Every change Wellknown observed on this MCP server, newest first, with what it was before and what it became. Tool-surface changes carry the definition diff. Nothing here is edited after the fact.
Changed the definition of "check_domain", "dig", "dnssec_chain" and 3 more
Check adomaindomain's DNS
A siteCheckora domain that is not working:one call. First line,whether the name resolves in publicDNS.DNS,Thenthen the eleven-check audit of its zone, each row ok, warn, fail or skipped,withwhy;why. Use it first for a broken site or domain (DNS only, not HTTP orTLS.TLS), then dig for one record, trace for the delegation and dnssec_chain for DNSSEC. Measured from the isitdns edge and its probes, never the caller's network, with no key and a limit of 100 calls a minute per address. from moves the recursion, TTL and UDP truncation rows to that region's probe. A repeat within 300 s can come from the stored audit, marked stored.
before
—after
{"properties":{"api":{"description":"The /api GET that asks it again, as a new reading","type":"string"},"askAgain":{"description":"The isitdns.net page that asks it again, when one does","type":"string"},"checks":{"description":"The eleven rows: id, label, status, detail, receipt ids","type":"array"},"generatedAt":{"description":"When the audit ran","type":"string"},"receipts":{"description":"One per DNS read: what, of whom, from where, when, rcode, flags, EDE, ms, answer","type":"array"},"resolves":{"description":"The first line: state, the line, the receipt ids it rests on","type":"object"},"summary":{"description":"Counts of ok, warn, fail and skip rows","type":"object"}},"required":["api"],"type":"object"}⟨6 unchanged words⟩ ,"readOnlyHint":true,"title":"Check adomaindomain's DNS"}
digDig one record
OneDigrecordonefromname and type at onepublicboard resolver, or at Cloudflare, Google, Quad9 and AdGuard side by side (resolver all): records, flags, rcode, EDE, latency. For a whole domain use check_domain, for the delegation trace, for the zone's own servers sweep_domain. Asked over DoH from the isitdns edge,orwithDo53nofromkey
TheWalksignedthezoneDNSSECcutschain from the root totheone answer: DS and DNSKEY at each signed zone cut, key tags, signers, signature windows, and the first link that breaks orwheregoes insecure. Use itgoesafterinsecure.check_domain's dnssec row fails or a resolver answers SERVFAIL, not for one signed record (dig) or the delegation (trace). Read through Cloudflare's resolver over DoH with CD=1 from the isitdns edge, with no key and a limit of 100 calls a minute per address. Signature bytes are not verified, sothisa
RegistrationReadstatusa(RDAP)registration
TheRead a domain's registration from its registry's RDAPrecordserver:statuseseachandstatus with whateachit means for resolution, the registration, expiry and change dates, thenameservers.nameservers,
Sweep adomain across its authoritativezone'sserversnameservers
AfterSweep azonezone'schangenameservers:a sampletheofsamethenamesnameservers'andaddressestypes askedeachat
DelegationTracewalka delegation
TheTrace a delegation from the root to the authority, like dig +trace: each referral and its glue, lame or unreachable servers, the finalanswer.answer and its TTLs. Use it when a name fails at a zone cut or after a nameserver change, not for one record (dig) or whether the zone's servers agree (sweep_domain). Each hop is asked with RD=0 over TCP from the isitdns edge, or from a probe where the edge cannot dial, with no key and a limit of 100 calls a minute per address. Give the full host name: the walk ends at the zone that answers for it, and type (default A) is what it asks there.
before
—
{"properties":{"api":{"description":"The /api GET that asks it again, as a new reading","type":"string"},"askAgain":{"description":"The isitdns.net page that asks it again, when one does","type":"string"},"receipts":{"description":"One per DNS read: what, of whom, from where, when, rcode, flags, EDE, ms, answer","type":"array"},"report":{"description":"verdict, headline, steps, the TTL facts, meaning","type":"object"},"trace":{"description":"query, readAt, hops, failed dials, finalAnswer, warnings","type":"object"}},"required":["report","trace","api","receipts"],"type":"object"}Changed the definition of "check_domain" and "dnssec_chain"
⟨7 unchanged words⟩ one call. First line, whether the nameresolves.resolves in public DNS. Then the eleven-check audit of its zone, each row ok, warn, fail or skipped, withwhy.why; DNS only, not HTTP or TLS.
⟨21 unchanged words⟩ where it goes insecure. Signature bytes are notverified.verified, so this alone does not show the answer validates.
Changed the definition of "dig" and "sweep_domain"
⟨21 unchanged words⟩ (from). follow: true walks a CNAMEchain.chain (separate reads, DNSSEC off).
After a zone change:eachanameserver'ssampleansweroftothe
Removed "alias_chain" and "path_receipt"; changed the definition of "check_domain", "dig", "dnssec_chain" and 3 more (8 tools before, 6 now)
Use when aAdomainsite orwebsitedomain is not workingor not resolving (is it DNS?): one call.The firstFirst linesays, whether the nameresolves;resolves.thenThen the eleven-check audit of its zone, each row ok, warn, fail or skipped,andwith
Changed the definition of "dig"
⟨130 unchanged words⟩ alias such as 8.8.8.8, or all forthecloudflare,tier-1google,operatorsquad9, adguard side by side.","type":"string"} ⟨20 unchanged words⟩
Added "path_receipt" (7 tools before, 8 now)
Path receipt — Use when the person wants proof of what their resolver sends. First call: one dig to run. Second, with the nonce: what we saw (resolver address, UDP/TCP, DO, CD, EDNS size, cookie, ECS, case, arrivals) and the signed TXT.
