Information processed
When you use DNSTrace.dev, the domain name or IP address you submit is sent to our service and to the public data providers required to answer the lookup. These queries are infrastructure identifiers, but they may still be personal data in some contexts.
Like every website, our hosting provider receives connection information including your public IP address, browser headers, time of access and requested path. The “My IP” feature uses this connection address and public network metadata to show your network, ASN and approximate network region. When the primary connection is IPv6, the browser may contact an IPv4-only ipify endpoint, with icanhazip as fallback, to display the public IPv4 path separately.
Apple Private Relay status is checked against Apple's published egress range list. A confirmed result identifies the relay exit address, not the original ISP address or device location. DNSTrace.dev cannot and does not attempt to bypass a privacy relay.
Data sources and processors
Results may use Cloudflare DNS and Workers, Google Public DNS, RDAP.org and registry RDAP services, RIPEstat, Globalping, ipapi, ipwho.is, FreeIPAPI, ipify, icanhazip, Apple's Private Relay range service, NetworkCalc, crt.sh and Cert Spotter. Each provider processes requests under its own privacy terms. The current provider inventory and access notes appear on our provider map.
Storage and logs
DNSTrace.dev does not require accounts and does not build profiles from lookup history. Short-lived caches may store public lookup results to improve speed and reduce load on upstream services. Sampled first-party operational telemetry may temporarily retain request metadata to measure uptime, latency, cache performance, failures and abusive traffic. Rate limiting uses a one-way connection tag that rotates every minute; its request counter is deleted after five minutes.
Cookies and analytics
DNSTrace.dev has no advertising tracker, cross-site analytics, marketing pixel, browser fingerprinting or data sale. It does not store a persistent browser identifier. The operational telemetry described above is used only to run and protect this service, not to follow people across websites or build advertising profiles.
Visits are counted with Umami, an open-source analytics service we run ourselves on our own server rather than a third-party platform. It records the page requested, the referring page and a coarse country, browser and device type derived from the request. It sets no cookie, stores no IP address and creates no identifier that can follow a visitor to another website; the session key it derives from the request is hashed with a salt that rotates daily. The result is a count of page views. It is not shared, sold or combined with lookup inputs, and nothing about it is used to identify an individual.
Our hosting provider also runs Cloudflare Web Analytics on this site. It is cookieless, records a page view and page-performance timings such as load and rendering speed, and does not build a cross-site profile or a persistent visitor identifier. Cloudflare processes it as our provider under its own privacy terms.
When Turnstile protection is configured, Cloudflare processes a verification on a user-initiated check. After a successful verification, DNSTrace.dev sets a signed, HttpOnly, SameSite cookie that permits lookups for 15 minutes. The cookie contains an expiry and a protected connection tag; it does not contain lookup history and is not used for advertising.
Your choices
Do not submit a domain or IP address if you do not want the relevant public providers to receive that query. You can inspect DNS and registry data directly at the source. For privacy questions, contact privacy@dnstrace.dev.