SHEET 09 / INSTRUMENT
Read the records that route the site and email.
The checker runs in your browser and queries the selected public resolver. The domain and returned records are not submitted to this website.
LIVE DNS CHECKER
Instrument · DNS over HTTPS
The checker runs in your browser and requires JavaScript. Below you can still read what it checks and see a sample report.
- NS Name servers: NS records identify the servers that host the DNS zone. All other records are managed there.
- A Website address (IPv4): An A record points the domain to the IPv4 address of the web server.
- AAAA Website address (IPv6): An AAAA record points the domain to an IPv6 address. If it exists, the website must also respond over IPv6.
- MX Incoming mail: MX records identify the servers that receive mail for the domain. A lower priority number is tried first.
- SPF Allowed senders: SPF is a TXT record listing the systems allowed to send mail for the domain. A domain may have only one SPF record.
- DKIM Message signature: A DKIM public key lets receiving servers verify that a message was signed for the domain and was not altered in transit.
- DMARC Anti-spoofing policy: DMARC tells receiving servers how to handle mail that fails SPF and DKIM checks and where to send reports.
- CAA Certificate authorities: CAA records limit which certificate authorities may issue certificates for the domain.
- DNSSEC DNS zone signature: DNSSEC signs the DNS zone so resolvers can verify that an answer was not changed in transit.
- TXT Other TXT records: Ownership checks and other service records. The tool displays these values without rating them.
SAMPLE REPORT
DNS report for vasafirma.example
6 passed · 1 review · 0 errors
-
NSName servers
InformationNS records identify the servers that host the DNS zone. All other records are managed there.
- Name
vasafirma.example- Cached for
- 86400 seconds
Record
ns1.primer-dns.examplens2.primer-dns.example
-
Name servers: sample result from a completed browser check.
-
AWebsite address (IPv4)
PassAn A record points the domain to the IPv4 address of the web server.
- Name
vasafirma.example- Cached for
- 3600 seconds
Record
192.0.2.10
-
Website address (IPv4): sample result from a completed browser check.
-
MXIncoming mail
PassMX records identify the servers that receive mail for the domain. A lower priority number is tried first.
- Name
vasafirma.example- Cached for
- 3600 seconds
Record
10 mx1.vasafirma.example
-
Incoming mail: sample result from a completed browser check.
-
SPFAllowed senders
ErrorSPF is a TXT record listing the systems allowed to send mail for the domain. A domain may have only one SPF record.
- Name
vasafirma.example- Cached for
- 3600 seconds
Record
v=spf1 a mx ~allv=spf1 include:spf.primer-bilten.example ~all
-
Allowed senders: sample result from a completed browser check.
Next step Correct the record in the DNS or mail provider panel, then run the check again.
-
DKIMMessage signature
PassA DKIM public key lets receiving servers verify that a message was signed for the domain and was not altered in transit.
- Name
default._domainkey.vasafirma.example- Cached for
- 3600 seconds
Record
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA…
-
Message signature: sample result from a completed browser check.
-
DMARCAnti-spoofing policy
ReviewDMARC tells receiving servers how to handle mail that fails SPF and DKIM checks and where to send reports.
- Name
_dmarc.vasafirma.example- Cached for
- 3600 seconds
Record
v=DMARC1; p=none; rua=mailto:dmarc@vasafirma.example
-
Anti-spoofing policy: sample result from a completed browser check.
Next step Compare this result with the intended settings in your DNS or mail provider panel.
-
CAACertificate authorities
InformationCAA records limit which certificate authorities may issue certificates for the domain.
- Name
vasafirma.example
-
Certificate authorities: sample result from a completed browser check.
-
DNSSECDNS zone signature
InformationDNSSEC signs the DNS zone so resolvers can verify that an answer was not changed in transit.
- Name
vasafirma.example
-
DNS zone signature: sample result from a completed browser check.
What it reads
The tool inspects nameservers, web addresses, mail routes, authentication records, CAA and DNSSEC signals.
What it does not prove
DNS can show configuration, but it cannot prove that a mailbox receives a message, a backup restores or a certificate renewal job will run.