Network · Made a little simpler

DNS checker

Look up A, AAAA, CNAME, MX, TXT, NS, SOA and CAA records through selected DNS providers. Compare configured probes, timestamps, TTLs and response details, and match an expected value locally.

Your workspaceUses network requests

Your query name is sent to ToolMellow’s server and the selected DNS providers. Regional checks use the configured probes. Results stay in this tab unless you download them.

DNS query
DNS providers
Query locations

Compare up to two providers and four configured locations. Provider comparison from one server is not a global propagation check. No automatic retries.

Compare literal, case-sensitive values exactly as shown. Only the requested record type is checked. The expected value stays in this tab and your downloaded report; it is not sent with the query.

Connecting to diagnostic server…

Three small steps.

  1. Enter a DNS name, choose a record type and select providers and configured query locations.
  2. Start the check and compare answers, DNS status, returned TTL and DNSSEC authentication.
  3. Optionally compare an expected value, inspect partial failures or authority records, and download the JSON report.

A few things to know.

One name and type per check, up to two DNS providers and four configured locations. IDNs and underscore service labels are supported; URLs, IP literals and wildcards are not. Regional results require real deployed probes. Two providers queried from one server do not prove global propagation. Queries go to the selected providers; result TTLs do not predict worldwide convergence. Expected-value matching compares only returned values of the requested type, with literal exact or contains matching; failed or truncated results are inconclusive. The expected value is not sent to providers.

How your privacy works →

A little more clarity.

Is this a global propagation map?

Results identify actual configured query probes. A location is runtime-verified only when a matching configured deployment region answered. One server comparing provider brands is not a global propagation test.

What does DNSSEC authenticated mean?

The selected resolver asserted that its answer was authenticated. An unauthenticated result can be unsigned; it is not by itself proof of a broken or malicious domain.

Why can providers disagree?

They can have different cached answers or reach different authoritative infrastructure. TTL is the remaining lifetime reported for that answer. NXDOMAIN, NODATA, SERVFAIL and HTTP/timeouts are distinct results.

Who receives my query?

ToolMellow and the selected probe/provider receive the DNS name. The broker does not forward your client address to the resolver; the resolver sees the probe address. Hosting and resolver logging policies apply.