Removed "dns_events", "ksk_board", "resolver_history" and 2 more; changed the definition of "alias_chain", "check_domain", "dig" and 4 more (12 tools before, 7 now)
Follow a name's CNAME chain one hopUseatwhen atime, asking one public resolver (Cloudflare DoH, recursion on) for type CNAME at each hop, so each hop's rcodename isits own (afull query returnsCNAMEonlyand thelast name's rcode,personRFCasks6604where
Changed the definition of "dig", "resolver_history", "resolver_status" and 1 more
⟨5 unchanged words⟩ on the board for one record, live,from the isitdns seat,over DoH from theCloudflareisitdnsedge.edge on Cloudflare. The resolver is a board id (cloudflare, ⟨344 unchanged words⟩
⟨26 unchanged words⟩ failed at once are excluded as our ownseat'sprobe's
Changed the definition of "alias_chain", "check_domain", "dig" and 9 more
⟨92 unchanged words⟩ NXDOMAIN (a dangling alias), a loop,a name that reads asan insidea networkname (not asked, and what a split-horizon leak looks like from outside), or a stop after 8 hops. Notes a target that reads like one written without its trailing dot.WhetherNotsomeonemeasured:coulddangling-target claima(takeover).danglingEverytargetquestion
Changed the definition of "resolver_status" and "sweep_domain"
⟨34 unchanged words⟩ bad, no data), its latency from one seat (thehomeboard's first seat,(ornamedfromin the median line, or another network, named on the row, whenhomethat seat did not vote), DNSSEC, and the time ⟨36 unchanged words⟩ has a status field that is still thehomeboard
Added "alias_chain", "dnssec_chain" and "registration"; changed the definition of "check_domain", "dig", "sweep_domain" and 1 more (9 tools before, 12 now)
{"properties":{"name":{"description":"The domain toauditaudit. Also accepted as \"domain\"; a URL is reduced to its host.","type":"string"}},"required": ⟨3 unchanged words⟩
⟨53 unchanged words⟩ maps to one, or "all" for the tier-1 operators side by side (cloudflare, google, quad9, adguard); every other board resolversideis
Changed the definition of "check_domain", "dig", "resolver_status" and 2 more
⟨67 unchanged words⟩ found and the caller decides what it means. It does not test HTTP, SMTP delivery, registrar status or arbitrary record types: use trace for the delegation path step by step, sweep_domain to compare the authoritative servers, dig for one record from one resolver. Six of the eleven belong to a ZONE ⟨49 unchanged words⟩
AskaONE public DNS resolver on the board foraone record, live, from the isitdns seat, over DoH from the Cloudflare edge. The resolver is a board id (cloudflare, google, quad9, opendns, adguard, cleanbrowsing, controld, quad9-unfiltered, adguard-family, cleanbrowsing-family, adguard-unfiltered, opendns-familyshield, nextdns, cloudflare-malware, cloudflare-family, mullvad-base, dns4eu-protective), an alias such as 8.8.8.8 or quad9 that maps to one, or "all" for every board resolver side by side; the default is cloudflare. A private (RFC 1918), link-local or LAN address, and any address not on the board, is refused, and the answer says why. To check whether the person's own path intercepts DNS, this tool is the reference only: ask canary.probe.isitdns.net here, and hand the person dig @192.0.2.1 <name> and dig @1.1.1.1 <name> to run on their own machine.
Changed the definition of "dig"
Ask a public DNS resolver,or anyonpublictheaddress,board for a record, live, from the isitdnsseat.seat, over DoH from the Cloudflare edge. Returns the answer, the flags, the rcode, ⟨6 unchanged words⟩ in the shape dig prints, plus theJSON.JSON, and ends with an "ask again" link to the same query on the site. Over MCP the transport is DoH only: DoT, Do53 over TCP and the probe's Do53 over UDP are on the HTTP surface (https://isitdns.net/api/query, transport=). A resolver with no DoH endpoint on file cannot be asked one at a time here and answers so; resolver "all" still reaches it through the edge's own fallback to Do53 over TCP or DoT, and each row names the transport that answered. An arbitrary address (an authoritative server, an ISP resolver) is not reachable over MCP: DoH to a guessed https://<ip>/dns-query is not a measurement of it; the answer names the HTTP surface that dials it over Do53 or DoT.
