Ueberpruefen
Event Times Around the World | ||||||||
---|---|---|---|---|---|---|---|---|
Location | Start time | End time | Location | Start time | End time | Location | Start time | End time |
Accra | Mon 15:15 | Mon 15:35 | Edmonton | Mon 08:15 | Mon 08:35 | Nairobi | Mon 18:15 | Mon 18:35 |
Addis Ababa | Mon 18:15 | Mon 18:35 | Frankfurt | Mon 16:15 | Mon 16:35 | Nassau | Mon 10:15 | Mon 10:35 |
Adelaide * | Tue 01:45 | Tue 02:05 | Guatemala City | Mon 09:15 | Mon 09:35 | New Delhi | Mon 20:45 | Mon 21:05 |
Algiers | Mon 16:15 | Mon 16:35 | Halifax | Mon 11:15 | Mon 11:35 | New Orleans | Mon 09:15 | Mon 09:35 |
Almaty | Mon 21:15 | Mon 21:35 | Hanoi | Mon 22:15 | Mon 22:35 | New York | Mon 10:15 | Mon 10:35 |
Amman | Mon 17:15 | Mon 17:35 | Harare | Mon 17:15 | Mon 17:35 | Oslo | Mon 16:15 | Mon 16:35 |
Amsterdam | Mon 16:15 | Mon 16:35 | Havana | Mon 10:15 | Mon 10:35 | Ottawa | Mon 10:15 | Mon 10:35 |
Anadyr | Tue 03:15 | Tue 03:35 | Helsinki | Mon 17:15 | Mon 17:35 | Paris | Mon 16:15 | Mon 16:35 |
Anchorage | Mon 06:15 | Mon 06:35 | Hong Kong | Mon 23:15 | Mon 23:35 | Perth | Mon 23:15 | Mon 23:35 |
Ankara | Mon 18:15 | Mon 18:35 | Honolulu | Mon 05:15 | Mon 05:35 | Philadelphia | Mon 10:15 | Mon 10:35 |
Antananarivo | Mon 18:15 | Mon 18:35 | Houston | Mon 09:15 | Mon 09:35 | Phoenix | Mon 08:15 | Mon 08:35 |
Asuncion * | Mon 12:15 | Mon 12:35 | Indianapolis | Mon 10:15 | Mon 10:35 | Prague | Mon 16:15 | Mon 16:35 |
Athens | Mon 17:15 | Mon 17:35 | Islamabad | Mon 20:15 | Mon 20:35 | Reykjavik | Mon 15:15 | Mon 15:35 |
Atlanta | Mon 10:15 | Mon 10:35 | Istanbul | Mon 18:15 | Mon 18:35 | Rio de Janeiro | Mon 12:15 | Mon 12:35 |
Auckland * | Tue 04:15 | Tue 04:35 | Jakarta | Mon 22:15 | Mon 22:35 | Riyadh | Mon 18:15 | Mon 18:35 |
Baghdad | Mon 18:15 | Mon 18:35 | Jerusalem | Mon 17:15 | Mon 17:35 | Rome | Mon 16:15 | Mon 16:35 |
Bangalore | Mon 20:45 | Mon 21:05 | Johannesburg | Mon 17:15 | Mon 17:35 | Salt Lake City | Mon 08:15 | Mon 08:35 |
Bangkok | Mon 22:15 | Mon 22:35 | Kabul | Mon 19:45 | Mon 20:05 | San Francisco | Mon 07:15 | Mon 07:35 |
Barcelona | Mon 16:15 | Mon 16:35 | Karachi | Mon 20:15 | Mon 20:35 | San Juan | Mon 11:15 | Mon 11:35 |
Beijing | Mon 23:15 | Mon 23:35 | Kathmandu | Mon 21:00 | Mon 21:20 | San Salvador | Mon 09:15 | Mon 09:35 |
Beirut | Mon 17:15 | Mon 17:35 | Khartoum | Mon 17:15 | Mon 17:35 | Santiago * | Mon 12:15 | Mon 12:35 |
Belgrade | Mon 16:15 | Mon 16:35 | Kingston | Mon 10:15 | Mon 10:35 | Santo Domingo | Mon 11:15 | Mon 11:35 |
Berlin | Mon 16:15 | Mon 16:35 | Kinshasa | Mon 16:15 | Mon 16:35 | São Paulo | Mon 12:15 | Mon 12:35 |
Bogota | Mon 10:15 | Mon 10:35 | Kiritimati | Tue 05:15 | Tue 05:35 | Seattle | Mon 07:15 | Mon 07:35 |
