RESOLVER COMPARISON
Waiting for a lookup
Run your first DNS check
Results from Google Public DNS and Cloudflare 1.1.1.1 will appear here with TTL, latency, response flags, and DNSSEC state.
LIVE DNS OPERATIONS
Compare trusted public resolvers, inspect DNSSEC, verify expected values, and understand why DNS answers differ.
Presets only fill comparison guidance locally. Normalized matching ignores surrounding whitespace, quotes, case, and a final DNS dot. Safe Regex is bounded and rejects lookarounds, backreferences, and nested quantifiers.
Runs sequentially within the existing resolver rate limit. Each result is saved server-side.
RESOLVER COMPARISON
Results from Google Public DNS and Cloudflare 1.1.1.1 will appear here with TTL, latency, response flags, and DNSSEC state.
MEMBERSHIP
DnsCheckr uses only the named public resolver sources shown in each result. Membership pays for private workspace features, not DNS data or a claimed worldwide probe network.
Compare validated answers with Checking Disabled to distinguish insecure, valid, and failing chains.
Inspect MX, SPF, DKIM, DMARC, MTA-STS, TLS-RPT, and CAA without hiding raw records.
Save checks locally, compare evidence, and export portable JSON reports with schema metadata.
Returned alias data is shown as resolver evidence. DnsCheckr does not rewrite names or make an authoritative-transport claim.
Fingerprint and association records are displayed as returned DNS data only. No SSH host key, email identity, or certificate is contacted or verified.
Zone digest and DNSSEC records retain their structured resolver-returned values. DnsCheckr does not calculate a zone digest or assert a chain is authoritative proof.
Returned address only; no hosting, routing, or geolocation claim.
Returned address only; no hosting, routing, or geolocation claim.
No automatic target lookup.
No automatic name rewriting.
No SMTP-delivery test.
Recursive observation, not direct delegation proof.
Forward confirmation is separate evidence.
No service connection test.
Not zone-transfer evidence.
No mail-policy syntax or delivery validation.
No URI or service action is executed.
Returned URI text is not fetched or linked.
No certificate-issuance test.
Named-resolver DNSSEC context only.
Named-resolver DNSSEC context only.
No SSH server key was contacted.
No certificate or identity was verified.
No TLS endpoint or certificate was tested.
Named-resolver DNSSEC context only.
Named-resolver DNSSEC context only.
Named-resolver DNSSEC context only.
No parent-zone action is asserted.
No parent-zone action is asserted.
No synchronization action is performed.
No zone digest is calculated or validated.
No service connection test.
No HTTPS connection test.
No endpoint is contacted.
No key import or cryptographic verification.
DNSSEC RELATIONSHIPS
DS in a parent zone references a child zone’s DNSKEY. RRSIG signs an RRset; NSEC/NSEC3 can support authenticated denial. The AD flag is a named resolver’s validation signal, not direct authoritative proof.
DATA-SOURCE TRANSPARENCY
Queries use Google Public DNS and Cloudflare 1.1.1.1 through fixed HTTPS endpoints. Results show timestamp, TTL, RCODE, AD/CD/TC flags, latency, and raw answers. No paid API or location-based probe is used.