Changed the definition of "check_domain", "dig", "dns_events" and 6 more
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true,"title":"Check a domain"}
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true,"title":"dig"}
Changed the definition of "resolver_status" and "sweep_domain"
⟨8 unchanged words⟩ now? Every public resolver isitdns watches, itslatestverdictreadingfrom every isitdns seat that voted this round (statusok,latencyslow,DNSSECpartial, bad, no data),readitseverylatency3fromminutes
Added "sweep_domain" (8 tools before, 9 now)
Sweep a domain across its authoritative servers — Find the zone's nameservers from the root down, then ask one address of each nameserver name per family (IPv4 and IPv6) every name x type you list, with recursion off, over TCP, and widen to every other address: the zone apex SOA and the certificate-readiness questions first, then any question the sampled servers disagree on, then any that failed, as far as the per-sweep budget, the rate limit and the deadline allow. Readiness says not measured, naming the addresses, whenever one was held back. The result's holdback field says which addresses were sampled, which questions were widened, which …
Changed the definition of "top_domains"
TopMonitored domains board
The DNS health of thetopdomains100isitdnsdomainsmonitors, a list isitdns keeps, as of the last DAILY snapshot: rcode, addresses, DNSSEC andrankpoints,movementordered by points, for each. Those come from one probe per ⟨59 unchanged words⟩
Certificate changed, valid to 2026-12-17
Changed the definition of "check_domain"
Thetwelve-checkeleven-check DNS audit for a domain: parent and ⟨6 unchanged words⟩ DNSSEC chain, TTL sanity, mail posture,up to six nameservers on one serial,glue at the parent, a DS that matches ⟨38 unchanged words⟩ found and the caller decides what it means.SevenSix of thetwelveeleven belong to a ZONE rather than to a ⟨4 unchanged words⟩ DNSSEC chain, the nameserver's recursion policy, theserial, theglue, the DS match and the TCP fallback), so if you ask about a hostname thosesevensix are evaluated for the enclosing zone: the ⟨10 unchanged words⟩
Changed the definition of "check_domain"
Theeight-checktwelve-check DNS audit for a domain: parent and ⟨5 unchanged words⟩ recursion, DNSSEC chain, TTL sanity, mailposture.posture, up to six nameservers on one serial, glue at the parent, a DS that matches a live DNSKEY, and whether a truncated UDP answer can be had over TCP. Every check reports ok, warn, fail or ⟨17 unchanged words⟩ found and the caller decides what it means.ASeven of the twelve belong to a ZONE rather than to a name (the delegation,athe DNSSEC chainand,athe
Changed the definition of "top_domains"
⟨10 unchanged words⟩ the last DAILY snapshot: rcode, addresses, DNSSEC,nameserversand rank movement for each.OneThose come from one probe per day at 11:11:11 UTC,so this boardanddoesdo not move intraday. The nameservers and the points are read separately, at Cloudflare's recursive, and are refreshed through the day. Ask for one domain to get its row ⟨23 unchanged words⟩
Certificate recorded, valid to 2026-10-19
Authorization not required
First tool surface recorded: 8 tools (server version 2026-09-10)
Showing the latest 24 events. The API returns up to 500 and filters by kind: ?kind=tool_surface_changed
before
—after
{"properties":{"agreement":{"description":"resolver all: rows grouped by answer, and the ones with none","type":"object"},"api":{"description":"The /api GET that asks it again, as a new reading","type":"string"},"askAgain":{"description":"The isitdns.net page that asks it again, when one does","type":"string"},"follow":{"description":"follow: the CNAME hops, how the chain ends, its reads","type":"object"},"query":{"description":"The question as asked: name, type, flags, transport","type":"object"},"receipts":{"description":"One per DNS read: what, of whom, from where, when, rcode, flags, EDE, ms, answer","type":"array"},"results":{"description":"One row per resolver: id, response (rcode, flags, records, EDE), latencyMs, at, vantage, or error","type":"array"}},"required":["api"],"type":"object"}⟨4 unchanged words⟩ openWorldHint":true,"readOnlyHint":true,"title":"digDig one record"}
before
—after
{"properties":{"answer":{"description":"The end: rcode, records, signatures, denial, problems","type":["object","null"]},"api":{"description":"The /api GET that asks it again, as a new reading","type":"string"},"firstBreak":{"description":"The first link that breaks: at, why","type":["object","null"]},"insecureAt":{"description":"The zone where it goes insecure","type":["string","null"]},"links":{"description":"One per zone cut: zone, DS, key tags and roles, signer, problems","type":"array"},"readAt":{"description":"When the walk began","type":"string"},"receipts":{"description":"One per DNS read: what, of whom, from where, when, rcode, flags, EDE, ms, answer","type":"array"},"signaturesVerified":{"description":"Always false: signature bytes are not checked","type":"boolean"}},"required":["links","signaturesVerified","readAt","api","receipts"],"type":"object"}before
—after
{"properties":{"api":{"description":"The /api GET that asks it again, as a new reading","type":"string"},"delegationSigned":{"description":"DS at the registry, null if not stated","type":["boolean","null"]},"domain":{"description":"The registered domain answered for","type":"string"},"events":{"description":"Dates by event: registration, expiration, last changed","type":"object"},"nameservers":{"description":"The nameservers on file, null if the registry sent none","type":["array","null"]},"readAt":{"description":"When the lookup began","type":"string"},"reads":{"description":"Each HTTP read: url, at, ms, status, error","type":"array"},"status":{"description":"Each status, its effect, what it means for resolution","type":"array"}},"required":["domain","status","reads","readAt","api"],"type":"object"}⟨4 unchanged words⟩ openWorldHint":true,"readOnlyHint":true,"title":"RegistrationReadstatusa(RDAP)registration"}
before
—after
{"properties":{"api":{"description":"The /api GET that asks it again, as a new reading","type":"string"},"certReadiness":{"description":"Per name: CAA and ACME readiness","type":"array"},"holdback":{"description":"The sample: addresses known, addresses asked, and each address not asked with why","type":"object"},"notPrinted":{"description":"Counts trimmed to fit, all at api","type":"object"},"receipts":{"description":"One per DNS read: what, of whom, from where, when, rcode, flags, EDE, ms, answer","type":"array"},"results":{"description":"One row per name and type: flags, answers, not asked","type":"array"},"servers":{"description":"Each nameserver address: name, address, family","type":"array"},"zone":{"description":"The zone swept","type":"string"}},"required":["api"],"type":"object"}⟨6 unchanged words⟩ ,"readOnlyHint":true,"title":"Sweep adomain across its authoritativezone'sserversnameservers"}
⟨4 unchanged words⟩ openWorldHint":true,"readOnlyHint":true,"title":"DelegationTracewalka delegation"}
Use for one exactOnequestionrecordtofrom one public resolver, not as the first call for a site that is not working. Returns: records, flags, rcode, EDEand,latency;latency. DoH from the edge, or Do53 from a region's probe (from). follow: true walks a CNAME chain.
⟨46 unchanged words⟩ ,"both"],"type":"string"},"follow":{"default":false,"description":"Also walk the CNAME chain from this name, hop by hop, to its addresses","type":"boolean"},"from":{"description":"Ask from the probe ⟨111 unchanged words⟩
Use when a name fails validation or the person asks whether its DNSSEC chain holds. Returns eachThe signed zonecutcuts from the root to the answer: DS and DNSKEY at each, the first link that breaks,or where it goes insecure. Signature bytes are not verified.
