214.171.124, 126.96.36.199)
Nameservers A records
Some servers does not provide A records for nameservers.
missing A record(s) for (ns1.zonerisq.ca,ns2.zonerisq.ca) at nameserver 188.8.131.52
missing A record(s) for (ns2.zonerisq.ca,ns1.zonerisq.ca) at nameserver 184.108.40.206
Nameservers report identical NS records
The NS records at all your nameservers are identical.
Some nameservers does not respond:
Nameserver name validity
All of the NS records that your nameservers report are valid (no IPs or partial domain names).
Number of nameservers
You have 4 nameservers. You must have at least 2 nameservers (RFC2182 section 5 recommends at least 3 nameservers), and preferably no more than 7.
All the nameservers listed at the parent servers answer authoritatively for your domain.
Missing (stealth) nameservers
All your nameservers are also listed at the parent servers.
Root missing nameservers
All of the nameservers listed at the parent nameservers are also listed as NS records at your nameservers.
Nameservers on separate class C's
Nameservers are in a different networks.
All of your NS records appear to use public IPs.
SOA record is:
All your nameservers agree that your SOA serial number is 2016071567 That means that all your nameservers are using the same data.
SOA (Start of Authority) record states that your master (primary) name server is: dns1.crim.ca That server is listed at the parent servers, which is correct.
SOA serial number is: 2016071567 This appears to be in the recommended format of YYYYMMDDnn, where 'nn' is the revision. This number must be incremented every time you make a DNS change.
SOA Retry interval is : 10800 seconds. This seems OK. (Values about 3600-7200 seconds is good if not using DNS NOTIFY; RFC1912 2.2 recommends a value between 1200 to 43200 seconds (20 minutes to 12 hours)). This value determines how often secondary/slave nameservers check with the master for updates.
SOA Retry interval is : 900 seconds. This seems OK. (Values about 120-7200 seconds is good). The retry value is the amount of time your secondary/slave nameservers will wait to contact the master nameserver again if the last attempt failed.
SOA Expire time is : 604800 seconds. This seems OK. (Values 604800 to 2419200 seconds (1-4 weeks) is good). RFC1912 suggests 2-4 weeks. This is how long a secondary/slave nameserver will wait before considering its DNS data stale if it can't reach the primary nameserver.
SOA Expire time is : 300 seconds. This seems OK. (about 300 to 86400 seconds or 5 min - 24 hours is good). RFC2308 suggests a value of 1-3 hours. This value used to determine the default (technically, minimum) TTL (time-to-live) for DNS entries, but now is used for negative caching.
Trace to crim.ca
lookup crim.ca at A.ROOT-SERVERS.NET(220.127.116.11) 7 ms
A.ROOT-SERVERS.NET(18.104.22.168) refer to c.ca-servers.ca(22.214.171.124)
lookup crim.ca at c.ca-servers.ca(126.96.36.199) 69 ms
c.ca-servers.ca(188.8.131.52) refer to dns1.crim.ca(184.108.40.206)
lookup crim.ca at dns1.crim.ca(220.127.116.11) 12 ms
got A record 'crim.ca IN A 18.104.22.168' from crim.ca(22.214.171.124)