dns.google — DNS Report
B
86%
42
Pass
2
Warnings
0
Failures
4
Info
48
Total
Processed in 2s
● 📋 Domain Registration
PASS| Registrar | MarkMonitor Inc. |
| Registrar ID | 292 |
| Registry ID | 2C7E70B08-GOOGLE |
| Created | Apr 16, 2018 |
| Updated | Mar 20, 2026 |
| Expires | Apr 16, 2027 (243 days left) |
| DNSSEC | ✓ Signed |
| Status | client delete prohibited client transfer prohibited client update prohibited |
| RDAP Nameservers | ns1.zdns.google ns2.zdns.google ns3.zdns.google ns4.zdns.google |
● 🌐 DNS Records
PASSSOA Records (1)
| Name | Value | TTL |
|---|---|---|
| dns.google | ns1.zdns.google cloud-dns-hostmaster.google.com 1 21600 3600 259200 300 | 21600 |
NS Records (4)
| Name | Value | TTL |
|---|---|---|
| dns.google | ns4.zdns.google | 21600 |
| dns.google | ns2.zdns.google | 21600 |
| dns.google | ns3.zdns.google | 21600 |
| dns.google | ns1.zdns.google | 21600 |
A Records (2)
| Name | Value | TTL |
|---|---|---|
| dns.google | 8.8.4.4 | 900 |
| dns.google | 8.8.8.8 | 900 |
AAAA Records (2)
| Name | Value | TTL |
|---|---|---|
| dns.google | 2001:4860:4860::8888 | 900 |
| dns.google | 2001:4860:4860::8844 | 900 |
TXT Records (2)
| Name | Value | TTL |
|---|---|---|
| dns.google | https://xkcd.com/1361/ | 300 |
| dns.google | v=spf1 -all | 300 |
CAA Records (2)
| Name | Value | TTL |
|---|---|---|
| dns.google | 0 issue "pki.goog" | 86400 |
| dns.google | 128 issue "pki.goog" | 86400 |
DNSKEY Records (2)
| Name | Value | TTL |
|---|---|---|
| dns.google | Flags=256 Protocol=3 Alg=8 KeyTag=58953 | 300 |
| dns.google | Flags=257 Protocol=3 Alg=8 KeyTag=56044 | 300 |
● 🔗 Parent Nameservers
PASS| Nameserver | IPv4 | IPv6 | Glue |
|---|---|---|---|
| ns2.zdns.google | 216.239.34.114 | 2001:4860:4802:34::72 | Yes |
| ns1.zdns.google | 216.239.32.114 | 2001:4860:4802:32::72 | Yes |
| ns4.zdns.google | 216.239.38.114 | 2001:4860:4802:38::72 | Yes |
| ns3.zdns.google | 216.239.36.114 | 2001:4860:4802:36::72 | Yes |
| ✓ | Nameservers Listed at Parent | The parent TLD nameserver has 4 nameserver(s) listed for dns.google.ns1.zdns.google ns3.zdns.google ns4.zdns.google ns2.zdns.google |
| ✓ | Minimum Nameserver Count | 4 nameservers found. Good redundancy. |
| ✓ | Glue Record: ns2.zdns.google | Glue record found for ns2.zdns.google: 216.239.34.114, 2001:4860:4802:34::72 |
| ✓ | Public IP: ns2.zdns.google | Nameserver ns2.zdns.google has a public IP address. |
| ✓ | Glue Record: ns1.zdns.google | Glue record found for ns1.zdns.google: 216.239.32.114, 2001:4860:4802:32::72 |
| ✓ | Public IP: ns1.zdns.google | Nameserver ns1.zdns.google has a public IP address. |
| ✓ | Glue Record: ns4.zdns.google | Glue record found for ns4.zdns.google: 216.239.38.114, 2001:4860:4802:38::72 |
| ✓ | Public IP: ns4.zdns.google | Nameserver ns4.zdns.google has a public IP address. |