Use when a domain has vanished from DNS and the person asks whether it expired or is on hold. Returns theThe registry's RDAP record: statuses and what each means for resolution, the datesand,itsthenameservers;nameservers.noNo contacts.
Use afterAfter a zone change, when the person asks whether the authoritative servers agree. Returns: each nameserver's answer to each name and typeyou list, the disagreements, lame or silent servers,andCAA and ACME readiness.
Use when the person wants to walk theThe delegationfor afromname,the root toauthoritativethe authority, like dig+trace. Returns+trace: each referral and glue, lame or unreachable servers, the finalanswer and a verdict.answer.
Follow a CNAME chain — Use when a name is a CNAME and the person asks where it leads. Returns each hop with its target and TTL, and how it ends: addresses, none, a resolver failure, NXDOMAIN (dangling), a loop, or an inside name.
Path receipt — Use when the person wants proof of what their resolver sends. First call: one dig to run. Second, with the nonce: what we saw (resolver address, UDP/TCP, DO, CD, EDNS size, cookie, ECS, case, arrivals) and the signed TXT.
⟨3 unchanged words⟩ "The name to follow, e.g. www.example.com. Alsoacceptedas \"domain\"; a URL isreducedreadtoas its host.","type":"string"}}, ⟨4 unchanged words⟩
The eleven-check DNS auditUseforwhen a domain:parent and child nameservers agree, no open recursion, DNSSEC chain, TTL sanity, mail posture, glue at the parent, a DS that matches a live DNSKEY, and whether a truncated UDP answer can be had over TCP. Every check reports ok, warn, failorskipped with the reason. No score, no grade. Itwebsitedoesis nottest HTTP, SMTP delivery, registrar statusworking orarbitrary record types: use trace for the delegation path step by step, sweep_domain to compare thenotauthoritativeresolvingservers,(isdigitforDNS?): onerecordcall.fromTheonefirstresolver.lineSixsaysofwhether theeleven belong to a ZONE rather than to aname(the delegation, the DNSSECresolves;chain,then thenameserver'seleven-checkrecursionauditpolicy,oftheitsgluezone,the DS match and theeachTCProwfallback)ok,so if you ask about a hostname those six are evaluated for the enclosing zone: the answer names it and marks the rows it applies to. Every transaction the audit made is a receipt under its check. Give thewarn,personfailtheorapi:skipped andask again: lines as printed.why.
{"properties":{"from":{"description":"Ask from the probe in this region","enum":["north-america","europe"],"type":"string"},"name":{"description":"The domain to audit. Alsoacceptedas \"domain\"; a URL isreducedreadtoas its host.","type":"string"}}, ⟨4 unchanged words⟩
Ask ONE public DNS resolver on the boardUse for onerecord, live, over DoH from the isitdns edge on Cloudflare. The resolver is a board id (cloudflare, google, quad9, opendns, adguard, cleanbrowsing, controld, quad9-unfiltered, adguard-family, cleanbrowsing-family, adguard-unfiltered, opendns-familyshield, nextdns, cloudflare-malware, cloudflare-family, mullvad-base, dns4eu-protective), an alias such as 8.8.8.8 or quad9 thatexactmapsquestion to one,or "all" for the tier-1 operators side by side (cloudflare, google, quad9, adguard); every other boardpublic resolveris asked by its id; the default is cloudflare. A private (RFC 1918),link-local or LAN address, and any addressnoton the board, is refused, and the answer says why. To check whether the person's own path intercepts DNS, this tool is the reference only: ask canary.probe.isitdns.net here, and hand the person dig @192.0.2.1 <name>, which should get no answer (a documentation address with no server, RFC 5737; hand it overaswritten), and dig @1.1.1.1 <name>, both to run on their own machine. Returnstheanswer, the flags, the rcode, Extended DNS Errors and the latency in the shape dig prints, plus the JSON, and ends with an "ask again" link to the same query on the site (afirstdigcallwithfor aflag off its default has no page and carries no link). With resolver "all", one TTL line per record set (RRSIG aside) seen on two or more rows with the same data: the lowest and highest TTL and the resolversite thatreported each. Over MCP the transportisDoH only: DoT, Do53 over TCP and the probe's Do53 over UDP are on the HTTP surface (https://isitdns.net/api/query, transport=). A resolver with no DoH endpoint on file cannot be asked here and answers so. Off-board address: refused; the answer carries the /api/query URL. With resolver "all": one line per group of rows with the same answer; NO ANSWER (asked, no reply) and NOT MEASURED (notasked) rows by name. The transcript is the primary result: keep the asked-at time, the resolver, transport, vantage, rawworking.DNSReturnssectionsrecords, flags, rcode, EDE,latency,andthe api and ask-again links. Givelatency;theDoHpersonfrom theapi: and ask again: lines as printededge,(aordigDo53withfrom aflag off its default has no page and no askregion'sagainprobeline(from).
{"properties":{"cd":{"default":false,"description":"Checking disabled: askAsk the resolver not to validate","type": ⟨14 unchanged words⟩ ,"ecs":{"description":"EDNS Client Subnetin CIDR form, e.g. 192.0.2.0/24","type":"string"},"family":{"default":"v4","description":"Which addressAddress family to dialthe resolver on","enum":["v4","v6","both"],"type":"string"},"namefrom":{"description":"TheAsknamefromtotheaskprobefor,ine.g.thisexample.comregion","enum":["north-america","europe"],"type":"string"},"name":{"description":"Theorname, e.g.
