Skip to main content
Cached Result — Showing the most recent stored analysis for agentquery (originally scanned 2026-06-21T01:31:27Z).

This page is served from cache so crawlers, bookmarks and shared links don't re-trigger a fresh scan. Click Re-scan to run a new analysis right now.

Registry Zone Health Intelligenceagentquery is a shared registry suffix.
This report focuses on zone infrastructure health: DNSSEC signing, nameserver diversity, certificate authority policy, and delegation security. Email authentication protocols (SPF, DMARC, DKIM) are not applicable to registry suffixes — they apply to domains registered under this zone.
Registry operators, ICANN, and ccTLD authorities can use this view to assess zone security posture.

Registry Zone Health Report

agentquery
2026-06-21T01:31:27Z ·v26.50.05-178-ge29adbdc4 · SHA-3-512: d700✱✱✱✱ Verify ·Cross-Referenced
Recon ModeRecon Mode Snapshot Re-analyze New Domain

Non-existent / Undelegated Domain

Domain is not delegated or has no DNS records. This may be an unused subdomain or unregistered domain.

What This Means

  • No authoritative DNS data is available for this domain
  • Security posture cannot be evaluated without DNS records
  • The domain may never have been registered, or has expired
  • If this is your domain, check your registrar to confirm it's active
Intelligence Sources

This analysis used 4 DNS resolvers (consensus), reverse DNS (PTR), Team Cymru (ASN attribution), IANA RDAP (registrar), crt.sh (CT logs), and SMTP probing (transport). All using open-standard protocols.

Full List
Verify Report Integrity SHA-3-512 Has this report been altered since generation? Verify below

This cryptographic hash seals the analysis data, domain, timestamp, and tool version into a tamper-evident fingerprint. Any modification to the report data will produce a different hash. This is distinct from the posture hash (used for drift detection) — the integrity hash uniquely identifies this specific report instance.

d7000d375797e0fd0ab9414a29e3f2b6bdaf064adf3924b060cc9fade439f3738ce0ee3a9f91d27b35728d83644d635daabce0ee522b7c889baf4f265bfb91ca
Evaluations reference 12 RFCs. Methods are reproducible using the verification commands provided. Results reflect DNS state at 2026-06-21T01:31:27Z.

Download the intelligence dump and verify its integrity, like you would a Kali ISO or any critical artifact. The SHA-3-512 checksum covers every byte of the download — deterministic serialization ensures identical hashes across downloads.

After downloading, verify with any of these commands:

Tip: cd ~/Downloads first (or wherever you saved the files).

OpenSSL + Sidecar (macOS, Linux, WSL)
cat dns-intelligence-agentquery.json.sha3 && echo '---' && openssl dgst -sha3-512 dns-intelligence-agentquery.json
Python 3 (cross-platform)
python3 -c "import hashlib; print(hashlib.sha3_512(open('dns-intelligence-agentquery.json','rb').read()).hexdigest())"
sha3sum (coreutils 9+)
sha3sum -a 512 dns-intelligence-agentquery.json
Compare the output against the .sha3 file or the checksum API at /api/analysis/17936/checksum. Hash algorithm: SHA-3-512 (Keccak, NIST FIPS 202).

Every finding in this report is backed by DNS queries you can run yourself. These vetted one-liners reproduce the exact checks used to build this report for agentquery. Our analysis adds multi-resolver consensus, RFC-based evaluation, and cross-referencing — but the underlying data is always independently verifiable. We are intelligence analysts, not gatekeepers.

DNS Records

Query A records (IPv4) RFC 1035
dig +noall +answer agentquery A
Query AAAA records (IPv6) RFC 1035
dig +noall +answer agentquery AAAA
Query MX records (mail servers) RFC 1035
dig +noall +answer agentquery MX
Query NS records (nameservers) RFC 1035
dig +noall +answer agentquery NS
Query TXT records RFC 1035
dig +noall +answer agentquery TXT

Domain Security

Check DNSSEC DNSKEY records RFC 4035
dig +dnssec +noall +answer agentquery DNSKEY
Check DNSSEC DS records RFC 4035
dig +noall +answer agentquery DS
Validate DNSSEC chain (requires DNSSEC-validating resolver) RFC 4035
dig +dnssec +cd agentquery A @1.1.1.1

Brand & Trust

Check CAA records (certificate authority authorization) RFC 8659
dig +noall +answer agentquery CAA

DNS Records

Check HTTPS/SVCB records RFC 9460
dig +noall +answer agentquery HTTPS

Domain Security

Check CDS/CDNSKEY automation records RFC 7344
dig +noall +answer agentquery CDS

Infrastructure Intelligence

RDAP domain registration lookup RFC 9083
curl -sL 'https://rdap.org/domain/agentquery' | python3 -m json.tool | head -50
Commands use dig, openssl, and curl — standard tools available on macOS, Linux, and WSL. Results may vary slightly due to DNS propagation timing and resolver caching.
Intelligence Confidence Audit Engine Gold · 9/9 Evaluated
How confident are these results? Each protocol is independently verified against RFC standards. No self-awarded badges.
SPF
Gold 15236 runs
DKIM
Gold 15013 runs
DMARC
Gold 15217 runs
DANE/TLSA
Gold 14995 runs
DNSSEC
Gold 15194 runs
BIMI
Gold 15010 runs
MTA-STS
Gold 15031 runs
TLS-RPT
Gold 15046 runs
CAA
Gold 15043 runs
Maturity: Development Verified Consistent Gold Gold Master

0s

Running Real-Time Scan Telemetry

Most scans complete in less than one minute. Some may take longer.

Markers represent known resolver locations. Anycast routing selects the nearest node — exact routing is internal to each provider.

Pipeline nodes reflect live data as each analysis phase completes.

Telemetry Log 0 polls