Live DNS Record & Security Inspector

Authoritative, zero-latency DNS resolution powered directly by RFC-8484 DNS-over-HTTPS (DoH). Query any domain worldwide for root and authoritative zone records, audit SPF and DMARC mail policies, and verify DNSSEC cryptographic chain validation.

DNS-over-HTTPS Query Engine Select record types and query Cloudflare / Google Anycast resolvers in real time
Query Types:
Evaluating... DNSSEC Validation (AD Flag)
Evaluating... DMARC Policy Enforcement
Evaluating... SPF Mail Sender Authentication
Evaluating... CAA Certificate Authority Lock
Resolved RRsets for worldtldmonitor.com Queried via Cloudflare 1.1.1.1 DoH Anycast Gateway
Live Ready
Record Type Name / Label TTL Resource Record Data (RDATA)
Click "Inspect DNS Records" above to execute real-time DoH queries.
DNS Security Posture: RFC Standards & Best Practices

DNSSEC & The AD Bit (RFC 4035)

When the Authenticated Data (AD) bit is set to 1 in the DNS response header, the validating resolver has cryptographically verified the answers against the digital signatures (RRSIG) chained up to the ICANN root zone trust anchor.

DMARC Policy Enforcement (RFC 7489)

Domain-based Message Authentication, Reporting, and Conformance prevents email spoofing. A policy of p=reject instructs recipient mail servers to discard unauthenticated emails outright, while p=quarantine routes suspicious mail to spam folders.

CAA Issuer Restrictions (RFC 8659)

Certificate Authority Authorization resource records specify precisely which public CAs (such as Let's Encrypt, DigiCert, or Google Trust Services) are legally authorized to issue SSL/TLS certificates for the domain, preventing rogue or compromised CA issuance.