| ✓ | Glue Record: ns3.zdns.google | Glue record found for ns3.zdns.google: 216.239.36.114, 2001:4860:4802:36::72 |
| ✓ | Public IP: ns3.zdns.google | Nameserver ns3.zdns.google has a public IP address. |
| ✓ | Parent/Auth NS Consistency | The nameservers listed at the parent match those returned by the authoritative nameservers. |
● 🖥️ Authoritative Nameservers
PASS| Nameserver | UDP | TCP | Auth | Recursion | IPv6 | Latency |
|---|---|---|---|---|---|---|
| ns1.zdns.google | ✓ | ✓ | ✓ | Closed | ✓ | 47ms |
| ns2.zdns.google | ✓ | ✓ | ✓ | Closed | ✓ | 180ms |
| ns3.zdns.google | ✓ | ✓ | ✓ | Closed | ✓ | 72ms |
| ns4.zdns.google | ✓ | ✓ | ✓ | Closed | ✓ | 40ms |
| ✓ | Authoritative Nameservers Found | Found 4 authoritative nameserver(s): ns4.zdns.google, ns1.zdns.google, ns3.zdns.google, ns2.zdns.google |
| ✓ | All Nameservers Respond | All authoritative nameservers are responding to DNS queries. |
| ✓ | UDP DNS (Port 53) | At least one nameserver is responding to UDP DNS queries on port 53. |
| ✓ | TCP DNS (Port 53) | TCP DNS queries are supported. Required for large responses and DNSSEC. |
| ✓ | Authoritative Response | At least one nameserver returns an authoritative (AA) response for the zone. |
| ✓ | Open Recursion | Nameservers do not appear to answer recursive queries from outside. Good. |
| ✓ | Public IP Addresses | All nameservers have publicly routable IP addresses. |
| ✓ | IPv6 Support | At least one nameserver has an IPv6 (AAAA) address. |
| ✓ | NS Record Consistency | All authoritative nameservers return identical NS records. |
| ✓ | Multiple Network Diversity | Nameservers appear to be on different subnets/networks. Good resilience. |
● 📄 SOA Record
WARNING| Primary NS (MNAME) | ns1.zdns.google |
| Email (RNAME) | cloud-dns-hostmaster.google.com |
| Serial | 1 |
| Refresh | 21600 (6 hours) |
| Retry | 3600 (1 hour) |
| Expire | 259200 (3 days) |
| Minimum TTL | 300 (5 min) |
| ✓ | SOA Record Exists | SOA record found for dns.google. |
| ✓ | SOA MNAME | SOA MNAME (ns1.zdns.google) is listed as an authoritative nameserver. |
| ✓ | SOA RNAME | SOA contact email: cloud-dns-hostmaster@google.com |
| ℹ | SOA Serial Format | SOA serial is 1. The recommended format is YYYYMMDDNN (e.g., 2024010101). |
| ✓ | SOA Serial Consistency | All authoritative nameservers return the same SOA serial number. |
| ✓ | SOA Refresh | SOA Refresh is 21600 seconds (6h). Reasonable value. |
| ✓ | SOA Retry | SOA Retry is 3600 seconds. |
| ⚠ | SOA Expire | SOA Expire is 259200 seconds (3 days). RFC 1912 recommends 2-4 weeks. |
| ✓ | SOA Minimum TTL | SOA Minimum TTL (negative caching) is 300 seconds. |
● 📧 Mail Servers (MX)
INFONo MX records found. This domain cannot receive email.
| ℹ | MX Records | No MX records found for dns.google. This domain cannot receive email. |
● 🌍 WWW / Web
WARNINGNo WWW records found.
| ⚠ | WWW Record | No A, AAAA, or CNAME record found for www.dns.google. Visitors to www.dns.google will receive an error. |
● 🔒 DNSSEC
PASS| Enabled | Yes |
| DS Records | KeyTag=56044 Alg=8 DigestType=2 Digest=1B0A7E90AA6B1AC65AA5B573EFC44ABF6CB2559444251B997103D2E40C351B08 |
| DNSKEY | KeyTag=58953 Alg=RSASHA256 Flags=256, KeyTag=56044 Alg=RSASHA256 Flags=257 |
| Algorithms | RSASHA256, RSASHA256 |
Chain of Trust
| Level | DS | DNSKEY | RRSIG | Status |
|---|---|---|---|---|
| . | — | ✓ | ✓ | PASS |
| ✓ | ✓ | ✓ | PASS | |
| dns.google | ✓ | ✓ | ✓ | PASS |
| ✓ | DNSSEC Enabled | DNSSEC appears to be enabled for dns.google. |
| ✓ | DS Record | DS record(s) found at the parent zone. The delegation is signed.KeyTag=56044 Alg=8 DigestType=2 Digest=1B0A7E90AA6B1AC65AA5B573EFC44ABF6CB2559444251B997103D2E40C351B08 |
| ✓ | DNSKEY Record | DNSKEY record(s) found in the zone.KeyTag=58953 Alg=RSASHA256 Flags=256 KeyTag=56044 Alg=RSASHA256 Flags=257 |
| ✓ | DNSSEC Algorithm | Algorithm RSASHA256 is in use. This is a strong algorithm. |
| ✓ | DNSSEC Algorithm | Algorithm RSASHA256 is in use. This is a strong algorithm. |
| ✓ | RRSIG Records | RRSIG (signature) records found. Zone records are signed.TypeCovered=DNSKEY Alg=8 KeyTag=56044 Signer=dns.google TypeCovered=SOA Alg=8 KeyTag=58953 Signer=dns.google TypeCovered=NS Alg=8 KeyTag=58953 Signer=dns.google |
| ✓ | DNSSEC Chain | Chain of trust: ✓ . → ✓ google → ✓ dns.google |
● 🛡️ Email Security
INFOSPF (Sender Policy Framework)
| Record | v=spf1 -all |
| All Mechanism | -all |
| DNS Lookups | 0 / 10 max |
DMARC (Domain-based Message Authentication)
| Record | v=DMARC1; p=reject; rua=mailto:mailauth-reports@google.com |
| Policy (p=) | reject |
| Aggregate Reports (rua) | mailto:mailauth-reports@google.com |
CAA (Certificate Authority Authorization)
| Flag | Tag | Value |
|---|---|---|
| 128 | issue | pki.goog |
| 0 | issue | pki.goog |
| ✓ | SPF Record | SPF record found.v=spf1 -all |
| ✓ | SPF All Mechanism | SPF record uses '-all' (fail). Non-listed senders will be rejected. Good. |
| ✓ | SPF DNS Lookup Count | SPF record uses approximately 0 DNS lookups (limit is 10). |
| ✓ | DMARC Record | DMARC record found.v=DMARC1; p=reject; rua=mailto:mailauth-reports@google.com |
| ✓ | DMARC Policy | DMARC policy is 'reject'. Failing emails will be rejected. Maximum protection. |
| ✓ | DMARC Reporting (rua) | Aggregate reports (rua) will be sent to: mailto:mailauth-reports@google.com |
| ✓ | CAA Records | CAA records found (2). Certificate issuance is restricted. |
| ℹ | CAA issuewild Tag | No 'issuewild' CAA tag. The 'issue' policy applies to wildcard certificates too, unless overridden. |
| ℹ | CAA iodef Tag | No 'iodef' CAA tag. Consider adding an iodef tag to receive reports of unauthorized certificate requests. |
● 📡 DNS Propagation
PASS| Status | Resolver | Location | Result | Latency |
|---|---|---|---|---|
| ✓ | Cloudflare 2 (1.0.0.1) | US (Cloudflare) | 8.8.4.4, 8.8.8.8 | 11ms |
| ✓ | Cloudflare (1.1.1.1) | US (Cloudflare) | 8.8.4.4, 8.8.8.8 | 11ms |
| ✓ | Google Public DNS 2 (8.8.4.4) | US (Google) | 8.8.4.4, 8.8.8.8 | 17ms |
| ✓ | Google Public DNS (8.8.8.8) | US (Google) | 8.8.8.8, 8.8.4.4 | 18ms |
| ✓ | Comodo Secure (8.26.56.26) | US (Comodo) | 8.8.8.8, 8.8.4.4 | 20ms |
| ✓ | OpenDNS (208.67.222.222) | US (OpenDNS) | 8.8.4.4, 8.8.8.8 | 17ms |
| ✓ | Quad9 (9.9.9.9) | US (Quad9) | 8.8.4.4, 8.8.8.8 | 21ms |
| ✓ | Verisign (64.6.64.6) | US (Verisign) | 8.8.8.8, 8.8.4.4 | 16ms |
| ✓ | OpenDNS 2 (208.67.220.220) | US (OpenDNS) | 8.8.8.8, 8.8.4.4 | 17ms |
| ✓ | Yandex.DNS (77.88.8.8) | RU (Yandex) | 8.8.8.8, 8.8.4.4 | 186ms |