Skip to content

DNS security

DNS checker

Look up the DNS records a name publishes, as public resolvers answer for it: addresses, aliases, mail servers, text records, nameservers, and the records that govern certificates and DNSSEC. Each record is shown with its TTL, and nothing is judged.

Checked from Ironfang Security's scanner address with the same low-impact limits as a scan. Nothing you enter is kept.

What this checks

What the result means

The table shows what a resolver returns today for each record type at the name you entered. A row with no records means the name exists but has nothing of that type; a row saying the name does not exist means the resolver answered NXDOMAIN.

The TTL is the number of seconds a resolver may cache an answer. After you change a record, resolvers that cached the old one keep returning it until its TTL runs out, so a change can take that long to be seen everywhere.

This is a lookup, not a check: nothing is marked as passed or needing attention. The DNS security checker judges the same DNS for nameserver redundancy, CAA, DNSSEC and dangling CNAMEs.

Scope and limitations

Related guides

Questions

Why does the result differ from what my DNS provider shows?
Usually caching. Public resolvers keep an answer for its TTL, so a record you changed recently can show its old value until that time runs out. If the new value never appears, check the NS records: they show which provider the domain is actually delegated to.
What is a TTL?
Time to live: how many seconds a resolver may cache a record before asking again. A short TTL makes changes appear sooner; a long one means fewer lookups reach your nameservers.
Why can I not see my DMARC or DKIM record?
They are published at other names: DMARC at _dmarc followed by your domain, and DKIM at a selector name under _domainkey. This tool looks up only the name you enter; the DMARC and DKIM checkers look in the right places.

Related security tools