Test your own path
Two queries, run from your own machine through the resolver it already uses.
Step 1: Is your answer being rewritten?#
What the test proves. canary.probe.isitdns.net has one A record, 192.0.2.111, an address from the documentation block of RFC 5737. Any other answer was written somewhere between you and the zone.
The command. No @server: this asks your own resolver.
dig +short canary.probe.isitdns.net(Resolve-DnsName canary.probe.isitdns.net -Type A).IPAddressnslookup -type=A canary.probe.isitdns.netThe expected result. Fixture: the same name asked of 1.1.1.1 over IPv4 from a path with no port-53 interception (a query to 192.0.2.1 from it timed out), 2026-10-05.
Asks 1.1.1.1 for the canary's address.
dig -4 @1.1.1.1 canary.probe.isitdns.net AGO 192.0.2.111
NO GO anything else, NXDOMAIN and SERVFAIL included
The id, the Query time, the WHEN line and the TTL move on every run.
What it cannot prove. A correct answer does not show where it came from: a cache or a forwarder can hand back the right address. It covers this one name; a filter can rewrite some names and pass others.
Next step. On anything else, ask 1.1.1.1 directly and compare: dig @1.1.1.1 canary.probe.isitdns.net A. On 192.0.2.111, go to step 2.
Source. RFC 5737, section 3: 192.0.2.0/24 is reserved for documentation.
Step 2: Did your query reach the authority?#
What the test proves. A label nobody has asked before is in no cache, so the answer has to come from the isitdns.net authoritative servers, and they answer it with a TXT string. A string back means your query reached them.
The command. A fresh label each run: x and 26 characters from a-z2-7.
N=$(LC_ALL=C tr -dc 'a-z2-7' < /dev/urandom | head -c26)
dig +short TXT x$N.t.probe.isitdns.net$N = -join ((97..122) | Get-Random -Count 26 | % {[char]$_})
Resolve-DnsName -Type TXT "x$N.t.probe.isitdns.net" | % StringsThe expected result. Fixture: one fresh label asked of 1.1.1.1 from the same path, 2026-10-05. Do not rerun it: that label has been asked, so a resolver can answer it from cache.
Asks 1.1.1.1 for the TXT at a fresh label.
dig -4 @1.1.1.1 x425gylw4kva6shmyrcmktwmdzb.t.probe.isitdns.net TXTGO a base64url TXT string comes back
NO GO empty, SERVFAIL or NXDOMAIN
The string is different on every run, and so are the id, the Query time and the WHEN line.
What it cannot prove. It says the query arrived, not which resolver carried it or where that resolver sits. A label that was asked before can be answered from a resolver's cache, which reads as a GO the authority never saw; mint a new one every run. A label that is not x and 26 of a-z2-7 answers SERVFAIL or NXDOMAIN, which reads here as a NO GO that is not one.
Next step. On a NO GO, check the label is x and 26 of a-z2-7, then ask 1.1.1.1 directly: dig @1.1.1.1 TXT x$N.t.probe.isitdns.net.
Source. RFC 1035, section 3.2.1: a TTL is how long a record may be cached before the source is asked again. Base64url is RFC 4648, section 5.
See also#
- check-a-resolver: find the resolver you use and whether it tells the truth
- dig-flags: what each flag in the header means