isitdns?

How we decide

what we measure

No login, no ads. Free.

board: DoT, latency, ad flag, continuous
domain check: Do53, DoH, delegation, DNSSEC chain, on demand
verdict: names the failed rung

where we measure from

probes: thehermit, theoracle, thewizard and theranger
table: one row per resolver, one column per probe
cards: thehermit only

the domain check

Checking a domain runs eleven checks and tells you what each one found. There is no number out of 100 and no letter.

2026-09-11: 19 domains, 8 checks, 5 checks ok on all 19. No score.

11 rows: ok / warn / fail / skipped, reason, name asked

The last three were added on 2026-09-14, and they are the ones you cannot run from inside your own network: what your parent ships in its referral, whether the digest your parent publishes still matches a key you have live, and whether a server that truncates a UDP answer will serve it over TCP.

checkwhat it asks
ns-consistencyThe nameservers the parent delegates to and the ones the zone publishes are the same set, and no nameserver name is an alias (RFC 2181 section 10.3) or NXDOMAIN.
no-open-recurseThe zone's nameserver does not answer a recursive question for a name it does not serve.
dnssecA DS at the parent and a DNSKEY at the child, and the chain validates at a validating resolver.
ttl-sanityThe apex A TTL and the SOA minimum.
spfAn SPF record exists and ends in a qualifier that means something.
dmarcA _dmarc policy exists and is not p=none.
caaA CAA record names the certificate authorities allowed to issue.
wildcardWhether a wildcard answers for names nobody defined.
glueEach nameserver named inside the zone it serves has its address in the parent's referral, and that address is one the zone serves (RFC 2181 section 5.4.1).
ds-matches-dnskeyThe DS the parent publishes matches a DNSKEY live at the apex (RFC 4034 section 5.1.4).
udp-truncationWhether the server truncates the apex DNSKEY answer over UDP, and whether TCP returns it.

Skipped is not failed. A check we could not run says so and is counted separately. Reverse zones (in-addr.arpa, ip6.arpa) do not send mail or hold certificates, so the three mail and certificate checks do not run there at all: eight rows instead of eleven.

Zone or name. A delegation, a DNSSEC chain, a nameserver's recursion policy, a zone's glue, its chain of trust and the size of its apex answers all belong to a ZONE. Asking about a hostname evaluates those six against the zone it sits in and the other five against the name itself, so the answer names the zone and marks the rows that belong to it. A registrable domain, which is most questions, gets neither because there is nothing to distinguish.

the monitored domains points, in full

The monitored domains board has two orders. Rank is the order the board was stored in that day. Best is points: one integer per domain, 0 to 100, counted from what the zone publishes. Source: one reading a day at Cloudflare's recursive, from the Cloudflare edge. One vantage, not the authoritative servers.

pointsthe question
30signed The parent publishes a DS record, so the delegation is signed.
15ipv6 The apex publishes AAAA.
12ns-count The zone publishes two or more nameservers.
10caa A CAA record at the apex limits which certificate authorities may issue.
10mail The apex says what it does about mail: an MX, or an RFC 7505 null MX.
10ttl The apex TTL reading does not exceed 86400s, and reaches 60s.
8ns-parents Those nameservers sit under more than one registrable parent domain.
5apex-direct No CNAME record is published at the apex itself.

The weights sum to 100. No curve and no average: the number is the points earned, added up.

The TTL question is one-sided, because the reading is. We read the apex TTL through a caching resolver, which counts it down, so what we hold is a floor. Over 86400s is a proven miss: a floor above the band cannot come from a zone below it. Under 60s proves nothing, because a zone publishing 60s reads under 60 on every sample that is not a fresh fill, so that case is unknown and scores 0 rather than being counted against the zone. 60s to 86400s earns the 10.

Ties break by the stored rank, the lower rank higher: from 2026-09-24 that is the domain's line in a list we keep, and before it an outside daily ranking. Nothing else breaks a tie.

Three outcomes per question: earned, missed, unknown. Missed is measured and absent. Unknown is no answer, or a reading that cannot settle it. Both score 0, so every row carries a mark for it, and the expander on the board names the questions and their points. An unknown is not dropped from the total: one denominator per row.

No facts row, no rank. No number, not a zero, and the row sits at the end of the best order.

Us. isitdns.net is measured by the same path and the same formula, pinned above the board. It is not on the list and it is in none of the board's counts. It has no stored rank, so its position reads as the rows above it plus one, with the number of rows it ties with.

Not: a grade, a security rating, an operator ranking. It says nothing about networks: we read names and records, so nameservers under several parent domains earn those 8 points even when one company runs all of them. The parent is found with a short list of registry suffixes and not the full public suffix list, so nameservers under a two-part suffix we do not list can read as one parent and cost those 8 points. A flattened or ALIAS apex is not docked, because it answers A and AAAA at the apex; only a CNAME record at the apex itself loses those points. A ttl miss can still hide: a zone at two days whose readings all land inside the band earns the points.

Board data: CC BY 4.0.

when we won't answer

stale: "no data."
every answer: read time

incidents and strikes

An incident is one continuous run of something we watch being degraded or down. A strike is one logged incident. We count incidents, not bad seconds, so a long outage is one strike, not thousands.

how we talk about it

We report what we observed, never an accusation. "We observed a DNS incident involving a provider, from one vantage, at this time" is a statement about our own instrument, not an official status for anyone.

Plain names, no logos, no affiliation with any provider named. Honest data only: real measurements or honest "no data," never a placeholder.

your privacy

No accounts, no ads, no profiles, no PII.

Page views are counted, cookieless.