DNS resolver comparison
After changing a record, tell a cached answer that is still waiting for its TTL from a change that was never published correctly.
How it measures
- The enclosing zone is found by walking up the name until NS records answer; the first authoritative server that resolves is queried directly, so its answer is what the zone actually publishes.
- Cloudflare (1.1.1.1), Google (8.8.8.8) and Quad9 (9.9.9.9) are queried in parallel from the same location; answer sets are normalized (sorted, lower-cased) before comparison.
- Agreement is reported per resolver against the authoritative answer and overall.
Limits
- Four observations from one network location. Resolvers in other regions, ISPs and corporate networks keep their own caches and are not measured; this is not a propagation map.
- Only the first authoritative server that resolves is queried; a secondary lagging behind the primary is not detected (compare SOA serials for that).
- Public resolvers legitimately differ from the authoritative answer until the previous record's TTL expires.
Troubleshooting
- Authoritative answer differs from all three resolvers
- The change is published but cached copies have not expired yet. Wait for the old TTL; lower TTLs before the next planned change.
- Resolvers agree with each other but not with the authoritative server, long after the TTL
- Check whether the registrar delegation points at the servers you edited; the NS record lookup shows the delegation the resolvers use.