LaunchRanked

DNS propagation checker

Enter a domain and a record type. We ask 18 public DNS resolvers over HTTPS, including servers in cities on four continents, show each answer with its TTL and say whether they agree.

Subdomains work, and so do names like _dmarc.example.com.

Check for a value you just set (optional)

An IPv4 address per line, such as 203.0.113.10. We then show which resolvers already return it.

Short answer: enter a domain and a record type. We ask 18 public resolvers over HTTPS, show each answer with its TTL, and say whether they agree. Add the value you just set and we show which resolvers already return it.

What “propagation” really is

A DNS change doesn’t travel anywhere. Resolvers keep each answer for its TTL, the time in seconds a record may be cached before it should be discarded (RFC 1035). After you change a record, a resolver that cached the old one keeps serving it until that TTL runs out, then asks again and gets the new one. So the wait is the old TTL, and it differs resolver by resolver. If you plan a change, lower the TTL a day or more ahead and raise it again afterwards.

What this measures, and what it doesn’t

These are public resolvers, and every query leaves our server, which runs on Cloudflare’s network. Seven of them (Google, Cloudflare, Quad9, OpenDNS, AdGuard, Control D and Mullvad) don’t name a location, and several run one address from many data centres (anycast), so which server answers depends on where the query comes from and we can’t see it. The other eleven are listed by their operators as a server in one named place: eight DNS.SB servers (Frankfurt, London, New York, San Jose, Tokyo, Singapore, Sydney and Bengaluru), Applied Privacy in Vienna, UncensoredDNS’s single-location address in Copenhagen, and Switch in Zurich and Lausanne. Those answers show what a resolver in that city holds. They don’t show what visitors there get, because visitors use their own provider’s resolver.

Reading the result

  • Letters. Resolvers that return exactly the same records share a letter. A is the most common answer.
  • All agree. The change has reached these resolvers, or nothing changed.
  • Some have no record, or an older one. The usual picture mid-change. The longest TTL shown is the most an older cached answer can last. A resolver that said “no such record” may keep saying it for the zone’s negative-caching time (RFC 2308), even after you add the record.
  • Different, overlapping addresses. Normal for round robin and CDNs, which return different addresses to different resolvers.
  • DNSSEC validated. The resolver says it checked the answer’s DNSSEC signatures. No label means it didn’t, which is what you see for a domain that isn’t signed.

Limits

We can’t ask your domain’s authoritative name servers directly, because they don’t speak HTTPS; compare against the value in your DNS provider’s dashboard. Quad9 blocks domains on its malicious-domain list, and Switch blocks the Swiss gambling-law list, so those two can differ for such domains. For every record type from one resolver, use the DNS lookup; for email records, the SPF, DKIM and DMARC checker.

Questions

How long does DNS propagation take?

Until the old record's TTL has run out on every resolver that cached it. That's often minutes to a few hours and at most the old TTL, which you can read in your DNS provider. Changing name servers at your registrar depends on the TTL the registry sets for the delegation, which you don't control and which can be a day or more.

Why do resolvers show different TTLs for the same record?

A resolver counts the TTL down from when it cached the record, so the number you see is the time left on its copy. A resolver that cached the record a minute ago shows a TTL a minute lower than one that cached it just now. Different TTLs on matching records are normal.

Does this show propagation in different countries?

Partly. Eight of the resolvers are DNS.SB servers in Frankfurt, London, New York, San Jose, Tokyo, Singapore, Sydney and Bengaluru, from a list DNS.SB publishes, and three more say where they are. So the answers come from resolvers in those cities. But all the queries leave our server, and your visitors use their own provider's resolver, which isn't on this list. Treat it as a sign of progress, not a count of visitors.

The records match everywhere, but I still see the old site. Why?

Your browser, operating system, router or office network may hold its own cached copy of the old answer, and a CDN or the old host may still serve the old site on a name that now points at the new one. Clear the DNS cache on your device, try another network, and check the site's certificate covers the new host.

What does SERVFAIL mean?

The resolver couldn't get a valid answer from the domain's name servers. A broken DNSSEC setup, an unreachable or misconfigured name server and a lame delegation can all cause it. If only some resolvers return it, compare the ones that validate DNSSEC with the ones that don't.

Free launch

Launching something? Get a page that ranks.

Launch free on LaunchRanked: a permanent, SEO-ready product page, a weekly leaderboard slot and a followed link after human review. No badge required.

Related free tools

See all free tools