Boston | Mon 10:15 | Mon 10:35 | Kolkata | Mon 20:45 | Mon 21:05 | Seoul | Tue 00:15 | Tue 00:35 |
Brasilia | Mon 12:15 | Mon 12:35 | Kuala Lumpur | Mon 23:15 | Mon 23:35 | Shanghai | Mon 23:15 | Mon 23:35 |
Brisbane | Tue 01:15 | Tue 01:35 | Kuwait City | Mon 18:15 | Mon 18:35 | Singapore | Mon 23:15 | Mon 23:35 |
Brussels | Mon 16:15 | Mon 16:35 | Kyiv | Mon 17:15 | Mon 17:35 | Sofia | Mon 17:15 | Mon 17:35 |
Bucharest | Mon 17:15 | Mon 17:35 | La Paz | Mon 11:15 | Mon 11:35 | St. John's | Mon 11:45 | Mon 12:05 |
Budapest | Mon 16:15 | Mon 16:35 | Lagos | Mon 16:15 | Mon 16:35 | Stockholm | Mon 16:15 | Mon 16:35 |
Buenos Aires | Mon 12:15 | Mon 12:35 | Lahore | Mon 20:15 | Mon 20:35 | Suva * | Tue 04:15 | Tue 04:35 |
Cairo | Mon 17:15 | Mon 17:35 | Las Vegas | Mon 07:15 | Mon 07:35 | Sydney * | Tue 02:15 | Tue 02:35 |
Calgary | Mon 08:15 | Mon 08:35 | Lima | Mon 10:15 | Mon 10:35 | Taipei | Mon 23:15 | Mon 23:35 |
Canberra * | Tue 02:15 | Tue 02:35 | Lisbon | Mon 15:15 | Mon 15:35 | Tallinn | Mon 17:15 | Mon 17:35 |
Cape Town | Mon 17:15 | Mon 17:35 | London | Mon 15:15 | Mon 15:35 | Tashkent | Mon 20:15 | Mon 20:35 |
Caracas | Mon 11:15 | Mon 11:35 | Los Angeles | Mon 07:15 | Mon 07:35 | Tegucigalpa | Mon 09:15 | Mon 09:35 |
Casablanca * | Mon 16:15 | Mon 16:35 | Madrid | Mon 16:15 | Mon 16:35 | Tehran | Mon 18:45 | Mon 19:05 |
Chicago | Mon 09:15 | Mon 09:35 | Managua | Mon 09:15 | Mon 09:35 | Tokyo | Tue 00:15 | Tue 00:35 |
Copenhagen | Mon 16:15 | Mon 16:35 | Manila | Mon 23:15 | Mon 23:35 | Toronto | Mon 10:15 | Mon 10:35 |
Dallas | Mon 09:15 | Mon 09:35 | Melbourne * | Tue 02:15 | Tue 02:35 | Vancouver | Mon 07:15 | Mon 07:35 |
Dar es Salaam | Mon 18:15 | Mon 18:35 | Mexico City | Mon 09:15 | Mon 09:35 | Vienna | Mon 16:15 | Mon 16:35 |
Darwin | Tue 00:45 | Tue 01:05 | Miami | Mon 10:15 | Mon 10:35 | Warsaw | Mon 16:15 | Mon 16:35 |
Denver | Mon 08:15 | Mon 08:35 | Minneapolis | Mon 09:15 | Mon 09:35 | Washington DC | Mon 10:15 | Mon 10:35 |
Detroit | Mon 10:15 | Mon 10:35 | Minsk | Mon 18:15 | Mon 18:35 | Winnipeg | Mon 09:15 | Mon 09:35 |
Dhaka | Mon 21:15 | Mon 21:35 | Montevideo | Mon 12:15 | Mon 12:35 | Yangon | Mon 21:45 | Mon 22:05 |
Doha | Mon 18:15 | Mon 18:35 | Montréal | Mon 10:15 | Mon 10:35 | Zagreb | Mon 16:15 | Mon 16:35 |
Dubai | Mon 19:15 | Mon 19:35 | Moscow | Mon 18:15 | Mon 18:35 | Zürich | Mon 16:15 | Mon 16:35 |
Dublin | Mon 15:15 | Mon 15:35 | Mumbai | Mon 20:45 | Mon 21:05 |
The web is being accessed more and more on mobile devices. Designing your websites to be mobile friendly ensures that your pages perform well on all devices. Crowd-sourced application compatibility for macOS, iOS and Windows.
