Skip to content
SVILENKOVIĆ ITOPTICAL NETWORKSR

SHEET 09 / INSTRUMENT

Read the records that route the site and email.

The checker runs in your browser and queries the selected public resolver. The domain and returned records are not submitted to this website.

LIVE DNS CHECKER

Instrument · DNS over HTTPS

The checker runs in your browser and requires JavaScript. Below you can still read what it checks and see a sample report.

  • NS Name servers: NS records identify the servers that host the DNS zone. All other records are managed there.
  • A Website address (IPv4): An A record points the domain to the IPv4 address of the web server.
  • AAAA Website address (IPv6): An AAAA record points the domain to an IPv6 address. If it exists, the website must also respond over IPv6.
  • MX Incoming mail: MX records identify the servers that receive mail for the domain. A lower priority number is tried first.
  • SPF Allowed senders: SPF is a TXT record listing the systems allowed to send mail for the domain. A domain may have only one SPF record.
  • DKIM Message signature: A DKIM public key lets receiving servers verify that a message was signed for the domain and was not altered in transit.
  • DMARC Anti-spoofing policy: DMARC tells receiving servers how to handle mail that fails SPF and DKIM checks and where to send reports.
  • CAA Certificate authorities: CAA records limit which certificate authorities may issue certificates for the domain.
  • DNSSEC DNS zone signature: DNSSEC signs the DNS zone so resolvers can verify that an answer was not changed in transit.
  • TXT Other TXT records: Ownership checks and other service records. The tool displays these values without rating them.

You may also paste a website URL or an email address; the checker extracts the domain.

It appears after s= in the header of a received message. This field is optional.

DNS service

When you start the check, your browser sends DNS queries for this domain directly to the selected service (Cloudflare). The domain and results never reach my server and are not stored.

Cloudflare states that it truncates IP addresses and deletes resolver logs within 25 hours. Resolver privacy policy

SAMPLE REPORT

DNS report for vasafirma.example

Checked 28. 9. 2026. at 10:42 with Cloudflare.

6 passed · 1 review · 0 errors

  1. NSName servers

    Information

    NS records identify the servers that host the DNS zone. All other records are managed there.

    Name
    vasafirma.example
    Cached for
    86400 seconds

    Record

    • ns1.primer-dns.example
    • ns2.primer-dns.example
    • Name servers: sample result from a completed browser check.

  2. AWebsite address (IPv4)

    Pass

    An A record points the domain to the IPv4 address of the web server.

    Name
    vasafirma.example
    Cached for
    3600 seconds

    Record

    • 192.0.2.10
    • Website address (IPv4): sample result from a completed browser check.

  3. MXIncoming mail

    Pass

    MX records identify the servers that receive mail for the domain. A lower priority number is tried first.

    Name
    vasafirma.example
    Cached for
    3600 seconds

    Record

    • 10 mx1.vasafirma.example
    • Incoming mail: sample result from a completed browser check.

  4. SPFAllowed senders

    Error

    SPF is a TXT record listing the systems allowed to send mail for the domain. A domain may have only one SPF record.

    Name
    vasafirma.example
    Cached for
    3600 seconds

    Record

    • v=spf1 a mx ~all
    • v=spf1 include:spf.primer-bilten.example ~all
    • Allowed senders: sample result from a completed browser check.

      Next step Correct the record in the DNS or mail provider panel, then run the check again.

      Read the guide

  5. DKIMMessage signature

    Pass

    A DKIM public key lets receiving servers verify that a message was signed for the domain and was not altered in transit.

    Name
    default._domainkey.vasafirma.example
    Cached for
    3600 seconds

    Record

    • v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA…
    • Message signature: sample result from a completed browser check.

  6. DMARCAnti-spoofing policy

    Review

    DMARC tells receiving servers how to handle mail that fails SPF and DKIM checks and where to send reports.

    Name
    _dmarc.vasafirma.example
    Cached for
    3600 seconds

    Record

    • v=DMARC1; p=none; rua=mailto:dmarc@vasafirma.example
    • Anti-spoofing policy: sample result from a completed browser check.

      Next step Compare this result with the intended settings in your DNS or mail provider panel.

      Read the guide

  7. CAACertificate authorities

    Information

    CAA records limit which certificate authorities may issue certificates for the domain.

    Name
    vasafirma.example
    • Certificate authorities: sample result from a completed browser check.

      Read the guide

  8. DNSSECDNS zone signature

    Information

    DNSSEC signs the DNS zone so resolvers can verify that an answer was not changed in transit.

    Name
    vasafirma.example
    • DNS zone signature: sample result from a completed browser check.

01

What it reads

The tool inspects nameservers, web addresses, mail routes, authentication records, CAA and DNSSEC signals.

02

What it does not prove

DNS can show configuration, but it cannot prove that a mailbox receives a message, a backup restores or a certificate renewal job will run.