Walk the DNSSEC chainUseforwhenonea nameand type from the root key set to the answer, read through one public resolver with checking disabled (Cloudflare DoH, RFC 4035 section 3.2.2),failsandvalidationnameor thefirst link thatpersonbreaksaskswithwhether itsRFCDNSSEC4035chaincondition.holds.PerReturns each signed zone cut:the DS set at the parent and who signed it,from theDNSKEY set with key tags and roles (KSK, ZSK, revoked), which DS matches which key (SHA-1, SHA-256, SHA-384 digests computed), whether a DS-matched keyrootsignsto theDNSKEY set,answer andeach signature's window againsttheread time; then the answer's signerfirstandlinkkeythattagbreaks, orthe NSEC and NSEC3 records of a negative answer (counted, not checked). An insecure delegation (no DS at the parent) is reported aswherethe chain ends, not as a break. checked: key tags, signers, windows · signatures: not verified. Every read of the walk is a receipt with its time, rcode, flags, EDE and latency. Give the person the api: and ask again: linesitasgoesprinted.insecure.
⟨2 unchanged words⟩ "description":"The name, e.g. www.example.com. Alsoacceptedas \"domain\"; a URL isreducedreadtoas its host.","type":"string"}," ⟨21 unchanged words⟩
Is the domainUseitselfwhenonahold,domainexpiredhasorvanishedbeingfromdeleted?DNSAsksand theregistry's RDAP server (foundpersonthroughasksIANA'swhetherRDAPitbootstrapexpiredregistry,orRFCis9224)onandhold.returnsReturns theEPPregistry's RDAP statuseswithand what each means for resolution(clientHold,serverHold and redemptionPeriod meantheregistry says it is not publishing the delegation; resolvers keep a cached copy until its TTL runs out, and trace shows whether the TLD servers still refer), the registration, expiration and last-changeddates,the nameservers the registry holds,andwhether the delegation is signed. A hostname is walked up to the registered domain. Every HTTP read is a line withitsURL, status, round trip and time. Give the person the api: and ask again: linesnameservers;asnoprinted.contacts.
{"properties":{"domain":{"description":"Theregistereddomain or a hostname underit, e.g. example.com.it. Alsoacceptedas \"name\"; a URL isreducedreadtoas its host.","type":"string"}}, ⟨4 unchanged words⟩
Authoritative consistency, not cache propagation: find the zone's nameservers from the root down, then ask one address of each nameserver name per family (IPv4 and IPv6) every name x type you list, with recursion off, over TCP, and widen to every otherUseaddress:afterthea zoneapex SOA and the certificate-readiness questions first, then any question the sampled servers disagree on, then any that failed, as far as the per-sweep budget, the rate limit and the deadline allow. Readiness says not measured, naming the addresses, whenever one was held back. The result names the addresses sampledchange,the questions widened,when theaddresses neverpersonaskedasksandwhether theaddresses left out as slow or failing. Flags per name and type: disagreeauthoritative(serversdiffer, grouped by answer; vantages listed if more than one asked) · differs_by_vantage (split exactly by vantage; consistent with anycast or geo-steering, or one region lagging, which this sweep cannot tell apart) · not_authoritative (no aa bit) · lame (answered REFUSED) · no_answer (no response; the error per server) · not_asked (never sent: held back by the sample, paced out, the deadline, or 3 misses in a row) · serial_mismatch (SOA serials differ) · ttl_differs (same data, different TTLs) · same_error (every answering server gave the same error rcode) · private_address (RFC 1918, 6598, 4193, link-local,agree.loopback;Returns eachrange shown) · unreachable_from_edge (Cloudflare-hosted, the edge cannot dial it; asked from theoracle or thewizard instead, which via names) · relay_failed (asked from that probe, nonameserver's answer)· not_relayed (not sent from it: cap, budget, misses, deadline). A nameserver with no address found is listed as not asked, never dropped; an owner no server answered usably is not measured, never empty. Asked for HTTPS or SVCB (with A and AAAA at the same namestocompare hints), the answer also reads them (svcb):eachAliasMode target (at most 4, the rest named as not followed) followed one hop after the sweep from a recursive resolver, Cloudflare's DoH with recursion on, not the zone's own servers, for its own HTTPS or SVCB and its Aname andAAAA, reporting what those reads found (a ServiceMode record, address records only, none of the three, AliasMode again ortypeTargetNameyou"."list,NXDOMAIN:thealias dangles)disagreements,not read when a read failed,lame ornothing concluded when the reads contradict each other; a target that reads as inside a network is not asked; ipv4hint and ipv6hint against the address records when the target is thesilentownerservers, andmandatory keys the record does not carry (RFC 9460). It also reports certificate readiness per name: theCAAset that governs issuanceandwhere it was found (RFC 8659 section 3), and what is published at _acme-challenge (RFC 8555 section 8.4). Use this instead of many dig calls when checking a zone after a change. Limits: 16 names, 8 types; the plan samples at most 8 addresses and sends at most 256 sweep queries per sweep, sample and widening together (a zone with more addresses is sampled, never refused for its size); 512 sweep queries a minute per caller (IPv6 per /64), 256 a minute to any one nameserver address, 2048 a minute site-wide (the delegation walk, the zone-cut check of up to 8 queries and the DS read are extra and counted by the per-call limit; the AliasMode follow, at most 12 DoH queries to one public resolver, is extra and counted by neither). One question at a time per server; a server that misses 3 in a row is not asked the rest; the zone-cut check, the grid and the DS read stop 60 s after the sweep starts, the delegation walk before them is not inside that limit, and the AliasMode follow after them has its own 4 s deadline. Give the person the api: and ask again: lines asACMEprinted.readiness.
