DNS security
DNS checker
Look up the DNS records a name publishes, as public resolvers answer for it: addresses, aliases, mail servers, text records, nameservers, and the records that govern certificates and DNSSEC. Each record is shown with its TTL, and nothing is judged.
What this checks
- A and AAAA: the IPv4 and IPv6 addresses for the name you enter.
- CNAME: whether the name is an alias for another name.
- MX and TXT: the mail servers in order of preference, and text records such as SPF and verification tokens.
- NS and SOA: the nameservers the name is delegated to, and the zone's primary nameserver and contact.
- CAA and DS: the certificate authorities allowed to issue for the name, and the DNSSEC link from its parent zone.
- The TTL of each record, the resolver that answered, and whether it validated the answers with DNSSEC.
What the result means
The table shows what a resolver returns today for each record type at the name you entered. A row with no records means the name exists but has nothing of that type; a row saying the name does not exist means the resolver answered NXDOMAIN.
The TTL is the number of seconds a resolver may cache an answer. After you change a record, resolvers that cached the old one keep returning it until its TTL runs out, so a change can take that long to be seen everywhere.
This is a lookup, not a check: nothing is marked as passed or needing attention. The DNS security checker judges the same DNS for nameserver redundancy, CAA, DNSSEC and dangling CNAMEs.
Scope and limitations
- It looks up the name you enter only, not its
www.name or other subdomains. - It asks public resolvers, which can return a cached value for up to the TTL after a change. It does not query your nameservers directly and does not see internal DNS.
- CAA and DS are looked up at this name only. Certificate authorities also look at parent names for CAA, and a subdomain inside a signed zone has no DS record of its own; the CAA and DNSSEC checkers follow those rules.
- It covers nine record types. Others, such as SRV and PTR, are not looked up, and DMARC and DKIM records live at other names (
_dmarc.<domain>and<selector>._domainkey.<domain>): the DMARC and DKIM checkers read those.
Related guides
Questions
- Why does the result differ from what my DNS provider shows?
- Usually caching. Public resolvers keep an answer for its TTL, so a record you changed recently can show its old value until that time runs out. If the new value never appears, check the NS records: they show which provider the domain is actually delegated to.
- What is a TTL?
- Time to live: how many seconds a resolver may cache a record before asking again. A short TTL makes changes appear sooner; a long one means fewer lookups reach your nameservers.
- Why can I not see my DMARC or DKIM record?
- They are published at other names: DMARC at _dmarc followed by your domain, and DKIM at a selector name under _domainkey. This tool looks up only the name you enter; the DMARC and DKIM checkers look in the right places.
Related security tools
- DNS security checker - Check a domain's address records, nameserver redundancy, CAA, DNSSEC and dangling CNAMEs.
- Email security checker - Check MX, SPF, DMARC and DKIM together, and the protection of a domain that sends no mail.
- DNSSEC checker - See whether a domain's zone is signed, with a DS record at its parent.
- Subdomain finder - Find a domain's subdomains in public certificate transparency logs.

