Skip to content

DNS security checker

Run 35 checks for real security issues and broken records, against a domain's public DNS and its own nameservers. No best-practice nagging.

What it checks

  • Subdomain takeover: CNAMEs to deleted cloud resources or unregistered domains.
  • Nameservers whose own domain has lapsed, so anyone could take over answers.
  • Zone transfers any client can pull from each of your nameservers.
  • DNSSEC that fails validation, and retired signing algorithms.
  • SPF that lets anyone send as you, DKIM keys short enough to crack, broken DMARC, MTA-STS and TLS-RPT.
  • Private addresses, internal services and credentials published in public DNS.
  • Lame nameservers, registry mismatches and resolvers that can't resolve the domain.
Why no best-practice advice?
Missing CAA or a relaxed DMARC policy isn't a vulnerability, and mixing advice with real problems hides the problems. Every finding here is something exposed right now or a record that's broken.
Which resolvers do you use?
Cloudflare, Google Public DNS, Quad9, OpenDNS and AdGuard DNS. A name counts as missing only when most of them say it doesn't exist, so one resolver's hiccup can't raise a finding.
Is it safe to run against my domain?
Yes. It sends ordinary DNS queries, one zone transfer request per nameserver and one registry lookup. Nothing is changed and nothing is stored beyond a 10-minute cache.

What the DNS security checker looks for

This tool discovers a domain’s records in public DNS, then runs a fixed set of rules against them and against the domain’s own nameservers. It reports things that are exposed or broken right now, not best-practice suggestions. That includes subdomain takeover (a CNAME pointing at a deleted cloud resource or an unregistered domain), nameservers whose own domain has lapsed, zone transfers (AXFR) that any client can pull, DNSSEC that fails validation or uses a retired algorithm, SPF that authorises any sender, DKIM keys short enough to be cracked, broken DMARC, MTA-STS or TLS-RPT, private addresses or credentials published in public DNS, and lame or unresolvable nameservers.

The live checks run through five validating public resolvers: Cloudflare, Google Public DNS, Quad9, OpenDNS and AdGuard DNS. A name is only treated as missing when most of them agree it does not exist, so a single resolver’s hiccup will not raise a finding.

How to use it

Enter a registered apex domain such as example.com and select Check security. The tool sends ordinary DNS queries, one zone-transfer request per nameserver, and one registry lookup. It does not change anything, and it caches results for about ten minutes.

Reading the results

The summary panel groups findings by severity and lists each one with the record it came from. The note that reads Based on N records found in public DNS is the important caveat: public DNS cannot enumerate every record, so records the discovery step did not find were never checked. If the domain’s discovery was partial the note says so.

What it can miss

Because it works from public DNS only, it sees the records it can find by querying known names, not the full zone. Records with no public reference (obscure hostnames, internal-only subdomains) will not appear. A clean result means nothing broken was found in what was visible, not that the whole zone is clean. Connecting a provider read-only checks every record in the zone.

Next steps