⟨5 unchanged words⟩ or name to sweep, e.g. example.com. Alsoacceptedas \"name\"; a URL isreducedreadtoas its host.","type":"string"}," ⟨42 unchanged words⟩
Walk the delegationUsefromwhen theroot serverspersondownwants tothewalkauthoritativetheserverdelegation for a name,likerootdigto+trace:authoritative,recursionlikeoffdigat+trace.everyReturnshop,eachreferralsreferral and gluefollowed, lame,refused andor unreachable serversreported, the finalauthoritativeansweras given, plus a healthy-or-not verdict. It reads no DS, DNSKEY or RRSIG (the dnssec_check prompt does)andasks no recursive resolver (dig with resolver all does). Every hop, failed dial and side lookup isareceipt with its time, rcode, flags, EDE and latency. Give the person the api: and ask again: lines as printed.verdict.
⟨2 unchanged words⟩ {"description":"The name to walk. Alsoacceptedas \"domain\"; a URL isreducedreadtoas its host.","type":"string"}," ⟨16 unchanged words⟩
DNS outage feed — Days when several resolvers were unhealthy at once, as episodes: when each began, how long it ran, how many resolvers were affected at the peak, and which. Give the person the api: and ask again: lines as printed.
Root KSK board — The RFC 8509 root key sentinel across the public resolvers: which resolvers trust which root KSK, and the root DNSKEY set as read now. Give the person the api: and ask again: lines as printed.
Incident history — The incident record for the public resolvers: start time, duration and severity of each. Notable incidents by default; all=true includes short degradations. Windows where several operators failed at once are excluded as our own probe's path, and the answer says how many. Give the person the api: and ask again: lines as printed.
Resolver board — Is public DNS having trouble right now? Every public resolver isitdns watches, tier-1 first: one label each, each probe's timestamped reading (the question, the resolver address, the probe, family and transport, the answer or failure, flags, rcode, EDE, latency), and a fresh read from the edge. When answering, give the readings behind the label; never 'DNS is fine' or 'resolver X is down' without them. Give a resolver for one card. Give the person the api: and ask again: lines as printed.
Monitored domains board — The DNS health of the domains isitdns monitors, a list isitdns keeps, as of the last DAILY snapshot: rcode, addresses, DNSSEC and points, ordered by points, for each. Those come from one probe per day at 11:11:11 UTC and do not move intraday. The nameservers and the points are read separately, at Cloudflare's recursive, and are refreshed through the day. Ask for one domain to get its row, or omit to get the board and its summary. To check any domain right now rather than as of the snapshot, use check_domain. Give the person the api: and ask again: lines as printed.
⟨12 unchanged words⟩ , tier-1 first: one label each, eachseat'sprobe's timestamped reading (the question, the resolver address, theseatprobe, family and transport, the answer or failure ⟨47 unchanged words⟩
⟨83 unchanged words⟩ addresses, whenever one was held back. Theresult's holdback fieldresultsaysnameswhichthe addressesweresampled,whichthe questionswerewidened,whichthe addresseswerenever asked andwhichthewidening passaddressespacedleft out as slow or failing. Flags per name ⟨119 unchanged words⟩ via names) · relay_failed (asked from thatseatprobe, no answer) · not_relayed (not sent ⟨388 unchanged words⟩
⟨47 unchanged words⟩ warn, fail or skipped with the reason.THERE IS NO SCORE AND NO LETTER GRADE: the checks state what they found and the caller decidesNowhatscore,itnomeans.grade. It does not test HTTP, SMTP delivery, ⟨77 unchanged words⟩ it and marks the rows it applies to. Every transaction the audit made is a receipt under its check. Give the person the api: and ask again: lines as printed.
⟨275 unchanged words⟩ file cannot be asked here and answers so.EachOff-boardrowaddress:ofrefused; the answer carries the /api/query URL. With resolver "all":namesonethelinetransportperthatgroupanswered.ofAnrowsarbitrarywithaddressthe(ansameauthoritativeanswer;server,NOanANSWERISP(asked,resolverno reply)isand NOT MEASURED (notreachableasked)overrowsMCP:byDoHname.toTheatranscriptguessedishttpsthe primary result://<ip>/dns-queryiskeepnottheaasked-atmeasurementtime,oftheit;resolver, transport, vantage, raw DNS sections, flags, rcode, EDE, latency, and theanswerapinamesand ask-again links. Give theHTTPpersonsurfacethethatapi:dialsanditaskoveragain:Do53linesorasDoT.printed (a dig with a flag off its default has no page and no ask again line).
⟨20 unchanged words⟩ were affected at the peak, and which.This isGive thetoolpersonforthe"wasapi:thereandaaskDNSagain:outagelinesrecently".as printed.
⟨127 unchanged words⟩ the chain ends, not as a break.Keychecked: key tags,signersigners,nameswindowsand·windowssignatures:arenotchecked;verified. Every read of thesignatureswalkthemselvesisareanotreceiptverifiedwith its time,sorcode,aflags,cleanEDEwalkandislatency.notGiveathevalidation.person the api: and ask again: lines as printed.
⟨16 unchanged words⟩ and the root DNSKEY set as read now. Give the person the api: and ask again: lines as printed.
⟨85 unchanged words⟩ hostname is walked up to the registered domain.ContactsEveryareHTTPneverreadreturned.isNotaDNS:lineusewithititswhenURL,everystatus,nameserverroundanswerstrip andthetime.nameGivestillthedoespersonnottheresolve,api:orandtoaskseeagain:anlinesexpiryasdate.printed.
⟨34 unchanged words⟩ seat's path, and the answer says how many. Give the person the api: and ask again: lines as printed.
