DNS Propagation Checker
See what real networks around the world receive, compare every authoritative nameserver, and inspect delegation, DNSSEC, TTL and response-time evidence.
Real end-user network probes Authoritative baseline No account or saved query history
—
How to read this checkPlain-language guide and status key
Start with Valid answers: the share of completed checks matching the selected baseline. Review different, error and timeout rows next. If source servers unexpectedly disagree outside confirmed GeoDNS, or DNSSEC is bogus, fix that first—waiting for TTLs will not help.
- Read the verdict. It compares recursive caches with the selected baseline and checks source health separately.
- Check valid answers. No-response probes are reported separately, not counted as wrong.
- Inspect outliers. Open evidence for different answers, DNS errors and unusual regions.
- Use TTL carefully. It estimates one cache's remaining lifetime, not a universal deadline.
Result status key
Share & export
Geographic and value distribution
Map key: green means every observation completed and was valid; amber means results differ or include no-response probes; red means every probe ended without a usable result; unfilled means no probe or only pending probes. Regions describe probes, not exact resolver locations.
Observed answer clusters
Each cluster groups identical canonical answer sets, or the same no-answer/error status. The largest cluster is the most common, not automatically the correct one.
Resolver observations
What do the table columns mean?
- Status
- Interpretation against the selected baseline; the smaller line is the raw DNS response code.
- City / country
- Where the test probe ran—not necessarily the resolver's physical location.
- ASN / network
- The network hosting the probe. Diversity here strengthens coverage.
- Resolver
- The recursive DNS service queried; public resolvers may route to a nearby anycast site.
- Answer
- The canonicalized record set. Order, duplicates, hostname case and equivalent IPv6 spelling are normalized.
- Remaining TTL
- How long this cache may retain the answer; it is not a countdown for every user.
- DNS time
- Probe-to-resolver lookup time, not website page-load time.
- DNSSEC evidence
- A resolver claim. Independent chain validation is in the DNSSEC panel.
- Raw detail
- The exact diagnostic transcript plus network, resolver and DNSSEC context.
| DNSSEC evidence | Raw detail |
|---|
Authoritative nameservers
Direct checks show each source RRset, configured TTL, response time and SOA data. Unexpected disagreement is highlighted; confirmed regional GeoDNS answers are treated separately.
Delegation path
Follow the root-to-authority chain and compare parent NS, child NS and glue records.
DNSSEC chain
Independent DS → DNSKEY → RRSIG validation. Resolver AD flags remain labelled as resolver claims.
Continental delegation traces
Compare root-to-authority results from six continental vantage points.
Protocol and CNAME diagnostics
Inspect transport behavior, EDNS, truncation, TCP fallback and the complete CNAME chain.
Actionable warnings
Prioritized configuration and reachability findings from authoritative, delegation and DNSSEC analysis.