DDnsCheckr

LIVE DNS OPERATIONS

DNS Checker

Compare trusted public resolvers, inspect DNSSEC, verify expected values, and understand why DNS answers differ.

Advanced options Expected values and matching

Presets only fill comparison guidance locally. Normalized matching ignores surrounding whitespace, quotes, case, and a final DNS dot. Safe Regex is bounded and rejects lookarounds, backreferences, and nested quantifiers.

Runs sequentially within the existing resolver rate limit. Each result is saved server-side.

Ready. Results include exact resolver provenance.

RESOLVER COMPARISON

Waiting for a lookup

● LIVE

Run your first DNS check

Results from Google Public DNS and Cloudflare 1.1.1.1 will appear here with TTL, latency, response flags, and DNSSEC state.

MEMBERSHIP

Keep the lookup free. Upgrade the workspace.

DnsCheckr uses only the named public resolver sources shown in each result. Membership pays for private workspace features, not DNS data or a claimed worldwide probe network.

Loading membership options…

One workspace. Every DNS question.

01

DNSSEC evidence

Compare validated answers with Checking Disabled to distinguish insecure, valid, and failing chains.

02

Email DNS

Inspect MX, SPF, DKIM, DMARC, MTA-STS, TLS-RPT, and CAA without hiding raw records.

03

Change history

Save checks locally, compare evidence, and export portable JSON reports with schema metadata.

Supported DNS record guide

ALIASES

CNAME and DNAME

Returned alias data is shown as resolver evidence. DnsCheckr does not rewrite names or make an authoritative-transport claim.

IDENTITY

SSHFP and SMIMEA

Fingerprint and association records are displayed as returned DNS data only. No SSH host key, email identity, or certificate is contacted or verified.

INTEGRITY

ZONEMD and DNSSEC

Zone digest and DNSSEC records retain their structured resolver-returned values. DnsCheckr does not calculate a zone digest or assert a chain is authoritative proof.

Full DNS record catalogue

Show supported record types and evidence limits
A

IPv4 address

Returned address only; no hosting, routing, or geolocation claim.

AAAA

IPv6 address

Returned address only; no hosting, routing, or geolocation claim.

CNAME

Canonical alias

No automatic target lookup.

DNAME

Delegation alias

No automatic name rewriting.

MX

Mail exchange

No SMTP-delivery test.

NS

Nameserver host

Recursive observation, not direct delegation proof.

PTR

Reverse pointer

Forward confirmation is separate evidence.

SRV

Service location

No service connection test.

SOA

Zone authority data

Not zone-transfer evidence.

TXT

Text policy

No mail-policy syntax or delivery validation.

NAPTR

Naming authority pointer

No URI or service action is executed.

URI

URI locator

Returned URI text is not fetched or linked.

CAA

CA authorization

No certificate-issuance test.

DS

Delegation signer

Named-resolver DNSSEC context only.

DNSKEY

DNSSEC key

Named-resolver DNSSEC context only.

SSHFP

SSH fingerprint

No SSH server key was contacted.

SMIMEA

S/MIME association

No certificate or identity was verified.

TLSA

TLS association

No TLS endpoint or certificate was tested.

RRSIG

DNSSEC signature

Named-resolver DNSSEC context only.

NSEC

Authenticated denial

Named-resolver DNSSEC context only.

NSEC3

Hashed authenticated denial

Named-resolver DNSSEC context only.

CDS

Child DS signal

No parent-zone action is asserted.

CDNSKEY

Child DNSKEY signal

No parent-zone action is asserted.

CSYNC

Child-to-parent synchronization

No synchronization action is performed.

ZONEMD

Zone digest

No zone digest is calculated or validated.

SVCB

Service binding

No service connection test.

HTTPS

HTTPS service binding

No HTTPS connection test.

DSYNC

Delegation synchronization endpoint

No endpoint is contacted.

OPENPGPKEY

OpenPGP public key

No key import or cryptographic verification.

DNSSEC RELATIONSHIPS

Follow the chain deliberately

DS in a parent zone references a child zone’s DNSKEY. RRSIG signs an RRset; NSEC/NSEC3 can support authenticated denial. The AD flag is a named resolver’s validation signal, not direct authoritative proof.

DATA-SOURCE TRANSPARENCY

Two named resolver observations

Queries use Google Public DNS and Cloudflare 1.1.1.1 through fixed HTTPS endpoints. Results show timestamp, TTL, RCODE, AD/CD/TC flags, latency, and raw answers. No paid API or location-based probe is used.