What a Cloudflare zone should look like
Run 2026-09-29, thewizard. Times UTC.
NS#
dig -4 @a.gtld-servers.net isitdns.net NS +norecurse +noall +authorityisitdns.net. 172800 IN NS hera.ns.cloudflare.com.
isitdns.net. 172800 IN NS coleman.ns.cloudflare.com.dig -4 @coleman.ns.cloudflare.com isitdns.net NS +shortcoleman.ns.cloudflare.com.
hera.ns.cloudflare.com.13:50Z. Parent and child agree (RFC 1034 section 4.2.1).
A and AAAA at the apex#
dig +short isitdns.net A188.114.97.0
188.114.96.0dig +short isitdns.net AAAA2a06:98c1:3120::
2a06:98c1:3121::13:50Z. Addresses in Cloudflare's published ranges.
www#
dig -4 @coleman.ns.cloudflare.com www.isitdns.net A +noall +answerwww.isitdns.net. 300 IN A 188.114.96.0
www.isitdns.net. 300 IN A 188.114.97.013:50Z. Reads as A from the authority; no CNAME in the answer.
DS and DNSKEY#
dig -4 @a.gtld-servers.net isitdns.net DS +norecurse +short2371 13 2 2DF8E1D4E0855DF60F2A8B51C914F2F2866ED1E3344F74F9682DAC4D 42D18802The zone's keys, validated.
dig @1.1.1.1 isitdns.net DNSKEY +multilineNOERRORThe server had no complaint about the question.
qrThis message is the answer coming back, not the question going out.
rdYou asked this server to go and find the answer for you.
raThis server says it is willing to go and find answers for you.
adThis server says it checked the signatures, and they held up.
DNSKEYYou asked for the public keys this zone signs with.
3600How many seconds this answer can be reused before asking again. From a cache it is the time left, so it counts down.
Query timeHow long this one lookup took, start to finish.
GO ad set, and a KSK whose key id is the DS key tag, 2371
NO GO no ad, or no key id 2371
13:50Z. DS 2371, algorithm 13, digest 2 at the parent, matching the live KSK; ad set (RFC 4035 section 5). id, Query time, WHEN: move each run. TTLs: count down.
CAA#
dig +short isitdns.net CAA0 issue "comodoca.com"
0 issuewild "ssl.com"
0 issuewild "letsencrypt.org"
0 issue "sectigo.com"
0 issue "pki.goog; cansignhttpexchanges=yes"
0 issue "ssl.com"
0 issuewild "digicert.com; cansignhttpexchanges=yes"
0 issuewild "sectigo.com"
0 issuewild "pki.goog; cansignhttpexchanges=yes"
0 issuewild "comodoca.com"
0 issue "letsencrypt.org"
0 issue "digicert.com; cansignhttpexchanges=yes"13:50Z. Six CAs, each named for issue and issuewild. No other CA is authorized to issue (RFC 8659 section 3).
MX, SPF, DMARC#
dig +short isitdns.net MX10 mx01.mail.icloud.com.
10 mx02.mail.icloud.com.dig +short isitdns.net TXT | grep spf1"v=spf1 include:icloud.com ~all"dig +short _dmarc.isitdns.net TXT"v=DMARC1; p=reject;"13:50Z. Mail is iCloud. SPF ends ~all (RFC 7208 section 5.1); DMARC is p=reject (RFC 7489 section 6.3).
Verification TXT at the apex#
dig +short isitdns.net TXT | grep -v spf1"google-site-verification=v9f56K9…"
"apple-domain=eMnc…"
"v=MCPv1; k=ed25519; p=x58sm…"13:50Z. Three ownership proofs: Google, Apple, the MCP registry key. Tokens cut with ….
A Pages preview host#
The preview host's address.
dig @1.1.1.1 stage.isitdns.net ANOERRORThe server had no complaint about the question.
qrThis message is the answer coming back, not the question going out.
rdYou asked this server to go and find the answer for you.
raThis server says it is willing to go and find answers for you.
adThis server says it checked the signatures, and they held up.
AYou asked for the IPv4 address this name points at.
Query timeHow long this one lookup took, start to finish.
GO NOERROR, ANSWER: 0, the zone's SOA in authority
NO GO an address
13:50Z. NOERROR, no data (RFC 2308 section 2.2). No public address, by design.
A delegated child: probe.isitdns.net#
dig -4 @coleman.ns.cloudflare.com probe.isitdns.net NS +norecurse +noall +authorityprobe.isitdns.net. 300 IN NS pns2.isitdns.net.
probe.isitdns.net. 300 IN NS pns3.isitdns.net.dig -4 @coleman.ns.cloudflare.com probe.isitdns.net DS +norecurse +short51770 13 2 4C3D85FE215D049C89D5776FD49116B5915460ED0A920405006C8509 9B6C81B5The child zone's canary, validated.
dig @1.1.1.1 canary.probe.isitdns.net ANOERRORThe server had no complaint about the question.
qrThis message is the answer coming back, not the question going out.
rdYou asked this server to go and find the answer for you.
raThis server says it is willing to go and find answers for you.
adThis server says it checked the signatures, and they held up.
AYou asked for the IPv4 address this name points at.
5How many seconds this answer can be reused before asking again. From a cache it is the time left, so it counts down.
Query timeHow long this one lookup took, start to finish.
GO NOERROR, ad set, 192.0.2.111
NO GO SERVFAIL, or no ad
13:50Z. A child zone we run ourselves: NS pns2 and pns3, DS 51770 at the parent, canary 192.0.2.111 with ad set.
If your Pages host resolves and the site says 522: DNS is done; attach the host on the Cloudflare side.
If your DS is not at the registrar: the zone is signed and nobody can tell.
See also#
- cloudflare-hardening: Cloudflare's zone settings
- check-a-delegation: parent and child, compared
- delegations: what a delegated child is
- dnssec: DS, DNSKEY and the chain of trust
- caa: the CAA record
- email-records: SPF, DKIM and DMARC