DNS & SSL Inspector FREE
Look up DNS records and inspect the SSL/TLS certificate for any domain, all in one place.
One vantage point, not the whole internet
No global propagation claim
The records shown are what one recursive resolver answered for this query, and the certificate is what one TLS handshake from our server presented. Other resolvers, regions and network paths can legitimately answer differently, especially soon after a change. DKIM is not reported as absent, because a DKIM record lives under a selector name that cannot be enumerated: if it is not checked, we say so instead of guessing.
FAQ
I changed a record and it still shows the old value. Why?
Caching. Resolvers keep an answer for as long as its TTL says they may. The TTL profile chart is there precisely to tell you how long that will be.
Is this a global propagation check?
No. It is one lookup from one resolver. A propagation check queries many resolvers in many regions; this tool deliberately does not claim to.
Why is DKIM not checked?
DKIM keys are published at selector._domainkey, and the selector is chosen by whoever sends your mail. There is no way to list selectors from outside, and guessing common names would report a confident absence that means nothing.
What does an expiring certificate actually break?
Browsers refuse the connection with a full-page interstitial, and API clients usually fail outright. It is one of the few problems that takes a whole site down at a precise, predictable second.
Need help with DNS, domains or hosting?
We can set up reliable infrastructure and ship better digital products.


