Website DNS Checker
Test whether a domain's DNS is set up soundly. Instead of listing raw records, this checker runs a series of health checks and tells you what passes, what could fail under pressure and what is missing, for the website and for email.
- Encrypted connection
- No sign-up
- Free to use
How to use Website DNS Checker
- Enter the domain of the website.
- Select Check DNS health.
- Read the summary: failed checks first, then warnings.
- Go through the four groups, name servers, zone settings, website records and email records, and use the links to inspect any record in detail.
Website DNS Checker features
Name server checks
Number of name servers, whether each one resolves and whether they sit on separate networks.
www and bare domain
Confirms that both forms of the address lead somewhere and flags broken aliases.
Zone timers
Evaluates the SOA expire and negative-caching values against common recommendations.
IPv6 and CAA
Reports IPv6 support and whether certificate issuance is restricted.
Email readiness
MX, SPF and DMARC status in one place.
Explained results
Every check states the fact it found and why it matters.
When to use Website DNS Checker
- Reviewing a domain after moving it to a new DNS provider.
- A pre-launch check for a new website.
- Diagnosing why a site works with www but not without, or the other way round.
- A periodic audit of the domains you are responsible for.
Website DNS Checker FAQ
How is this different from a DNS lookup?
A lookup shows the records that exist. This checker interprets them: it tests whether the combination is complete and robust, for example whether there are enough name servers, whether www resolves and whether mail authentication is in place. Use the DNS Lookup tool when you want to see a specific record.
Why does a domain need at least two name servers?
DNS is the first step of every visit and every email. If the only name server is unreachable, nothing else works, however healthy the web server is. Two or more servers, ideally in different networks, remove that single point of failure. The standards require a minimum of two.
Should both example.com and www.example.com resolve?
Yes. People type both, and links to both exist. One should be the main address and the other should redirect to it, but both need DNS records for that redirect to happen.
What are the SOA timers?
The start-of-authority record contains values that control how secondary name servers synchronise and how long “no such name” answers are cached. The expire value decides how long secondaries keep serving the zone when the primary is down, and the last value sets the negative caching time.
What is a CAA record and do I need one?
A Certification Authority Authorization record lists which certificate authorities may issue certificates for the domain. It is optional. Without it, any authority may issue; with it, a certificate request to another authority is refused, which reduces the risk of mis-issuance.
Is the lack of IPv6 a problem?
Not today. Networks that only offer IPv6 to their users provide translation to reach IPv4 sites. Publishing AAAA records lets those visitors connect directly, which can be slightly faster, so it is reported as a note rather than a warning.
What makes a DNS setup robust
DNS failures are among the most disruptive a website can suffer, because they take everything down together: the site, its subdomains, the email, the API. They are also unusually quiet while they develop. A domain with a single working name server behaves perfectly until that server has a bad day. A missing www record is invisible to an owner who always types the bare domain. This is why a health check looks for weaknesses, not just for errors that are already causing trouble.
The foundation is delegation. The registry points the domain at a set of name servers, and those servers must all exist, resolve and answer for the zone. Using the name servers of a large DNS provider satisfies this almost automatically, since such providers run many machines behind each name, often with anycast routing that makes a few addresses stand for servers around the world. Self-hosted name servers need more care to avoid sitting in the same rack or network.
The second layer is completeness. A working website needs address records for every name people use, at minimum the bare domain and www. Email needs MX records, and trustworthy email needs SPF and DMARC next to them. Domains that are not meant to receive mail are better off saying so explicitly than leaving the question open.
Finally there are the settings that matter only on bad days: the SOA timers that decide how long secondary servers carry on alone, the TTLs that decide how fast a change spreads, and CAA records that limit who may issue certificates. None of them affect a normal visit, and all of them shape how gracefully the domain copes when something goes wrong.