DNS
DNS
| List of tools tagged as DNS |
|---|
|
ACME DNS Challenge Readiness Check
Check ACME DNS-01 readiness before retrying issuance with exact TXT matching, delegation-path validation, and public-resolver cache hints.
|
|
ACME HTTP 01 Readiness Validator
Check ACME HTTP-01 retry readiness with a weighted evidence review of the public challenge route and a clear fix-before-retry verdict.
|
|
Alternative DCV Checker
Check alternative certificate DCV proofs across DNS and web paths, including CSR-derived values and per-host mismatch or transport evidence.
|
|
BIMI Record Generator
Build a BIMI DNS TXT record for your selector and provider while checking DMARC posture, logo evidence and publication readiness.
|
|
BIMI Validation Report
Check a domain's BIMI readiness across DMARC, logo SVG and certificate evidence with live public DNS results plus prioritized fix notes.
|
|
Blacklist Checker (DNSBL/RBL)
Check a mail host or sender IP across selected DNSBLs, distinguish policy listings from resolver errors, and inspect provider evidence.
|
|
CAA Validation Report
Check a hostname's CAA policy through its effective DNS record set and wildcard rules, with issuer findings and public resolver evidence.
|
|
DANE TLSA Validation Report
Validate DANE TLSA records across mail or direct TLS routes with DNSSEC evidence, record checks, and optional certificate digest comparison.
|
|
DKIM DNS Record Generator
Build a DKIM TXT record from a selector and public key with validation and DNS string splitting, plus rollout checks before publishing.
|
|
DKIM Validation Report
Check a DKIM selector in public DNS and review its record count, key strength and policy tags with clear testing and resolver evidence.
|
|
DMARC DNS Record Generator
Build a current or legacy DMARC TXT record with policy inheritance and reporting destinations plus DNS string splitting and rollout review.
|
|
DMARC Validation Report
Validate a domain's DMARC policy and check syntax, alignment and external report receivers before making stricter mail enforcement changes.
|
|
DNS Cache Capacity Calculator
Estimate DNS resolver cache memory from insert churn and TTL, then compare budget headroom with upstream QPS and hit-versus-miss latency.
|
|
DNS Configuration Report
Audit a domain's public DNS for authority, address and mail-policy gaps while comparing TTL horizons and resolver-visible evidence across common records.
|
|
DNS Delegation Trace Analyzer
Trace a public hostname through DNS delegation and aliases, compare resolver views, and inspect DNSSEC or negative-cache clues.
|
|
DNS Denial Proof Report
Investigate NXDOMAIN or NODATA using recursive resolver evidence plus NSEC or NSEC3 coverage, DNSSEC clues and negative-cache retry timing.
|
|
DNS Glue & Delegation Check
Check DNS glue and delegation for a public zone, compare resolver views, and identify missing NS addresses, aliases, or DS evidence.
|
|
DNS Propagation Checker
Check DNS propagation across public resolvers, compare the intended record set, and identify cache holdouts with TTL and failure evidence.
|
|
DNS Record Enumerator
Enumerate public DNS records for a domain or IP through Cloudflare or Google, compare query coverage, and flag mail or DNSSEC gaps.
|
|
DNS Record Lookup
Look up DNS records for a domain, URL or IP through Google or Cloudflare with response codes, returned TTL evidence and DNSSEC flags.
|
|
DNS TTL Change Window Calculator
Plan a DNS TTL cutover window from cache-drain and observation timing, including negative-cache checks and resolver refresh pressure.
|
|
DNS Wildcard Behavior Check
Test DNS wildcard behavior with random public resolver probes and distinguish broad matches, branch boundaries, mixed views, and cached negatives.
|
|
DNS Zone File Generator
Draft a BIND or provider-ready DNS zone file with normalized records, SOA and TTL checks, plus mail and DNSSEC review warnings.
|
|
DNS Zone File Validator
Validate a DNS zone file before import, uncover authority and TTL conflicts, and inspect expanded records without uploading the source.
