Network Tools

DNS Record Checker & Diagnostics

Comprehensive DNS diagnostic suite.

  • Runs in your browser
  • Free, no signup

Examples: example.com • google.com • cloudflare.com • github.com

Diagnostic transparency: This tool verifies actual DNS zone records returned by public resolvers. It does not fabricate arbitrary scores or mark missing optional records (such as CAA or DMARC) as fatal errors.

DNS queries are performed through standard resolvers and domain targets are not stored.

Instead of checking DNS records one by one, the DNS Record Checker queries all primary zone records simultaneously. Get an immediate overview of web routing (A/AAAA/CNAME), mail exchangers (MX), zone authority (NS/SOA), and security policies (SPF/DMARC/CAA).

Our engine provides objective technical observations rather than arbitrary "SEO scores" or marketing grades.

How to use this tool

  1. Enter the domain you wish to inspect (e.g., example.com).
  2. Click Check DNS Records to run simultaneous queries across all record types.
  3. Review the Configuration & Health Summary at the top, followed by grouped tables for each record type found.

Email authentication: SPF, DKIM and DMARC

Email spoofing is one of the most common cyber threats. Modern mail systems require three complementary DNS technologies: SPF (Sender Policy Framework TXT record) lists authorized sending IPs, DKIM signs outgoing email cryptographically, and DMARC specifies how receiving servers handle failures.

This diagnostic tool automatically detects your SPF policy and checks the dedicated _dmarc subdomain for active enforcement policies.

Certificate Authority Authorization (CAA)

CAA records allow domain owners to declare which Certificate Authorities (such as Let's Encrypt, DigiCert, or Sectigo) are permitted to issue TLS certificates for their domain.

If no CAA records are present, any trusted CA is allowed to issue a certificate. While not mandatory, configuring CAA prevents unauthorized certificate issuance.

Frequently asked questions

Is it an error if my domain has no CAA records?

No. CAA is an optional hardening measure. When omitted, standard certificate issuance proceeds normally without restriction.

Why does my apex domain have no CNAME record?

DNS standards (RFC 1912) forbid CNAME records at the zone apex (the root domain like example.com) because a CNAME cannot coexist with other record types such as SOA and NS. Apex domains should use A/AAAA records or ALIAS/ANAME features provided by modern DNS hosts.