dnstrace.devRun lookup

Evidence model

How DNSTrace.dev reaches an answer

Each result starts with public evidence. Confidence increases only when independent signals agree.

Selection and fallback

Every lookup checks the Cloudflare edge cache first. On a miss, it calls the primary source for that evidence type and uses a documented fallback only after a timeout, rate limit, malformed response or service failure. DNSTrace.dev does not randomly hop providers to evade usage limits. Responses identify the successful source and the providers attempted.

DNS

Record answers use Cloudflare DNS over HTTPS with Google Public DNS as an error fallback. Global propagation checks are separate live measurements created through Globalping. A global result describes the recursive resolver seen by each probe, not every resolver in a country.

Subdomains

Public certificate-transparency records from crt.sh reveal hostnames that have appeared on certificates. DNSTrace.dev checks current A and CNAME answers for up to 50 recent names. Historical certificate evidence is not proof that a hostname remains active, and names that never appeared on a public certificate are outside this dataset.

Registration

Domain and IP registration starts with RDAP.org. If discovery fails, IANA's official bootstrap registries locate the authoritative RDAP service directly. Registrar RDAP is followed when linked. Redacted or missing fields remain unpublished.

Network and routing

ASN, BGP prefix, RPKI and abuse contacts use RIPEstat. Network geolocation uses ipapi with ipwho.is and FreeIPAPI as failure fallbacks. Geolocation is approximate and never presented as a device or home address.

Web delivery

CDN, WAF and platform detection correlates proprietary response headers, CNAME targets, published IP ranges and ASN ownership. DNS operator, reverse proxy, application platform and network owner are separate layers. A proxy can hide the origin, so DNSTrace.dev does not invent one. Each platform DNSTrace.dev can identify has a reference page recording its signals and the limits of the detection, and the content management system, framework or runtime behind the response is documented separately in the application stack reference.

TLS

NetworkCalc reads the certificate presented by the live hostname. crt.sh adds separately labeled certificate-transparency history, with Cert Spotter available as an authenticated failure fallback. Issuance does not prove that a certificate is currently served.

View every provider and access rule →