The live health board, not a list to choose from: isIs public DNSOKhaving trouble right now? Every public resolver isitdns watches,its verdicttier-1fromfirst:everyoneisitdnslabelseateach,thateachvotedseat'sthistimestampedroundreading (ok, slow,thepartialquestion,bad,thenoresolverdata)address,its latency from one seat (theboard's firstseat,namedfamilyinandthetransport,mediantheline,answer oranother networkfailure,named on the rowflags,when that seat did notrcode,vote)EDE,DNSSEClatency), andthe time it was read. The text is the 30 saboardfreshtextreadandfrom theJSON is /api/statusedge.(60Whens)answering,sogive thetwo canreadingsbebehindfromthereadingslabel;upneverto'DNSaisminutefine'apart;orin'resolverthatXJSONiseachdown'resolverwithoutrowthem.hasGive astatusresolverfieldforthatoneiscard.stillGive theboard round's reading, andperson thevotes are in its global field, each vote under its seat's name. Giveapi:aandresolverasktoagain:getlinesoneascard.printed.
⟨110 unchanged words⟩ widening pass paced out as slow or failing.PerFlags per name and typeit says whether the servers agree: disagree (and whichservers differ,every answered servergrouped byanswer, with theanswer; vantages listedwhenif more than one asked),· differs_by_vantage (the answerssplit exactly byvantage: the same nameserver names and families, at least two servers per vantage, agree from each vantage and the vantages got different answers;vantage; consistent withananycast orgeo-steered answergeo-steering,and also withor one regionof an anycast authoritylagginga change, which this sweep cannot tellapart; SOA serials, CAA readiness and the ACME names keep their own checks; anything short of that evidence stays disagree, with the vantages listedapart),· not_authoritative (no aa bit),· lame (answered REFUSED),· no_answer (noresponse from this vantage, withresponse; the error per server),· not_asked (never sent: held back by the sample, paced outas slow or failing, the deadline, or 3 misses in a rowfrom that server; never counted as agreement),· serial_mismatch (SOA),ttl_differs (serversserialsthatdiffer)agree·onttl_differsthe(same dataand answered with the aa bit hand out one answer line with, different TTLs: the line and each server's TTL, one flag per line that differs),· same_error (everyserver that answered this questionansweringansweredserverwithgave the same error rcode, such as SERVFAIL; the servers asked, not every server of the zone),· private_address (an A or AAAA answer in inside address space:RFC 1918,RFC6598shared space,RFC4193unique local, link-localor, loopback; eachline with its range; it may be deliberate, and it is also what a split-horizon leak looks like fromrangeoutsideshown),or· unreachable_from_edge (aCloudflare-hostedserver, theCloudflareedge cannot dial,which is our reach and not their health). Those servers areit; asked fromone of two sinks instead, on thetheoracle or thewizardseatinstead,over TCP with recursion off,whicheachviasinknames)with·itsrelay_failedown(askedcapfromandthatbudgetseat,and eachno answernames its vantage in via (edge, sink:theoracle or sink:thewizard);relay_failed says the sink was asked and did not answer;· not_relayedsays the relay did(notsendsentitfrom(itsit: cap,the sinkbudget,repeatedmisses,or thedeadline). A nameserver with no address found ⟨6 unchanged words⟩ dropped; an owner no server answered usably isreported asnot measured, neverasempty. Asked for HTTPS or SVCB (with A ⟨331 unchanged words⟩ after them has its own 4 s deadline. Give the person the api: and ask again: lines as printed.
⟨85 unchanged words⟩ rather than as of the snapshot, use check_domain. Give the person the api: and ask again: lines as printed.
⟨32 unchanged words⟩ reported, the final authoritative answer as given,andplus aplain verdict on whether the delegation ishealthy-or-nothealthy.verdict. It reads no DS, DNSKEY or RRSIG ⟨7 unchanged words⟩ recursive resolver (dig with resolver all does). Every hop, failed dial and side lookup is a receipt with its time, rcode, flags, EDE and latency. Give the person the api: and ask again: lines as printed.
⟨398 unchanged words⟩ asked from one of two sinks instead,pns2on(Phoenix)the theoracle orp3a1thewizard(Amsterdam)seat, over TCP with recursion off, each sink ⟨9 unchanged words⟩ names its vantage in via (edge, sink:pns2theoracle or sink:p3a1thewizard); relay_failed says the sink was asked and ⟨395 unchanged words⟩
⟨61 unchanged words⟩ name to ask for, e.g. example.com or_dmarc.example.com_dmarc.example.com. Also accepted as \"domain\"; a URL is reduced to its host.","type":"string"},"norec":{" ⟨50 unchanged words⟩ 8.8.8.8 or dns.google, or \"all\" foreverythepublictier-1resolveroperators side byside.side (cloudflare, google, quad9, adguard). An address that is not on the board ⟨41 unchanged words⟩
⟨301 unchanged words⟩ , one flag per line that differs), same_error (every server that answered this question answered with the same error rcode, such as SERVFAIL; the servers asked, not every server of the zone), private_address (an A or AAAA answer in inside address space: RFC 1918, RFC 6598 shared space, RFC 4193 unique local, link-local or loopback; each line with its range; it may be deliberate, and it is also what a split-horizon leak looks like from outside), or unreachable_from_edge (a Cloudflare-hosted server the Cloudflare edge cannot ⟨102 unchanged words⟩ reported as not measured, never as empty. Asked for HTTPS or SVCB (with A and AAAA at the same names to compare hints), the answer also reads them (svcb): each AliasMode target (at most 4, the rest named as not followed) followed one hop after the sweep from a recursive resolver, Cloudflare's DoH with recursion on, not the zone's own servers, for its own HTTPS or SVCB and its A and AAAA, reporting what those reads found (a ServiceMode record, address records only, none of the three, AliasMode again or TargetName ".", NXDOMAIN: the alias dangles), not read when a read failed, or nothing concluded when the reads contradict each other; a target that reads as inside a network is not asked; ipv4hint and ipv6hint against the address records when the target is the owner, and mandatory keys the record does not carry (RFC 9460). It also reports certificate readiness per name: the ⟨113 unchanged words⟩ read are extra and counted by the per-calllimitlimit; the AliasMode follow, at most 12 DoH queries to one public resolver, is extra and counted by neither). One question at a time per server; ⟨22 unchanged words⟩ stop 60 s after the sweep starts,andthe delegation walk before them is not inside thatlimit.limit, and the AliasMode follow after them has its own 4 s deadline.
