isitdns? wiki/Troubleshooting/Test your own path
Troubleshooting

Test your own path

Two queries, run from your own machine through the resolver it already uses.

Step 1: Is your answer being rewritten?#

What the test proves. canary.probe.isitdns.net has one A record, 192.0.2.111, an address from the documentation block of RFC 5737. Any other answer was written somewhere between you and the zone.

The command. No @server: this asks your own resolver.

dig +short canary.probe.isitdns.net
(Resolve-DnsName canary.probe.isitdns.net -Type A).IPAddress
nslookup -type=A canary.probe.isitdns.net

The expected result. Fixture: the same name asked of 1.1.1.1 over IPv4 from a path with no port-53 interception (a query to 192.0.2.1 from it timed out), 2026-10-05.

Asks 1.1.1.1 for the canary's address.

 dig -4 @1.1.1.1 canary.probe.isitdns.net A
; <<>> DiG 9.20.11-0ubuntu0.2-Ubuntu <<>> -4 @1.1.1.1 canary.probe.isitdns.net A
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 30457
;; flags: qr rd ra ad; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1232
;; QUESTION SECTION:
;canary.probe.isitdns.net. IN A
;; ANSWER SECTION:
canary.probe.isitdns.net. 30 IN A 192.0.2.111
;; Query time: 152 msec
;; SERVER: 1.1.1.1#53(1.1.1.1) (UDP)
;; WHEN: Mon Oct 05 20:29:44 CDT 2026
;; MSG SIZE rcvd: 69

GO 192.0.2.111

NO GO anything else, NXDOMAIN and SERVFAIL included

what each part of this output means →

The id, the Query time, the WHEN line and the TTL move on every run.

What it cannot prove. A correct answer does not show where it came from: a cache or a forwarder can hand back the right address. It covers this one name; a filter can rewrite some names and pass others.

Next step. On anything else, ask 1.1.1.1 directly and compare: dig @1.1.1.1 canary.probe.isitdns.net A. On 192.0.2.111, go to step 2.

Source. RFC 5737, section 3: 192.0.2.0/24 is reserved for documentation.

Step 2: Did your query reach the authority?#

What the test proves. A label nobody has asked before is in no cache, so the answer has to come from the isitdns.net authoritative servers, and they answer it with a TXT string. A string back means your query reached them.

The command. A fresh label each run: x and 26 characters from a-z2-7.

N=$(LC_ALL=C tr -dc 'a-z2-7' < /dev/urandom | head -c26)
dig +short TXT x$N.t.probe.isitdns.net
$N = -join ((97..122) | Get-Random -Count 26 | % {[char]$_})
Resolve-DnsName -Type TXT "x$N.t.probe.isitdns.net" | % Strings

The expected result. Fixture: one fresh label asked of 1.1.1.1 from the same path, 2026-10-05. Do not rerun it: that label has been asked, so a resolver can answer it from cache.

Asks 1.1.1.1 for the TXT at a fresh label.

 dig -4 @1.1.1.1 x425gylw4kva6shmyrcmktwmdzb.t.probe.isitdns.net TXT
; <<>> DiG 9.20.11-0ubuntu0.2-Ubuntu <<>> -4 @1.1.1.1 x425gylw4kva6shmyrcmktwmdzb.t.probe.isitdns.net TXT
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 13764
;; flags: qr rd ra ad; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1232
;; QUESTION SECTION:
;x425gylw4kva6shmyrcmktwmdzb.t.probe.isitdns.net. IN TXT
;; ANSWER SECTION:
x425gylw4kva6shmyrcmktwmdzb.t.probe.isitdns.net. 30 IN TXT "AnBuczJqxE8IKu-MOPEteLj7i-iNwAO9LQEAhQAAAAAAAAAAAAAAAAAA__-sREWslBVDrXN2asALIXJofB0Rn677OpgjcPKHNWwdtJHWfXd6UwgG-jLHvCH_K1FhEAiAr-R0hwQsYEy8Q7fQHjVlAQ"
;; Query time: 261 msec
;; SERVER: 1.1.1.1#53(1.1.1.1) (UDP)
;; WHEN: Mon Oct 05 20:29:44 CDT 2026
;; MSG SIZE rcvd: 239

GO a base64url TXT string comes back

NO GO empty, SERVFAIL or NXDOMAIN

what each part of this output means →

The string is different on every run, and so are the id, the Query time and the WHEN line.

What it cannot prove. It says the query arrived, not which resolver carried it or where that resolver sits. A label that was asked before can be answered from a resolver's cache, which reads as a GO the authority never saw; mint a new one every run. A label that is not x and 26 of a-z2-7 answers SERVFAIL or NXDOMAIN, which reads here as a NO GO that is not one.

Next step. On a NO GO, check the label is x and 26 of a-z2-7, then ask 1.1.1.1 directly: dig @1.1.1.1 TXT x$N.t.probe.isitdns.net.

Source. RFC 1035, section 3.2.1: a TTL is how long a record may be cached before the source is asked again. Base64url is RFC 4648, section 5.

See also#