Parent nameservers know A records for your domain, Very good !
The glue provided by the root servers does not match glue that provided by your authoritative DNS servers.
(ns1.l3.net. 172800 IN A 126.96.36.199) present at Parent, missing at (188.8.131.52, 184.108.40.206)
(ns2.l3.net. 172800 IN A 220.127.116.11) present at Parent, missing at (18.104.22.168, 22.214.171.124)
Nameservers A records
Some servers does not provide A records for nameservers.
missing A record(s) for (ns2.Level3.net,ns1.Level3.net) at nameserver 126.96.36.199
missing A record(s) for (ns1.Level3.net,ns2.Level3.net) at nameserver 188.8.131.52
Nameservers report identical NS records
The NS records at all your nameservers are identical.
All of your nameservers listed at the parent nameservers responded.
Nameserver name validity
All of the NS records that your nameservers report are valid (no IPs or partial domain names).
Number of nameservers
You have 2 nameservers. You must have at least 2 nameservers (RFC2182 section 5 recommends at least 3 nameservers), and preferably no more than 7.
All the nameservers listed at the parent servers answer authoritatively for your domain.
Missing (stealth) nameservers
There are nameservers not listed at the parent servers:
Root missing nameservers
There are nameservers not listed at your nameservers:
Nameservers on separate class C's
Nameservers are in a different networks.
All of your NS records appear to use public IPs.
SOA record is:
Some nameservers have a different soa serial number That can occur because of recent master update (slave have not loaded master zone yet) or the is a problem in DNS.
There is serial 2017071902 at nameserver(s) (184.108.40.206)
There is serial 2017071702 at nameserver(s) (220.127.116.11)
SOA (Start of Authority) record states that your master (primary) name server is: ns2.Level3.net, but that server is not listed at the parent servers.
SOA serial number is: 2017071902 This appears to be in the recommended format of YYYYMMDDnn, where 'nn' is the revision. This number must be incremented every time you make a DNS change.
SOA Retry interval is : 7200 seconds. This seems OK. (Values about 3600-7200 seconds is good if not using DNS NOTIFY; RFC1912 2.2 recommends a value between 1200 to 43200 seconds (20 minutes to 12 hours)). This value determines how often secondary/slave nameservers check with the master for updates.
SOA Retry interval is : 600 seconds. This seems OK. (Values about 120-7200 seconds is good). The retry value is the amount of time your secondary/slave nameservers will wait to contact the master nameserver again if the last attempt failed.
SOA Expire time is : 2592000 seconds. This seems too big;. (Values 604800 to 2419200 seconds (1-4 weeks) is good). RFC1912 suggests 2-4 weeks. This is how long a secondary/slave nameserver will wait before considering its DNS data stale if it can't reach the primary nameserver.
SOA Expire time is : 3600 seconds. This seems OK. (about 300 to 86400 seconds or 5 min - 24 hours is good). RFC2308 suggests a value of 1-3 hours. This value used to determine the default (technically, minimum) TTL (time-to-live) for DNS entries, but now is used for negative caching.
Trace to level3.net
lookup level3.net at A.ROOT-SERVERS.NET(18.104.22.168) 5 ms
A.ROOT-SERVERS.NET(22.214.171.124) refer to e.gtld-servers.net(126.96.36.199)
lookup level3.net at e.gtld-servers.net(188.8.131.52) 10 ms
e.gtld-servers.net(184.108.40.206) refer to ns1.l3.net(220.127.116.11)
lookup level3.net at ns1.l3.net(18.104.22.168) 2 ms