Selection and fallback
Every lookup checks the Cloudflare edge cache first. On a miss, it calls the primary source for that evidence type and uses a documented fallback only after a timeout, rate limit, malformed response or service failure. DNSTrace.dev does not randomly hop providers to evade usage limits. Responses identify the successful source and the providers attempted.
DNS
Record answers use Cloudflare DNS over HTTPS with Google Public DNS as an error fallback. Global propagation checks are separate live measurements created through Globalping. A global result describes the recursive resolver seen by each probe, not every resolver in a country.
Subdomains
Public certificate-transparency records from crt.sh reveal hostnames that have appeared on certificates. DNSTrace.dev checks current A and CNAME answers for up to 50 recent names. Historical certificate evidence is not proof that a hostname remains active, and names that never appeared on a public certificate are outside this dataset.
Registration
Domain and IP registration starts with RDAP.org. If discovery fails, IANA's official bootstrap registries locate the authoritative RDAP service directly. Registrar RDAP is followed when linked. Redacted or missing fields remain unpublished.
Network and routing
ASN, BGP prefix, RPKI and abuse contacts use RIPEstat. Network geolocation uses ipapi with ipwho.is and FreeIPAPI as failure fallbacks. Geolocation is approximate and never presented as a device or home address.
Web delivery
CDN, WAF and platform detection correlates proprietary response headers, CNAME targets, published IP ranges and ASN ownership. DNS operator, reverse proxy, application platform and network owner are separate layers. A proxy can hide the origin, so DNSTrace.dev does not invent one. Each platform DNSTrace.dev can identify has a reference page recording its signals and the limits of the detection, and the content management system, framework or runtime behind the response is documented separately in the application stack reference.
TLS
NetworkCalc reads the certificate presented by the live hostname. crt.sh adds separately labeled certificate-transparency history, with Cert Spotter available as an authenticated failure fallback. Issuance does not prove that a certificate is currently served.