downgrade.alg18.westerbaan.name

This is a DNSSEC algorithm-downgrade test zone: its DS and DNSKEY records announce both ML-DSA-44 (algorithm 18, per draft-westerbaan-dnssec-mldsa) and ECDSAP256SHA256 (algorithm 13), but the alg 18 RRSIGs are deliberately stripped from the zone — only alg 13 signatures are served.

If you can see this page through a validating resolver that supports ML-DSA-44, that resolver does not implement the downgrade protection described in section “Downgrades” of the draft: it accepted the zone even though the promised post-quantum signatures are missing. A resolver with downgrade protection treats this zone as bogus. Resolvers without ML-DSA-44 support validate it normally via alg 13.

Try: dig +dnssec downgrade.alg18.westerbaan.name A

Related test zones: only (signed with alg 18 only) and dual (properly signed with both alg 18 and alg 13).