This is one of the three example domain names setup by HKIRC for testing the effect of DNSSEC validation. The three domain names are:
Depending on the DNS resolver that you are using, the expected results of accessing these example domain names will be different. They are illustrated in the table below.
disabled.dnssec.hkirc.hk | enabled.dnssec.hkirc.hk | failed.dnssec.hkirc.hk | |
---|---|---|---|
DNSSEC validating resolver | OK |
OK |
Not OK |
Resolver not perform dnssec validation (or misconfigured validating resolver) |
OK |
OK |
OK |
As this domain name is not DNSSEC enabled, both DNSSEC validating or non-validating resolver will return same response with no AD (Authentic Data) flag, its no information to tell whether DNS record is authoritative (trustworth) or not.
dig result from DNSSEC validating resolver:
dig result from resolver without validating DNSSEC: