dns.google — DNS Report

Scan ID: dns.google-1786881072446588444 Scanned: Aug 16, 2026
B 86%
Rescan
42 Pass
2 Warnings
0 Failures
4 Info
48 Total

Processed in 2s

📋 Domain Registration

PASS
Registrar MarkMonitor Inc.
Registrar ID 292
Registry ID 2C7E70B08-GOOGLE
Created Apr 16, 2018
Updated Mar 20, 2026
Expires Apr 16, 2027 (243 days left)
DNSSEC ✓ Signed
Status client delete prohibited client transfer prohibited client update prohibited
RDAP Nameservers ns1.zdns.google ns2.zdns.google ns3.zdns.google ns4.zdns.google

🌐 DNS Records

PASS

SOA Records (1)

Name Value TTL
dns.google ns1.zdns.google cloud-dns-hostmaster.google.com 1 21600 3600 259200 300 21600

NS Records (4)

Name Value TTL
dns.google ns4.zdns.google 21600
dns.google ns2.zdns.google 21600
dns.google ns3.zdns.google 21600
dns.google ns1.zdns.google 21600

A Records (2)

Name Value TTL
dns.google 8.8.4.4 900
dns.google 8.8.8.8 900

AAAA Records (2)

Name Value TTL
dns.google 2001:4860:4860::8888 900
dns.google 2001:4860:4860::8844 900

TXT Records (2)

Name Value TTL
dns.google https://xkcd.com/1361/ 300
dns.google v=spf1 -all 300

CAA Records (2)

Name Value TTL
dns.google 0 issue "pki.goog" 86400
dns.google 128 issue "pki.goog" 86400

DNSKEY Records (2)

Name Value TTL
dns.google Flags=256 Protocol=3 Alg=8 KeyTag=58953 300
dns.google Flags=257 Protocol=3 Alg=8 KeyTag=56044 300

🔗 Parent Nameservers

PASS
NameserverIPv4IPv6Glue
ns2.zdns.google 216.239.34.114 2001:4860:4802:34::72 Yes
ns1.zdns.google 216.239.32.114 2001:4860:4802:32::72 Yes
ns4.zdns.google 216.239.38.114 2001:4860:4802:38::72 Yes
ns3.zdns.google 216.239.36.114 2001:4860:4802:36::72 Yes
Nameservers Listed at ParentThe parent TLD nameserver has 4 nameserver(s) listed for dns.google.
ns1.zdns.google
ns3.zdns.google
ns4.zdns.google
ns2.zdns.google
Minimum Nameserver Count4 nameservers found. Good redundancy.
Glue Record: ns2.zdns.googleGlue record found for ns2.zdns.google: 216.239.34.114, 2001:4860:4802:34::72
Public IP: ns2.zdns.googleNameserver ns2.zdns.google has a public IP address.
Glue Record: ns1.zdns.googleGlue record found for ns1.zdns.google: 216.239.32.114, 2001:4860:4802:32::72
Public IP: ns1.zdns.googleNameserver ns1.zdns.google has a public IP address.
Glue Record: ns4.zdns.googleGlue record found for ns4.zdns.google: 216.239.38.114, 2001:4860:4802:38::72
Public IP: ns4.zdns.googleNameserver ns4.zdns.google has a public IP address.
Glue Record: ns3.zdns.googleGlue record found for ns3.zdns.google: 216.239.36.114, 2001:4860:4802:36::72
Public IP: ns3.zdns.googleNameserver ns3.zdns.google has a public IP address.
Parent/Auth NS ConsistencyThe nameservers listed at the parent match those returned by the authoritative nameservers.

🖥️ Authoritative Nameservers

PASS
NameserverUDPTCPAuthRecursionIPv6Latency
ns1.zdns.google Closed 47ms
ns2.zdns.google Closed 180ms
ns3.zdns.google Closed 72ms
ns4.zdns.google Closed 40ms
Authoritative Nameservers FoundFound 4 authoritative nameserver(s): ns4.zdns.google, ns1.zdns.google, ns3.zdns.google, ns2.zdns.google
All Nameservers RespondAll authoritative nameservers are responding to DNS queries.
UDP DNS (Port 53)At least one nameserver is responding to UDP DNS queries on port 53.
TCP DNS (Port 53)TCP DNS queries are supported. Required for large responses and DNSSEC.
Authoritative ResponseAt least one nameserver returns an authoritative (AA) response for the zone.
Open RecursionNameservers do not appear to answer recursive queries from outside. Good.
Public IP AddressesAll nameservers have publicly routable IP addresses.
IPv6 SupportAt least one nameserver has an IPv6 (AAAA) address.
NS Record ConsistencyAll authoritative nameservers return identical NS records.
Multiple Network DiversityNameservers appear to be on different subnets/networks. Good resilience.

📄 SOA Record

WARNING
Primary NS (MNAME)ns1.zdns.google
Email (RNAME)cloud-dns-hostmaster.google.com
Serial1
Refresh21600 (6 hours)
Retry3600 (1 hour)
Expire259200 (3 days)
Minimum TTL300 (5 min)
SOA Record ExistsSOA record found for dns.google.
SOA MNAMESOA MNAME (ns1.zdns.google) is listed as an authoritative nameserver.
SOA RNAMESOA contact email: cloud-dns-hostmaster@google.com
SOA Serial FormatSOA serial is 1. The recommended format is YYYYMMDDNN (e.g., 2024010101).
SOA Serial ConsistencyAll authoritative nameservers return the same SOA serial number.
SOA RefreshSOA Refresh is 21600 seconds (6h). Reasonable value.
SOA RetrySOA Retry is 3600 seconds.
SOA ExpireSOA Expire is 259200 seconds (3 days). RFC 1912 recommends 2-4 weeks.
SOA Minimum TTLSOA Minimum TTL (negative caching) is 300 seconds.

📧 Mail Servers (MX)

INFO

No MX records found. This domain cannot receive email.

MX RecordsNo MX records found for dns.google. This domain cannot receive email.

🌍 WWW / Web

WARNING

No WWW records found.

WWW RecordNo A, AAAA, or CNAME record found for www.dns.google. Visitors to www.dns.google will receive an error.

🔒 DNSSEC

PASS
Enabled Yes
DS Records KeyTag=56044 Alg=8 DigestType=2 Digest=1B0A7E90AA6B1AC65AA5B573EFC44ABF6CB2559444251B997103D2E40C351B08
DNSKEY KeyTag=58953 Alg=RSASHA256 Flags=256, KeyTag=56044 Alg=RSASHA256 Flags=257
Algorithms RSASHA256, RSASHA256

Chain of Trust

LevelDSDNSKEYRRSIGStatus
. PASS
google PASS
dns.google PASS
DNSSEC EnabledDNSSEC appears to be enabled for dns.google.
DS RecordDS record(s) found at the parent zone. The delegation is signed.
KeyTag=56044 Alg=8 DigestType=2 Digest=1B0A7E90AA6B1AC65AA5B573EFC44ABF6CB2559444251B997103D2E40C351B08
DNSKEY RecordDNSKEY record(s) found in the zone.
KeyTag=58953 Alg=RSASHA256 Flags=256
KeyTag=56044 Alg=RSASHA256 Flags=257
DNSSEC AlgorithmAlgorithm RSASHA256 is in use. This is a strong algorithm.
DNSSEC AlgorithmAlgorithm RSASHA256 is in use. This is a strong algorithm.
RRSIG RecordsRRSIG (signature) records found. Zone records are signed.
TypeCovered=DNSKEY Alg=8 KeyTag=56044 Signer=dns.google
TypeCovered=SOA Alg=8 KeyTag=58953 Signer=dns.google
TypeCovered=NS Alg=8 KeyTag=58953 Signer=dns.google
DNSSEC ChainChain of trust: ✓ . → ✓ google → ✓ dns.google

🛡️ Email Security

INFO

SPF (Sender Policy Framework)

Recordv=spf1 -all
All Mechanism -all
DNS Lookups0 / 10 max

DMARC (Domain-based Message Authentication)

Recordv=DMARC1; p=reject; rua=mailto:mailauth-reports@google.com
Policy (p=)reject
Aggregate Reports (rua)mailto:mailauth-reports@google.com

CAA (Certificate Authority Authorization)

FlagTagValue
128 issue pki.goog
0 issue pki.goog
SPF RecordSPF record found.
v=spf1 -all
SPF All MechanismSPF record uses '-all' (fail). Non-listed senders will be rejected. Good.
SPF DNS Lookup CountSPF record uses approximately 0 DNS lookups (limit is 10).
DMARC RecordDMARC record found.
v=DMARC1; p=reject; rua=mailto:mailauth-reports@google.com
DMARC PolicyDMARC policy is 'reject'. Failing emails will be rejected. Maximum protection.
DMARC Reporting (rua)Aggregate reports (rua) will be sent to: mailto:mailauth-reports@google.com
CAA RecordsCAA records found (2). Certificate issuance is restricted.
CAA issuewild TagNo 'issuewild' CAA tag. The 'issue' policy applies to wildcard certificates too, unless overridden.
CAA iodef TagNo 'iodef' CAA tag. Consider adding an iodef tag to receive reports of unauthorized certificate requests.

📡 DNS Propagation

PASS
StatusResolverLocationResultLatency
Cloudflare 2 (1.0.0.1) US (Cloudflare) 8.8.4.4, 8.8.8.8 11ms
Cloudflare (1.1.1.1) US (Cloudflare) 8.8.4.4, 8.8.8.8 11ms
Google Public DNS 2 (8.8.4.4) US (Google) 8.8.4.4, 8.8.8.8 17ms
Google Public DNS (8.8.8.8) US (Google) 8.8.8.8, 8.8.4.4 18ms
Comodo Secure (8.26.56.26) US (Comodo) 8.8.8.8, 8.8.4.4 20ms
OpenDNS (208.67.222.222) US (OpenDNS) 8.8.4.4, 8.8.8.8 17ms
Quad9 (9.9.9.9) US (Quad9) 8.8.4.4, 8.8.8.8 21ms
Verisign (64.6.64.6) US (Verisign) 8.8.8.8, 8.8.4.4 16ms
OpenDNS 2 (208.67.220.220) US (OpenDNS) 8.8.8.8, 8.8.4.4 17ms
Yandex.DNS (77.88.8.8) RU (Yandex) 8.8.8.8, 8.8.4.4 186ms