|
|
DNSSEC Validator
Validate a domain's DNSSEC trust evidence from parent DS through DNSKEY signatures and resolver AD signals with a focused 15-check report.
|
|
DoH Query Packet Crafter
Build an exact DNS-over-HTTPS query packet, inspect its wire fields and EDNS options, then replay it with GET or POST against a resolver.
|
|
EDNS Client Subnet (ECS) Tester
Compare DNS answers with and without an EDNS Client Subnet hint, then inspect answer steering, echoed scope, TTL drift, and privacy clues.
|
|
EDNS Options Inspector
Inspect EDNS OPT responses from public DNS-over-HTTPS resolvers, compare requested and returned options, and keep replay evidence.
|
|
Email Header Analyzer
Inspect raw email headers locally to trace relay delays and compare recorded SPF, DKIM and DMARC evidence while spotting sender mismatches.
|
|
Hostname Naming Standard Checker
Audit hostname inventories against RFC and Kubernetes syntax, organization regex rules and duplicate policy with browser-local evidence.
|
|
Internet Protocol (IP) Geolocation Finder
Check a public IP, hostname or URL for approximate location and network-owner clues with optional reverse DNS and clear evidence limits.
|
|
MTA-STS Validator
Check an email domain's MTA-STS TXT and HTTPS policy, then review MX patterns and the policy-host certificate before enforcement.
|
|
MX Record Lookup
Inspect a domain's MX route and compare public DNS answers while catching Null MX conflicts, unresolved exchanges, and alias targets.
|
|
Nameserver Health Check
Check a domain’s resolver-visible nameserver set and verify address coverage, SOA presence, and cross-resolver drift before a DNS cutover.
|
|
Punycode IDN Converter
Convert Unicode hostnames and xn-- Punycode labels in your browser with DNS length checks, normalization choices and mixed-script warnings.
|
|
Resolver Policy Difference Comparator
Compare public DNS answers across open and filtered profiles to separate policy splits from cache or DNSSEC drift with repeatable evidence.
|
|
Reverse DNS (PTR) Checker
Check PTR records for an IP or hostname, verify forward-confirmed reverse DNS, and compare expected names or public resolver views.
|
|
Reverse DNS Zone Generator
Generate an IPv4 reverse DNS zone with PTR records and SOA validation plus RFC 2317 classless delegation and parent-zone CNAME guidance.
|
|
SMIMEA / OPENPGPKEY Lookup
Look up SMIMEA or OPENPGPKEY records for a mailbox and derive its RFC owner name with DNSSEC and resolver evidence plus cache and payload details.
|
|
SPF Record Generator
Build an SPF TXT record from real sender paths with ordered mechanisms and lookup-budget planning plus DNS packaging and rollout checks.
|
|
SPF Validation Report
Check a domain's SPF record, trace include and redirect dependencies, and flag duplicate policies or lookup-budget risks from public DNS.
|
|
SRV / NAPTR Service Discovery Check
Trace SIP/SIPS, XMPP, or LDAP discovery through NAPTR and SRV to terminal addresses with optional public resolver comparison.
|
|
TLS-RPT Record Validator
Validate a TLS-RPT policy from live DNS or pasted text, check report destinations and RFC rules, then build a reviewable TXT record.
|
|
Trace CNAME Alias Chain
Trace every visible CNAME hop for a public hostname and compare resolver views before verifying the terminal DNS answer and provider suffix.
|
|
URL Blacklist Status Lookup
Check a suspicious URL with Safe Browsing and SURBL plus weighted string clues, then review every source's scope and gaps before choosing a safer next step.
|
|
WHOIS / RDAP Lookup
Check domain registration data through RDAP with WHOIS fallback, then review expiry timing, nameservers and evidence coverage for follow-up.
|
|
dnsmasq DHCP Config Generator
Generate a dnsmasq IPv4 DHCP scope with CIDR and pool checks plus reservations, client options and optional PXE lines for a review-ready config.
|