Verify a nameserver migration
Confirm the parent delegation and the zone's own NS records list the same servers before the old provider is switched off.
Authoritative zone health
Read the delegation from the parent zone, then query each nameserver over TCP for NS, SOA, DNSKEY and a zone transfer.
Check the spelling and try again.
Reading address, mail, nameserver and policy records.
What the result means
A recursive resolver hides which nameserver answered. DNSTrace.dev reads the delegation from the parent zone's own servers, then queries every delegated nameserver directly over TCP port 53 and compares what each one serves: the authoritative flag, NS set, SOA serial and timers, signatures, the DS-to-DNSKEY chain and whether zone transfers are open to anyone.
Diagnostic field guide
Three practical ways to use this lookup, followed by the boundary the result cannot cross.
Reviewed Sep 2026Confirm the parent delegation and the zone's own NS records list the same servers before the old provider is switched off.
A lame or unreachable nameserver only breaks lookups for the resolvers that happen to pick it. This test asks each one directly.
Check that the DS record at the parent matches a published key and that zone transfers are refused to the public.
How to read the result
Common questions
The parent lists a nameserver for the zone, but that server does not answer authoritatively for it. Resolvers that choose it receive REFUSED or a non-authoritative answer and must retry another server.
The delegation at the registrar was changed without updating the zone, or the zone was updated without changing the registrar. Both lists should be identical so every resolver converges on the same servers.
That secondary has not received the latest zone, usually because notifications or transfers from the primary are failing. It keeps serving stale data until its expire timer runs out.
Choose the question
Each tool has its own indexable page and runs only the checks its question needs, with the full report one click away.
Every address, mail, verification and policy record.
A · AAAA · MX · TXT · NS GLBGlobal DNSLive answers from probes across ten countries.
Answer · TTL · resolver · latency ZONEDNS health checkEvery nameserver asked directly for delegation, serial, glue and DNSSEC faults.
Authoritative · TCP 53 · AXFR RDPWHOIS / RDAPRegistrar, dates, status and published contacts.
Registry + registrar data IPIP lookupNetwork owner, route, reverse name and region.
IPv4 + IPv6 ASNASN lookupAutonomous system, BGP prefix and RPKI state.
RIPEstat routing signals NETGlobal network testPing, traceroute, MTR and HTTPS timing from ten countries.
Latency · loss · route · edge TLSSSL checkerIssuer, validity, names and fingerprint.
Live certificate check MXMX lookupReceiving servers, preference and detected mail provider.
Mail routing records MAILEmail securityComplete validation across authentication and transport.
Seven policy controls SPFSPF checkerSender policy, authorization strength and DNS-limit risks.
Policy syntax + safety DMARCDMARC checkerEnforcement, alignment, rollout and report destinations.
Anti-spoofing policy DKIMDKIM checkerSelector lookup, key presence, type and base64 form.
Public signing keys STSMTA-STS checkerDNS marker plus live HTTPS transport policy.
Encrypted inbound mail RPTTLS-RPT checkerSMTP TLS report policy and destination validation.
Transport visibility HDRSecurity headersBrowser protections from the final HTTPS response.
HSTS · CSP · framing · policyEvidence before certainty
A nameserver identifies the DNS operator. An edge address identifies a public delivery network. An ASN identifies the organization announcing a route. None automatically proves where a hidden origin application runs.
Field notes
Why locations disagree, what TTL controls and when to test again.
REGISTRY · 5 minWHOIS text became structured RDAPWhere registration fields come from and why some remain unpublished.
DELIVERY · 7 minAn edge address is not an originWhat public CDN and hosting signals can and cannot prove.
Agent-ready JSON
GET /api/dns?target=example.com&type=MX
Complete lookup for
Only this section ran.
These public addresses terminate at the provider's edge.
Every published answer
| Type | Host | Answer | TTL |
|---|
Certificate history + live DNS
| Host | Live DNS chain | State | Certificate evidence |
|---|
Certificate Transparency could not be reached.
Certificate transparency is historical evidence. “Not resolved” means the name did not return a current A/CNAME answer; it may be retired, internal, or IPv6-only.
Live answers around the world
Queries run on real probes in ten countries. Results may vary because of propagation, geo-routing, or resolver cache.
Authoritative nameservers, asked directly
Reads the delegation from the parent zone, then queries every nameserver over TCP port 53 for NS, SOA, DNSKEY and a zone transfer. No recursive resolver sits in between.
| Nameserver | Queried address | Response | Authoritative | SOA serial | Signed | AXFR |
|---|
What answers on HTTPS
Delivery and anti-spoofing
Where traffic lands
Reachability from ten countries
Real probes ping, trace the route to, or fetch the target. Latency reflects the probe's network, and anycast targets answer from a different edge in each region.
Registry data
Signals worth noticing
Allocation authority
These records describe the organization responsible for the address range. They do not identify the individual using this IP.
Routing and operational checks