What the checks mean

Name servers

The registry of the extension publishes the list of name servers that answer for the domain: this is the delegation. The zone lists its name servers too. Both lists should be the same, every server should answer, and all of them should serve the same version of the zone, shown by the serial number of its SOA record.

Website and e-mail

A and AAAA records give the IPv4 and IPv6 addresses of the name. MX records name the servers that receive its e-mail. SPF lists the servers allowed to send e-mail for the name, and DMARC tells receivers what to do with e-mail that passes neither the SPF nor the DKIM check for the name.

Security

DNSSEC signs the zone so that resolvers can detect forged answers: the registry publishes a DS record, which must match a key (DNSKEY) published in the zone. CAA records say which certificate authorities may issue certificates for the name.

OK, Warning, Missing

OK means that the check found what it looks for. Warning means that something deserves a look, and the explanation says what. Missing means that the check found nothing: the record does not exist, or no name server answered. For some records, such as CAA, a missing record is a choice and not a fault.

DNS zone check: frequent questions

Is the DNS zone check free?

Yes, and without an account. Each connection can run 10 new checks every 10 minutes. A name checked again within 5 minutes comes from our cache and does not count.

Which name is checked when I type a web address?

The domain name itself: https://www.example.com/page becomes example.com, and an e-mail address becomes its domain. Internationalised names can be typed in Unicode or in Punycode. The check works for any domain name, wherever it is registered.

Why do the registry and the zone list different name servers?

Usually because the name servers were changed on one side only: at the registrar, which updates the registry, or in the zone at the DNS provider. Resolvers start from the list of the registry, so a difference can send some of them to a server that no longer has the zone, or that has an old copy of it.

What does a different SOA serial mean?

The serial number goes up each time the zone changes, and secondary servers copy the zone when they see a higher serial. Different serials mean that some servers still serve an older version: for a few minutes after a change, or for longer if the copy fails. Run the check again a little later; if the serials still differ, contact your DNS provider. When the zone is served by two independent DNS providers, each one numbers its copy separately: the tool then does not compare their serials.

Does the tool verify DNSSEC signatures?

No. It reads the DS record at the registry and the keys in the zone, and checks that a key matches the DS record. A matching key does not prove that the signatures are valid. A missing or different key, on the other hand, makes the name fail for resolvers that validate DNSSEC.

My e-mail works: why does the tool say that SPF or DMARC is missing?

E-mail can be delivered without them. They let receivers tell your messages from forged messages that use your domain name, and without them receivers have no instruction from you about such messages.

Contact Domgate

Explore your opportunities Let's get in touch!