Read DNS sources and results
Nameservers, Google, Cloudflare, DNS over HTTPS and response codes explained.
Who answered?
Authoritative nameservers publish the domain's DNS data. Public recursive resolvers look up and cache those answers for users: 1.1.1.1 is Cloudflare and 8.8.8.8 is Google Public DNS. Hover or focus a source in the app for an explanation.
DNS over HTTPS (DoH) is another transport for querying a resolver. It is not another kind of DNS record. UDP and TCP are ordinary DNS transports; a TCP retry can occur when a UDP answer is truncated.
Cloudflare API shows the provider's saved configuration. It is distinct from the public DNS response and from Cloudflare's 1.1.1.1 resolver.
What does the response mean?
Answered (NOERROR) means the DNS query completed successfully. There can still be no answer of the requested type. NXDOMAIN means the queried name was reported as nonexistent. SERVFAIL means the service could not complete the query; REFUSED means it declined it. A timeout means no usable response arrived within the request budget.
AA identifies an authoritative answer. AD means the recursive resolver reports authenticated DNSSEC data. An AD value of false is not, by itself, proof that DNSSEC is broken. Latency measures this DNS query, not your website's speed.
Technical limits
DNStracr checks DS/DNSKEY matching and validating resolvers' DNSSEC signals; it does not independently validate a full local RRSIG signature chain. An unsigned domain is a separate state, not automatically a DNS outage.
The free scan samples up to two authoritative nameservers and one parent nameserver over public IPv4. It omits TLS, RDAP and actual email delivery. Monitor and discovery checks have their own scope; always read the displayed evidence rather than treating a summary as a complete security audit.
Documentation reviewed: 8 October 2026. Results describe configured checks and available evidence, not a complete security or service-availability guarantee.
Troubleshooting and contacting Support