⟨3 unchanged words⟩ "The zone or name to sweep, e.g.example.comexample.com. Also accepted as \"name\"; a URL is reduced to its host.","type":"string"},"names":{ ⟨41 unchanged words⟩
{"properties":{"name":{"description":"The name towalkwalk. Also accepted as \"domain\"; a URL is reduced to its host.","type":"string"},"type":{ ⟨15 unchanged words⟩
Follow a CNAME chain — Follow a name's CNAME chain one hop at a time, asking one public resolver (Cloudflare DoH, recursion on) for type CNAME at each hop, so each hop's rcode is its own (a full query returns only the last name's rcode, RFC 6604 section 3). Returns each owner, target and TTL, and how the chain ends: the addresses at its end (A and AAAA, each family on its own, an address in inside space marked), no address (NOERROR, no A or AAAA), a resolver failure (SERVFAIL, REFUSED: nothing known about the records), NXDOMAIN (a dangling alias), a loop, a name that reads as inside a network (not asked, and what a…
Walk the DNSSEC chain — Walk the DNSSEC chain for one name and type from the root key set to the answer, read through one public resolver with checking disabled (Cloudflare DoH, RFC 4035 section 3.2.2), and name the first link that breaks with its RFC 4035 condition. Per signed zone cut: the DS set at the parent and who signed it, the DNSKEY set with key tags and roles (KSK, ZSK, revoked), which DS matches which key (SHA-1, SHA-256, SHA-384 digests computed), whether a DS-matched key signs the DNSKEY set, and each signature's window against the read time; then the answer's signer and key tag, or the NSEC and NSEC3 r…
Registration status (RDAP) — Is the domain itself on hold, expired or being deleted? Asks the registry's RDAP server (found through IANA's RDAP bootstrap registry, RFC 9224) and returns the EPP statuses with what each means for resolution (clientHold, serverHold and redemptionPeriod mean the registry says it is not publishing the delegation; resolvers keep a cached copy until its TTL runs out, and trace shows whether the TLD servers still refer), the registration, expiration and last-changed dates, the nameservers the registry holds, and whether the delegation is signed. A hostname is walked up to the registered domain. …
The live health board, not a list to choose from: is public DNS OK right now? Every ⟨102 unchanged words⟩
FindAuthoritative consistency, not cache propagation: find the zone's nameservers from the root down, then ⟨253 unchanged words⟩ server; never counted as agreement), serial_mismatch (SOA), ttl_differs (servers that agree on the data and answered with the aa bit hand out one answer line with different TTLs: the line and each server's TTL, one flag per line that differs), or unreachable_from_edge (a Cloudflare-hosted server the ⟨290 unchanged words⟩
⟨10 unchanged words⟩ authoritative server for a name, like dig +trace: recursion off at every hop, referrals andsayglueinfollowed, lame, refused and unreachable servers reported, the final authoritative answer as given, and a plainstepsverdict on whether the delegation is healthy. It reads no DS, DNSKEY or RRSIG (the dnssec_check prompt does) and asks no recursive resolver (dig with resolver all does).
⟨74 unchanged words⟩ ,"description":"Clear RD, like dig +norec, when asking an authoritative server directly","type":"boolean"},"nsid":{ ⟨35 unchanged words⟩ registry alias such as 8.8.8.8 or dns.google, or \"all\" for every public resolver side byside, or any publicside.IPAn address","type":"string"},"transport":{"default":"doh","description":"DoH(RFC 8484 wire format), DoT on 853, Do53 over TCP, or Do53 over UDP. udp53that isthenottransporton theCloudflare edge cannot run, so itboard ismeasured from our own probe off Cloudflare (each result says which seat measured it in vantage) and it carries RD and DNSSEC only:refused+cd,hereECSwithandtheNSIDHTTPareURLrefusedthatrathercanthandialdropped.","enum":["doh","dot","tcp53","udp53it."],"type":"string"},"type":{" ⟨27 unchanged words⟩
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true,"title":"DNS outage feed"}
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true,"title":"Root KSK board"}
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true,"title":"Incident history"}
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true,"title":"Resolver board"}
⟨121 unchanged words⟩ servers agree: disagree (and which servers differ, every answered server grouped by answer, with the vantages listed when more than one asked), differs_by_vantage (the answers split exactly by vantage: the same nameserver names and families, at least two servers per vantage, agree from each vantage and the vantages got different answers; consistent with an anycast or geo-steered answer, and also with one region of an anycast authority lagging a change, which this sweep cannot tell apart; SOA serials, CAA readiness and the ACME names keep their own checks; anything short of that evidence stays disagree, with the vantages listed), not_authoritative (no aa bit), lame ⟨340 unchanged words⟩
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true,"title":"Sweep a domain across its authoritative servers"}
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true,"title":"Monitored domains board"}
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true,"title":"Delegation walk"}
⟨193 unchanged words⟩ their health). Those servers are asked fromtheonepns2ofsinktwo sinks instead, pns2 (Phoenix) or p3a1 (Amsterdam), over TCP with recursion off, each sink with its own cap and budget, and each answer names its vantage in via (edge, sink:pns2 or sink:pns2p3a1); relay_failed says the sink was asked and ⟨227 unchanged words⟩
⟨7 unchanged words⟩ from the board, e.g. github.com; omit forallthe100whole list","type":"string"}},"type":"object"}