Plan a migration
Capture DNS, mail, certificate and routing evidence before a provider or nameserver change.
Domain & IP intelligence
DNS, ownership, hosting, ASN, location and security signals, resolved into one readable lookup.
Check the spelling and try again.
Reading address, mail, nameserver and policy records.
What the result means
DNSTrace.dev connects answers from DNS, regional registries, public routing data, certificate transparency and live HTTPS responses. Results distinguish observed evidence from inference, so a CDN edge is never presented as a hidden origin server.
Diagnostic field guide
Three practical ways to use this lookup, followed by the boundary the result cannot cross.
Reviewed Sep 2026Capture DNS, mail, certificate and routing evidence before a provider or nameserver change.
Separate the DNS operator, public delivery edge, mail provider and network announcer instead of treating them as one company.
Check whether a failure begins at resolution, registration, routing, TLS, HTTP or email policy.
How to read the result
Common questions
A domain can expose DNS records, registry data, mail routes, certificate evidence, public web responses and the networks announcing its resolved addresses. Each signal describes a different layer.
No. It reads public records and ordinary public responses. It does not attempt exploitation, port scanning, authentication or access to private systems.
Quiet by design
Public infrastructure research should not require a private profile. DNSTrace keeps only the operational signals needed to run a reliable, fair service.
Read the privacy approachNo ad pixels, cross-site profiles or sale of lookup history.
Uptime, latency and failure signals, plus cookieless visit counts on our own server.
30 requests/min · 6 heavy checks/min
One private check protects every lookup.
Choose the question
Each tool has its own indexable page and opens the report at the evidence that answers its question.
Every address, mail, verification and policy record.
A · AAAA · MX · TXT · NS GLBGlobal DNSLive answers from probes across ten countries.
Answer · TTL · resolver · latency RDPWHOIS / RDAPRegistrar, dates, status and published contacts.
Registry + registrar data IPIP lookupNetwork owner, route, reverse name and region.
IPv4 + IPv6 ASNASN lookupAutonomous system, BGP prefix and RPKI state.
RIPEstat routing signals TLSSSL checkerIssuer, validity, names and fingerprint.
Live certificate check MXMX lookupReceiving servers, preference and detected mail provider.
Mail routing records MAILEmail securityComplete validation across authentication and transport.
Seven policy controls SPFSPF checkerSender policy, authorization strength and DNS-limit risks.
Policy syntax + safety DMARCDMARC checkerEnforcement, alignment, rollout and report destinations.
Anti-spoofing policy DKIMDKIM checkerSelector lookup, key presence, type and base64 form.
Public signing keys STSMTA-STS checkerDNS marker plus live HTTPS transport policy.
Encrypted inbound mail RPTTLS-RPT checkerSMTP TLS report policy and destination validation.
Transport visibility HDRSecurity headersBrowser protections from the final HTTPS response.
HSTS · CSP · framing · policyEvidence before certainty
A nameserver identifies the DNS operator. An edge address identifies a public delivery network. An ASN identifies the organization announcing a route. None automatically proves where a hidden origin application runs.
Field notes
Why locations disagree, what TTL controls and when to test again.
REGISTRY · 5 minWHOIS text became structured RDAPWhere registration fields come from and why some remain unpublished.
DELIVERY · 7 minAn edge address is not an originWhat public CDN and hosting signals can and cannot prove.
Agent-ready JSON
GET /api/dns?target=example.com&type=MX
Complete lookup for
These public addresses terminate at the provider's edge.
Every published answer
| Type | Host | Answer | TTL |
|---|
Certificate history + live DNS
| Host | Live DNS chain | State | Certificate evidence |
|---|
Certificate Transparency could not be reached.
Certificate transparency is historical evidence. “Not resolved” means the name did not return a current A/CNAME answer; it may be retired, internal, or IPv6-only.
Live answers around the world
Queries run on real probes in ten countries. Results may vary because of propagation, geo-routing, or resolver cache.
What answers on HTTPS
Delivery and anti-spoofing
Where traffic lands
Registry data
Signals worth noticing
Allocation authority
These records describe the organization responsible for the address range. They do not identify the individual using this IP.
Routing and operational checks