# DNSTrace.dev > DNSTrace.dev provides public DNS, RDAP/WHOIS, IP, ASN, BGP, TLS, HTTP security-header, email-security and global DNS measurement tools. DNSTrace.dev reports public infrastructure evidence. It separates DNS operator, CDN or reverse proxy, application platform and ASN network owner. It does not claim to identify an origin hidden by a proxy. ## Tools - [All tools](https://dnstrace.dev/tools) - [DNS Lookup: Check DNS Records & TTL](https://dnstrace.dev/dns-lookup): Run a complete DNS lookup for A, AAAA, CNAME, MX, TXT, NS, SOA, CAA and SRV records with TTL values, exact answers and cautious provider detection. - [WHOIS & RDAP Lookup: Domain Registration](https://dnstrace.dev/whois-lookup): Look up domain registration dates, expiry, registrar, status codes, nameservers and publicly available contacts using structured registry and registrar RDAP data. - [IP Address Lookup: ASN, ISP & Location](https://dnstrace.dev/ip-lookup): Inspect a public IPv4 or IPv6 address for ASN, ISP, BGP prefix, RPKI status, reverse DNS, abuse contact and approximate network-level location. - [DNS Propagation Checker: Global DNS Test](https://dnstrace.dev/dns-propagation-checker): Check how DNS records answer from ten countries using real Globalping probes, with resolver, TTL, response time and returned value for each location. - [SSL Certificate Checker: Expiry & Issuer](https://dnstrace.dev/ssl-checker): Check the live SSL/TLS certificate served by a hostname, including issuer, expiry, validity dates, SAN coverage, serial number and fingerprint. - [ASN Lookup: Network, BGP Prefix & RPKI](https://dnstrace.dev/asn-lookup): Find the autonomous system number, network holder, announced BGP prefix, RPKI route validation and published abuse contact for a public IP address. - [MX Lookup: Mail Server & Provider Check](https://dnstrace.dev/mx-lookup): Look up a domain's MX records, receiving mail servers, preference order and detected email provider, with the exact current DNS answers and TTL values. - [Email Security Checker: SPF, DKIM & DMARC](https://dnstrace.dev/email-security-checker): Validate a domain's MX, SPF, DKIM, DMARC, MTA-STS, TLS-RPT and BIMI configuration with exact public evidence, clear findings and repair guidance. - [SPF Record Checker & Validator](https://dnstrace.dev/spf-checker): Check and validate an SPF record for duplicate policies, unsafe all mechanisms, missing termination and excessive DNS-triggering terms. - [DMARC Checker: Policy & Alignment Test](https://dnstrace.dev/dmarc-checker): Validate a DMARC record, enforcement policy, rollout percentage, SPF and DKIM alignment modes, subdomain policy and aggregate reporting destinations. - [DKIM Checker: Selector & Public Key Test](https://dnstrace.dev/dkim-checker): Look up a DKIM selector and validate the exact TXT record, version, key type, public-key presence and basic base64 form, with tested selectors disclosed. - [MTA-STS Checker: DNS & HTTPS Policy](https://dnstrace.dev/mta-sts-checker): Validate both parts of MTA-STS: the DNS marker and live HTTPS policy, including version, mode, permitted MX patterns, policy id and maximum age. - [TLS-RPT Checker: SMTP TLS Reporting](https://dnstrace.dev/tls-rpt-checker): Validate a domain's SMTP TLS-RPT record, version and mail or HTTPS aggregate-report destinations used to monitor encrypted mail transport failures. - [Security Header Checker: HSTS & CSP Test](https://dnstrace.dev/security-header-checker): Check a website's final live HTTPS response for HSTS, CSP, X-Frame-Options, Permissions-Policy, MIME protection and cross-origin security headers. - [Subdomain discovery](https://dnstrace.dev/?view=subdomains): certificate-transparency names with current A/CNAME checks ## Delivery platform reference Each page records what the platform is, the exact public signals that identify it, what a detection proves and what it does not. - [All delivery platforms](https://dnstrace.dev/platforms) ### Content delivery networks - [Cloudflare](https://dnstrace.dev/platforms/cloudflare): CDN, reverse proxy and WAF, operated by Cloudflare, Inc. - [Akamai](https://dnstrace.dev/platforms/akamai): CDN and edge platform, operated by Akamai Technologies, Inc. - [Fastly](https://dnstrace.dev/platforms/fastly): Edge cloud and CDN, operated by Fastly, Inc. - [Amazon CloudFront](https://dnstrace.dev/platforms/amazon-cloudfront): CDN, operated by Amazon Web Services, Inc. - [Azure Front Door](https://dnstrace.dev/platforms/azure-front-door): Global load balancer and CDN, operated by Microsoft Corporation. - [Google Front End](https://dnstrace.dev/platforms/google-front-end): Cloud application edge, operated by Google LLC. - [Bunny CDN](https://dnstrace.dev/platforms/bunny-cdn): CDN, operated by BunnyWay d.o.o. - [Gcore](https://dnstrace.dev/platforms/gcore): CDN and edge cloud, operated by Gcore Luxembourg S.A. ### Security edges and website firewalls - [Imperva](https://dnstrace.dev/platforms/imperva): Security edge and WAF, operated by Imperva, Inc. - [Sucuri](https://dnstrace.dev/platforms/sucuri): Website firewall and CDN, operated by Sucuri, a GoDaddy brand. ### Application and frontend platforms - [Vercel](https://dnstrace.dev/platforms/vercel): Frontend application platform, operated by Vercel, Inc. - [Netlify](https://dnstrace.dev/platforms/netlify): Frontend application platform, operated by Netlify, Inc. - [Fly.io](https://dnstrace.dev/platforms/fly-io): Application platform, operated by Fly.io, Inc. - [Heroku](https://dnstrace.dev/platforms/heroku): Application platform, operated by Salesforce, Inc. - [GitHub Pages](https://dnstrace.dev/platforms/github-pages): Static hosting, operated by GitHub, Inc., a Microsoft subsidiary. ### Managed commerce and website platforms - [Shopify](https://dnstrace.dev/platforms/shopify): Commerce platform, operated by Shopify Inc. - [Wix](https://dnstrace.dev/platforms/wix): Managed website platform, operated by Wix.com Ltd. - [Pantheon](https://dnstrace.dev/platforms/pantheon): Managed web platform, operated by Pantheon Systems, Inc. - [Kinsta](https://dnstrace.dev/platforms/kinsta): Managed WordPress hosting, operated by Kinsta Inc. ## Application stack reference The software that produced the response, kept separate from the platform that delivered it. - [All application technologies](https://dnstrace.dev/stack) ### Content management systems - [WordPress](https://dnstrace.dev/stack/wordpress): Content management system, operated by Open source, WordPress Foundation. - [Drupal](https://dnstrace.dev/stack/drupal): Content management system, operated by Open source, Drupal Association. - [Joomla](https://dnstrace.dev/stack/joomla): Content management system, operated by Open source, Open Source Matters, Inc. - [Ghost](https://dnstrace.dev/stack/ghost): Content management system, operated by Open source, Ghost Foundation. - [Craft CMS](https://dnstrace.dev/stack/craft-cms): Content management system, operated by Pixel & Tonic, Inc. - [HubSpot](https://dnstrace.dev/stack/hubspot): Content management system, operated by HubSpot, Inc. ### Site builders and commerce platforms - [Squarespace](https://dnstrace.dev/stack/squarespace): Managed website platform, operated by Squarespace, Inc. - [Webflow](https://dnstrace.dev/stack/webflow): Managed website platform, operated by Webflow, Inc. - [Magento](https://dnstrace.dev/stack/magento): Commerce platform, operated by Adobe Inc., and the open-source Magento project. ### Web application frameworks - [Next.js](https://dnstrace.dev/stack/nextjs): Application framework, operated by Open source, maintained by Vercel. - [Nuxt](https://dnstrace.dev/stack/nuxt): Application framework, operated by Open source, NuxtLabs. - [SvelteKit](https://dnstrace.dev/stack/sveltekit): Application framework, operated by Open source, Svelte project. - [Astro](https://dnstrace.dev/stack/astro): Site framework, operated by Open source, the Astro Technology Company. - [Gatsby](https://dnstrace.dev/stack/gatsby): Site framework, operated by Open source, maintained under Netlify. - [Laravel](https://dnstrace.dev/stack/laravel): Application framework, operated by Open source, Laravel Holdings Inc. - [Django](https://dnstrace.dev/stack/django): Application framework, operated by Open source, Django Software Foundation. - [Ruby on Rails](https://dnstrace.dev/stack/ruby-on-rails): Application framework, operated by Open source, Rails Foundation. - [ASP.NET](https://dnstrace.dev/stack/aspnet): Application framework, operated by Microsoft Corporation. - [Express](https://dnstrace.dev/stack/express): Application framework, operated by Open source, OpenJS Foundation. ### Browser frameworks and libraries - [React](https://dnstrace.dev/stack/react): Frontend library, operated by Open source, maintained by Meta. - [Vue](https://dnstrace.dev/stack/vue): Frontend framework, operated by Open source, the Vue project. - [Angular](https://dnstrace.dev/stack/angular): Frontend framework, operated by Open source, maintained by Google. ### Languages and runtimes - [PHP](https://dnstrace.dev/stack/php): Server language, operated by Open source, the PHP Group. ## Machine-readable access - [API documentation](https://dnstrace.dev/api) — unauthenticated, no key required; rate limited to 30 requests/minute with 6/minute for live measurements - [OpenAPI](https://dnstrace.dev/openapi.json) - [Complete AI reference](https://dnstrace.dev/llms-full.txt) - [Methodology](https://dnstrace.dev/methodology) - [Provider map](https://dnstrace.dev/providers): active sources, fallbacks, access rules and runtime status - [API Markdown](https://dnstrace.dev/docs/api.md) - [Sitemap](https://dnstrace.dev/sitemap.xml) ## Important interpretation rules - IP geolocation is approximate network location, never a device or home address. - A nameserver identifies the DNS operator, not necessarily the host. - A CDN edge address does not reveal a protected origin. - Missing or redacted registration values remain unpublished. - Global DNS probes are a sample of recursive-resolver behavior, not a country-wide census. - A delivery platform, an application platform and a network owner are separate layers and are never merged. - A version reported in a header or asset path is self-reported and may be stale or wrong. - Absence of a signal is not absence of the technology; identifying headers are commonly removed.