coming from AS4804

- Internal, Forwarding & External
- Top 10 Authoritative ASNs
- Top 10 Resolver ASNs
- Top 10 Probe ASNs
- Qname Minimization
- Top EDNS Client Subnet masks
- Top 10 NX domain rewritingASNs
- Root Key Trust Anchor Sentinel for DNSSEC
- DNSKEY Algorithm ED448 support
- DNSKEY Algorithm ED25519 support
- DNSKEY Algorithm ECDSA-P384-SHA384 support
- DNSKEY Algorithm ECDSA-P256-SHA256 support
- DNSKEY Algorithm ECC-GOST support
- DNSKEY Algorithm RSA-SHA512 support
- DNSKEY Algorithm RSA-SHA256 support
- DNSKEY Algorithm RSA-SHA1-NSEC3 support
- DNSKEY Algorithm DSA-NSEC3 support
- DNSKEY Algorithm RSA-SHA1 support
- DNSKEY Algorithm DSA support
- DNSKEY Algorithm RSA-MD5 support
- DS Algorithm GOST DS support
- DS Algorithm SHA-384 DS support
- IPv6
- TCP
- TCP6

- have the same ASN as the probe (internal)
- are forwarding to a resolver with a different ASN (forwarding)
- have a ASN different from the probe ASN (external)

- have root KSK 19036 (and root KSK sentinel support)
- have root KSK 20326 (and root KSK sentinel support)
- do
**not**have root KSK 20326 (but**do**have root KSK sentinel support)

- validate DNSKEY algorithm ED448
- do
**not**validate DNSKEY algorithm ED448 - have broken DNSKEY algorithm ED448 validation support

- validate DNSKEY algorithm ED25519
- do
**not**validate DNSKEY algorithm ED25519 - have broken DNSKEY algorithm ED25519 validation support

- validate DNSKEY algorithm ECDSA384
- do
**not**validate DNSKEY algorithm ECDSA384 - have broken DNSKEY algorithm ECDSA384 validation support

- validate DNSKEY algorithm ECDSA256
- do
**not**validate DNSKEY algorithm ECDSA256 - have broken DNSKEY algorithm ECDSA256 validation support

- validate DNSKEY algorithm ECC-GOST
- do
**not**validate DNSKEY algorithm ECC-GOST - have broken DNSKEY algorithm ECC-GOST validation support

- validate DNSKEY algorithm RSA-SHA512
- do
**not**validate DNSKEY algorithm RSA-SHA512 - have broken DNSKEY algorithm RSA-SHA512 validation support

- validate DNSKEY algorithm RSA-SHA256
- do
**not**validate DNSKEY algorithm RSA-SHA256 - have broken DNSKEY algorithm RSA-SHA256 validation support

- validate DNSKEY algorithm RSA-NSEC3
- do
**not**validate DNSKEY algorithm RSA-NSEC3 - have broken DNSKEY algorithm RSA-NSEC3 validation support

- validates DNSKEY algorithm DSA-NSEC3
- do
**not**validate DNSKEY algorithm DSA-NSEC3 - have broken DNSKEY algorithm DSA-NSEC3 validation support

- validate DNSKEY algorithm RSA-SHA1
- do
**not**validate DNSKEY algorithm RSA-SHA1 - have broken DNSKEY algorithm RSA-SHA1 validation support

- validate DNSKEY algorithm DSA
- do
**not**validate DNSKEY algorithm DSA - have broken DNSKEY algorithm DSA validation support

- validate DNSKEY algorithm RSAMD5
- do
**not**validate DNSKEY algorithm RSAMD5 - have broken DNSKEY algorithm RSAMD5 validation support

- validate DS algorithm GOST
- do
**not**validate DS algorithm GOST - have broken DS algorithm GOST validation support

- validate DS algorithm SHA384
- do
**not**validate DS algorithm SHA384 - have broken DS algorithm SHA384 validation support

