Checks

DNSSEC not detected

This scan did not see a validating DNSSEC chain for the name.

Why it matters

Without DNSSEC, resolvers cannot cryptographically reject a forged answer.

What to do

Sign the zone and publish a DS record at the parent if you want DNSSEC.

Reference

DNSSEC adds cryptographic authenticity to DNS responses.

ICANN — DNSSEC