Measurement estimates from a single vantage point — not a compliance certification. Guidance below is for operators, not an SLA.
DNS
IPv4-only
[3] 0/0/0 [O]
Meaning: Shows how many authoritative name servers exist, and how many IPv6 endpoints are configured, responsive, and operational.
IPv4 3/3/3 · IPv6 0/0/0 · location O
| Host | IPv4 | IPv6 | Probes |
ns1.dreamhost.com [O] |
162.159.26.14 |
— |
ipv4 162.159.26.14 ok; |
ns2.dreamhost.com [O] |
162.159.26.81 |
— |
ipv4 162.159.26.81 ok; |
ns3.dreamhost.com [O] |
162.159.27.84 |
— |
ipv4 162.159.27.84 ok; |
📌 Action item(s):
- Publish AAAA records for name server: ns1.dreamhost.com, ns2.dreamhost.com, ns3.dreamhost.com.
Mail
Dual-stack
[1 MX] v4 smtp 4/4/4 v6 smtp 4/4/4 [O]
Meaning: Shows MX footprint and SMTP health per IP family. Operational means an SMTP banner and EHLO exchange succeeded on port 25.
IPv4 SMTP 4/4/4 · IPv6 4/4/4 · location O
| Host | IPv4 | IPv6 | Probes |
nmc-gov-nr.mail.protection.outlook.com [O] |
52.101.147.1, 52.101.148.1, 52.101.148.3, 52.101.148.13 |
2a01:111:f403:cc2f::, 2a01:111:f403:cc30::1, 2a01:111:f403:cc30::3, 2a01:111:f403:cc30:: |
ipv4 52.101.147.1 ok; ipv4 52.101.148.1 ok; ipv4 52.101.148.3 ok; ipv4 52.101.148.13 ok; ipv6 2a01:111:f403:cc2f:: ok; ipv6 2a01:111:f403:cc30::1 ok; ipv6 2a01:111:f403:cc30::3 ok; ipv6 2a01:111:f403:cc30:: ok; |
Web
IPv4-only
[1] 0/0/0 [I]
Meaning: Shows IPv6 web endpoint readiness for the discovered HTTPS host. Operational means family-specific HTTPS requests complete successfully.
IPv4 1/1/1 · IPv6 0/0/0 · location I
| Host | IPv4 | IPv6 | Probes |
www.nmc.gov.nr [I] |
67.205.29.10 |
— |
ipv4 ok; |
📌 Action item(s):
- Publish AAAA records for web host: www.nmc.gov.nr.
DNSSEC
Unsigned
U/-/-
Meaning: Shows whether DNSKEY data is observed at the apex (signed), absent (unsigned), or unavailable due to lookup error.
Apex DNSKEY presence only — not full chain validation.
Analyze on DNSViz
📌 Action item(s):
- Enable DNSSEC signing and publish a DNSKEY at the apex. Use DNSViz to validate the full chain.
DMARC
p=quarantine
p=quarantine — published organizational policy. Ask receivers to quarantine failing mail; reject is stronger.
Meaning: Published DMARC policy at _dmarc.nmc.gov.nr (DNS TXT). Shows organizational policy (p=) and subdomain policy (sp=) when set.
Record at _dmarc.nmc.gov.nr:
v=DMARC1; p=quarantine; rua=mailto:dmarc@nmc.gov.nr
Policy publication only — SPF/DKIM not measured. Not part of the 0–4 row score.
Check on dmarcian
📌 Action item(s):
- Tighten DMARC toward p=reject when ready. Review on dmarcian.