DNS security checker
Run 35 checks for real security issues and broken records, against a domain's public DNS and its own nameservers. No best-practice nagging.
What it checks
- Subdomain takeover: CNAMEs to deleted cloud resources or unregistered domains.
- Nameservers whose own domain has lapsed, so anyone could take over answers.
- Zone transfers any client can pull from each of your nameservers.
- DNSSEC that fails validation, and retired signing algorithms.
- SPF that lets anyone send as you, DKIM keys short enough to crack, broken DMARC, MTA-STS and TLS-RPT.
- Private addresses, internal services and credentials published in public DNS.
- Lame nameservers, registry mismatches and resolvers that can't resolve the domain.
Why no best-practice advice?
Which resolvers do you use?
Is it safe to run against my domain?
What the DNS security checker looks for
This tool discovers a domain’s records in public DNS, then runs a fixed set of rules against them and against the domain’s own nameservers. It reports things that are exposed or broken right now, not best-practice suggestions. That includes subdomain takeover (a CNAME pointing at a deleted cloud resource or an unregistered domain), nameservers whose own domain has lapsed, zone transfers (AXFR) that any client can pull, DNSSEC that fails validation or uses a retired algorithm, SPF that authorises any sender, DKIM keys short enough to be cracked, broken DMARC, MTA-STS or TLS-RPT, private addresses or credentials published in public DNS, and lame or unresolvable nameservers.
The live checks run through five validating public resolvers: Cloudflare, Google Public DNS, Quad9, OpenDNS and AdGuard DNS. A name is only treated as missing when most of them agree it does not exist, so a single resolver’s hiccup will not raise a finding.
How to use it
Enter a registered apex domain such as example.com and select Check security. The tool sends ordinary DNS queries, one zone-transfer request per nameserver, and one registry lookup. It does not change anything, and it caches results for about ten minutes.
Reading the results
The summary panel groups findings by severity and lists each one with the record it came from. The note that reads Based on N records found in public DNS is the important caveat: public DNS cannot enumerate every record, so records the discovery step did not find were never checked. If the domain’s discovery was partial the note says so.
What it can miss
Because it works from public DNS only, it sees the records it can find by querying known names, not the full zone. Records with no public reference (obscure hostnames, internal-only subdomains) will not appear. A clean result means nothing broken was found in what was visible, not that the whole zone is clean. Connecting a provider read-only checks every record in the zone.
Next steps
- How the security checks work documents every rule.
- Broken DNSSEC? Confirm the DS mismatch with the DNSSEC checker.
- Fixing SPF lookups is covered in the SPF 10-lookup limit.