What this tool checks
- A, AAAA, CNAME, MX, NS, TXT, CAA and SOA records
- SPF record present and unique
- DMARC record
- DKIM key under common selectors
- DNSSEC signature and validation
- CAA certificate authority restriction
How to use it
- 01
Enter a domain name (for example example.com). No need for http:// or a path.
- 02
Press Look up; records are fetched from public DNS resolvers.
- 03
Red and amber rows show the settings you should fix.
Technical details
How we query
Records are fetched over DNS over HTTPS (DoH) from Cloudflare and Google resolvers. DNSSEC status comes from the resolver's AD (Authenticated Data) flag and the DS record in the parent zone.
Why DKIM may show “not found”
DKIM keys are published under a selector name and can't be listed. The tool tries common selectors; if you use a custom one, your key may exist without showing up here.
TTL values
TTL is how long a record may be cached, in seconds. Lowering TTL before a change makes the switch faster.
Frequently asked questions
I changed a DNS record — why do I still see the old value?
Resolvers cache records for their TTL. The new value appears once it expires; for records with a high TTL this can take a few hours.
Is DNSSEC required?
Not required, but it prevents forged DNS answers and is recommended for finance, government and organizations where email security matters. When you enable it, make sure the DS record at your registrar is correct — a wrong DS can make your domain unreachable.
What does a CAA record do?
CAA says which certificate authorities may issue SSL certificates for your domain, making it harder for any other authority to issue one by mistake or through abuse.
Are the domains I look up stored?
No. Results are held in a short-lived memory cache, never written to a database, and queries are sent in a way that keeps them out of access logs.