Security and monitoring
DNS provider status
How the public DNS provider status page checks every nameserver each minute, uses six public resolvers, opens incidents and computes 30-day uptime.
3 min read
On this page
DNS provider status is a public page that shows whether each DNS provider's authoritative nameservers are answering right now, and how they've done over the last 30 days. It's measured by DNSMigrator, independent of the providers' own status pages.
What each page shows#
| Page | Shows |
|---|---|
| /dns-status | Live status of every monitored provider, a 30-day uptime leaderboard, one bar per day for each provider, downtime by day, response times and recent incidents |
/dns-status/<provider> | Each nameserver's latest answer and 24-hour uptime, the public resolver view, a 24-hour response time chart, the 30-day bar and the provider's incidents |
Each monitored provider's page under /providers links to its status page with Live DNS status.
How a check works#
- Pick a verified target. Each provider is checked against a zone it serves authoritatively: either a zone delegated to its nameservers, or a zone its nameservers answer for with authority while refusing a random zone they don't host. Providers without a verifiable zone aren't monitored.
- Query each nameserver directly. An authoritative NOERROR answer within 2 seconds counts as up. Answers slower than 1 second count as up but slow. Timeouts, SERVFAIL, REFUSED and non-authoritative answers count as failures, after one retry.
- Ask public resolvers. Cloudflare, Google Public DNS, Quad9, OpenDNS, AdGuard DNS and Control D are each asked for a new random name under the zone. The random label means the resolver can't answer from cache and has to reach the provider from its own network. NOERROR or NXDOMAIN means the provider answered.
- Decide the status. Operational means every nameserver answered. Degraded means at least one failed or was slow. Down means none answered and most public resolvers failed as well; if the resolvers still resolve the zone, the provider is shown as degraded instead.
Incidents#
An incident opens after two failing sweeps in a row and closes after three clean ones. Its severity rises to down if a later sweep is worse, and it lists the nameservers involved.
Protecting the numbers#
- Control checks. Each sweep also queries root and
.comservers. If they fail, the problem is on our side and the sweep is discarded. - Widespread failure. If more than 40% of providers fail in the same sweep, the sweep is discarded.
- Moved targets. If every nameserver of a provider cleanly refuses its target zone, the zone moved rather than the provider failing. That provider is skipped until its target is refreshed.
- More than one location. Each probe location records its own sweeps. A check only fails when most locations that reported that minute saw it fail. The page says how many locations are probing.
Data kept#
Raw checks are kept for 48 hours, hourly rollups for 35 days and incidents for 90 days.
Is this the provider's official status?
No. DNSMigrator isn't affiliated with any provider on the page. Each provider's own status page is the authority on its incidents.
Why can a provider show downtime its status page doesn't mention?
We measure individual nameservers. One anycast node or network path can fail for our locations while resolvers elsewhere retry another nameserver and never notice.
Does degraded mean my domain stopped resolving?
Usually not. Resolvers try the next nameserver when one fails, so a partial outage mostly adds latency.