Short answer: enter a domain and a record type. We ask 18 public resolvers over HTTPS, show each answer with its TTL, and say whether they agree. Add the value you just set and we show which resolvers already return it.
What “propagation” really is
A DNS change doesn’t travel anywhere. Resolvers keep each answer for its TTL, the time in seconds a record may be cached before it should be discarded (RFC 1035). After you change a record, a resolver that cached the old one keeps serving it until that TTL runs out, then asks again and gets the new one. So the wait is the old TTL, and it differs resolver by resolver. If you plan a change, lower the TTL a day or more ahead and raise it again afterwards.
What this measures, and what it doesn’t
These are public resolvers, and every query leaves our server, which runs on Cloudflare’s network. Seven of them (Google, Cloudflare, Quad9, OpenDNS, AdGuard, Control D and Mullvad) don’t name a location, and several run one address from many data centres (anycast), so which server answers depends on where the query comes from and we can’t see it. The other eleven are listed by their operators as a server in one named place: eight DNS.SB servers (Frankfurt, London, New York, San Jose, Tokyo, Singapore, Sydney and Bengaluru), Applied Privacy in Vienna, UncensoredDNS’s single-location address in Copenhagen, and Switch in Zurich and Lausanne. Those answers show what a resolver in that city holds. They don’t show what visitors there get, because visitors use their own provider’s resolver.
Reading the result
- Letters. Resolvers that return exactly the same records share a letter. A is the most common answer.
- All agree. The change has reached these resolvers, or nothing changed.
- Some have no record, or an older one. The usual picture mid-change. The longest TTL shown is the most an older cached answer can last. A resolver that said “no such record” may keep saying it for the zone’s negative-caching time (RFC 2308), even after you add the record.
- Different, overlapping addresses. Normal for round robin and CDNs, which return different addresses to different resolvers.
- DNSSEC validated. The resolver says it checked the answer’s DNSSEC signatures. No label means it didn’t, which is what you see for a domain that isn’t signed.
Limits
We can’t ask your domain’s authoritative name servers directly, because they don’t speak HTTPS; compare against the value in your DNS provider’s dashboard. Quad9 blocks domains on its malicious-domain list, and Switch blocks the Swiss gambling-law list, so those two can differ for such domains. For every record type from one resolver, use the DNS lookup; for email records, the SPF, DKIM and DMARC checker.