This test determines whether your DNS resolver validates DNSSEC signatures. For this test you need JavaScript turned on.
DNSSEC for Users
Modern operating systems support DNSSEC validation out of the box—though not all of them. The alternative is to use a validating resolver in your local network, e.g. a home router with DNSSEC support.
If you'd like to experiment with a validating resolver on your computer, you may want to try Dnssec-Trigger (more information). Keep in mind that web browsers do not distinguish between DNSSEC validation failures and general DNS failures (there is no security warning like with HTTPS errors).
To re-run the above test, you also need to:
- Flush the DNS cache of your OS (Windows:
ipconfig /flushdns
) - Restart browser or clear browser cache
DNSSEC for DNS Cache Operators
Modern operating systems ship the recursive DNS cache server with DNSSEC enabled in the default configuration. If this is not the case for you, follow the steps listed below for BIND or Unbound.
BIND
Since BIND 9.8, you can activate DNSSEC validation with the following lines in the options section of your named.conf:
dnssec-enable yes;
dnssec-validation auto;
Reload config: rndc reload
If you're running an older BIND version, you should update.
Unbound
Ueberpruefen
Unbound ships with a tool for secure retrieval of the root KSK.
Ueberpruefen Auf Englisch
- Update the root KSK:
unbound-anchor
- Make sure your unbound.conf contains the option auto-trust-anchor-file, e.g.:
auto-trust-anchor-file '/var/lib/unbound/root.key'
Reload config: unbound-control reload
Test validation
dig sigok.verteiltesysteme.net @127.0.0.1
(should return A record)dig sigfail.verteiltesysteme.net @127.0.0.1
(should return SERVFAIL)
If DNSSEC validation does not seem to work, check whether you're using more than one DNS resolver and whether each of them has DNSSEC validation enabled. The most common configuration error is to use a secondary DNS resolver without DNSSEC validation. Upon validation error, the operating system will fall back to the secondary resolver and the security checks of the primary resolver will be moot.
Results
- [2013-03-19] Presentation (HTML5), PDF (2.3 MB), Passive and Active Measurement Conference (PAM), Hong Kong.
- [2012-12-17] Paper (PDF), published in the Proceedings of the 2013 Passive and Active Measurement Conference (PAM).
- [2012-10-14] Presentation (HTML5), PDF (1.4 MB), DNS-OARC Workshop, Toronto.
Map shows ratio of validating clients per country, collected from October 2014 to March 2015. Some older result sets of the measurement (anonymized) are available for public download.
Other Tests
Ueberpruefen Synonym
These tests use slightly different mechanics. Most users should get the same result on all tests, but in some cases there may be discrepancies. Discrepancies are usually caused by using a combination of validating and non-validating resolvers.
- www.dnssec-or-not.com: online test by VeriSign (no JavaScript required)
- internet.nl/connection: online test by Dutch Internet Standards Platform
- www.dnssec-failed.org: webpage with bogus signature by Comcast (will not open at all if you are using DNSSEC)
Acknowledgements
Thanks to A.G., Michael, Brody, Jean-Michel, Jan-Piet, Zekah and Stefan for providing valuable feedback.
Iban Ueberpruefen
Contact
Matthäus Wander <mail(at)wander.science>