login.do
checked 2026-09-19 12:22 UTC · 5.56 s of live queries
Health score
Re-check now Propagation All records Blocklists Check guide
Parent zone and delegation
5 checksWhat the registry for .do publishes about your domain.
-
OK
Parent name servers
The .do registry answered from a.lactld.org (200.0.68.10). explain
a.lactld.org 200.0.68.10 ns.nic.do 190.113.72.177 ns1.nic.do 190.113.72.178 ns2.nic.do 190.113.65.12
-
OK
Delegation at the registry
The registry delegates the domain to 2 name server(s). explain
3433.ns1.above.com 3433.ns2.above.com
-
OK
Number of name servers
2 name servers are delegated, which is a healthy number. explain
-
Info
Glue records
All name servers are outside this zone, so no glue record is needed. explain
-
Warning
Registry and zone agree
The NS records at the registry differ from the NS records published by your own servers. Both lists should be identical. explain
Only at the registry: 3433.ns1.above.com, 3433.ns2.above.com Only in the zone: ns1.abovedomains.com, ns2.abovedomains.com
Name servers
12 checksDirect queries sent to every authoritative server of the zone.
-
Info
Answering servers
4 authoritative servers were queried directly over UDP. explain
Name server Addresses Response Serial Authoritative Answers 3433.ns1.above.com 103.224.182.77, 103.224.182.9, 103.224.212.9 3003.3 ms - ✕ ✕ 3433.ns2.above.com 103.224.182.10, 103.224.212.10, 103.224.212.51 67.1 ms 2026091901 ✓ ✓ ns1.abovedomains.com 103.224.182.77, 103.224.182.85, 103.224.182.9, 103.224.212.9 3003.3 ms - ✕ ✕ ns2.abovedomains.com 103.224.182.10, 103.224.212.10, 103.224.212.51, 103.224.212.53 66.9 ms 2026091901 ✓ ✓ -
Error
All name servers respond
2 name server(s) did not answer a direct query. Every delegated server must answer, otherwise a share of your visitors gets a timeout. explain
3433.ns1.above.com (103.224.182.77, 103.224.182.9, 103.224.212.9): Timeout ns1.abovedomains.com (103.224.182.77, 103.224.182.85, 103.224.182.9, 103.224.212.9): Timeout
-
OK
Authoritative answers
Every server answers authoritatively for the zone. explain
-
OK
SOA serial is in sync
All name servers report the same serial number (2026091901). explain
-
OK
NS records are identical
Every server publishes the same NS record set. explain
-
OK
Recursion is disabled
No name server offers open recursion to the internet. explain
-
OK
DNS over TCP
Every name server also answers over TCP. explain
-
Warning
EDNS(0) support
These servers ignore EDNS(0), which limits answer size and blocks DNSSEC: 3433.ns2.above.com, ns2.abovedomains.com explain
-
OK
Network diversity
Name servers are spread over 2 different networks. explain
-
Warning
IPv6 reachable name servers
No name server has an AAAA record. IPv6-only clients and networks will depend on a translator to resolve your domain. explain
-
Warning
Response time
The slowest name server took 3003.3 ms to answer (average 1535.2 ms). explain
-
Info
Reverse DNS of the name servers
Reverse names resolved for the servers. explain
3433.ns2.above.com: ns2.above.com ns2.abovedomains.com: ns2.above.com
SOA record
9 checksThe Start Of Authority record and its timers.
-
OK
SOA record exists
The zone publishes a SOA record. explain
ns1.abovedomains.com. hostmaster.trellian.com. 2026091901 10800 3600 604800 3600
-
OK
Primary server (MNAME)
The SOA points at ns1.abovedomains.com, which is one of the delegated name servers. explain
-
OK
Zone contact (RNAME)
Zone contact: hostmaster@trellian.com explain
-
OK
Serial number
The serial 2026091901 follows the recommended YYYYMMDDnn format. explain
-
OK
Refresh
Refresh is 3h, inside the recommended range. explain
-
OK
Retry
Retry is 1h, inside the recommended range. explain
-
Warning
Expire
Expire is 7d, below the recommended minimum of 14d. explain
-
OK
Minimum TTL (negative caching)
Minimum TTL (negative caching) is 1h, inside the recommended range. explain
-
OK
TTL values
Record TTLs are in a sensible range. explain
Record TTL (s) Duration NS 86400 1d A 3600 1h MX 3600 1h SOA 3600 1h
Web and address records
7 checksThe records a browser needs to open your site.
- OK
-
OK
No CNAME at the zone apex
The zone apex correctly has no CNAME record. explain
- OK
-
Warning
IPv6 (AAAA)
No AAAA record was found. IPv6-only mobile networks reach your site only through a carrier translator, which adds latency. explain
-
Info
HTTPS (SVCB) record
No HTTPS resource record. It is optional, but it removes the initial HTTP redirect and advertises HTTP/3 (ECH also relies on it). explain
-
Info
Wildcard record
A random, non-existent subdomain answers with 103.224.182.246, so the zone has a wildcard. This hides typos and prevents NXDOMAIN answers. explain
-
Warning
Web server answers
No web server answered on port 80 or 443 (ConnectionError). This does not affect DNS, but the site is not serving pages. explain
Mail delivery
6 checksMX records and everything a receiving server checks before accepting your mail.
-
OK
MX records
1 mail server(s) are published. explain
Priority Mail server Addresses Reverse DNS 10 park-mx.above.com 103.224.212.34 park-mx.above.com -
Warning
Mail server redundancy
Only one MX record exists. A second server (or a backup MX at a different provider) keeps mail queued during an outage instead of bouncing it. explain
-
OK
MX hosts resolve
Every mail server resolves to at least one address. explain
-
OK
Reverse DNS of the mail servers
Every mail server address has a PTR record. explain
103.224.212.34 -> park-mx.above.com
-
Info
DANE / TLSA
No TLSA record. DANE is optional and requires DNSSEC, but it is the strongest protection against downgrade attacks on SMTP. explain
-
OK
Blocklists (DNSBL)
No mail or web address of this domain is listed on the public blocklists we query. explain
Mail authentication
6 checksSPF, DKIM, DMARC and the modern transport policies.
-
OK
SPF
The SPF record ends in -all, so unauthorised senders are rejected or marked. explain
v=spf1 ip6:fdcf:abda:4154::/48 -all DNS lookups used: 0 of 10
-
Error
DMARC
No DMARC record at _dmarc.login.do. Without it, SPF and DKIM failures have no consequence and you receive no reports about abuse of your domain. explain
-
Warning
DKIM
No DKIM key was found on the selectors we probe. DKIM may still be active on a private selector, but without it DMARC survives no forwarding. explain
-
Info
MTA-STS
No MTA-STS policy. It stops attackers from stripping TLS between mail servers and is supported by the large providers. explain
-
Info
TLS-RPT
No TLS-RPT record. It is the reporting half of MTA-STS and DANE. explain
-
Info
BIMI
No BIMI record. It shows your brand logo next to authenticated mail and requires DMARC at p=quarantine or p=reject first. explain
Security
4 checksDNSSEC, certificate authorisation and exposure of the zone.
-
Warning
DNSSEC
DNSSEC is not enabled. Without it, answers for your domain can be forged on the way to the resolver. explain
-
Warning
CAA
No CAA record. Any certificate authority in the world may issue a certificate for your domain; a CAA record limits that to the ones you choose. explain
-
OK
Zone transfer (AXFR)
No name server allows an anonymous zone transfer. explain
-
OK
Software version disclosure
The name servers do not disclose their software version. explain
Records found
| Name | Type | TTL | Value |
|---|---|---|---|
| login.do | SOA | 3600 | ns1.abovedomains.com. hostmaster.trellian.com. 2026091901 10800 3600 604800 3600 |
| login.do | NS | 86400 | ns1.abovedomains.com. ns2.abovedomains.com. |
| login.do | A | 3600 | 103.224.182.246 |
| login.do | MX | 3600 | 10 park-mx.above.com. |
| login.do | TXT | 3600 | "b56a8347528bd33e90ffcc9fd139f1569a401ed6" "v=spf1 ip6:fdcf:abda:4154::/48 -all" |
| www.login.do | A | 3600 | 103.224.182.246 |
Registry data (RDAP)
The registry did not return RDAP data for this domain.