DNS Propagation

Compare live DNS answers from Cloudflare, Google, and dns.sb side by side.

Lookups are sent from your browser directly to Cloudflare, Google, and dns.sb DNS. Those resolvers see the domain you look up. Nothing is sent to this site's server.

Enter a domain and pick a record type, then press Look up to query Cloudflare, Google, dns.sb at the same moment.

Related tools

What it does

Looks up one record at three public resolvers at once, Cloudflare, Google, and dns.sb, and puts their answers next to each other so you can see whether a DNS change has actually landed. Each resolver reports its own cached copy with its own TTL, so when they all return the same data the record has propagated, and when one still holds the old value it tells you which one and what it is serving. It handles A, AAAA, CNAME, MX, TXT, NS, SOA, and CAA lookups, and reads the DNS status code so an NXDOMAIN or SERVFAIL shows up as plain English instead of a number.

How to use it

Type a domain name, pick the record type, and the page queries all three resolvers over DNS-over-HTTPS from your browser. Paste a full URL if that is what you have on the clipboard; the hostname is pulled out for you. The propagation row is the verdict: all resolvers agree, or answers differ and something is still cached. You can also paste a JSON bundle of saved DoH responses keyed by resolver name to compare a capture you took earlier.

Why this one

The usual propagation checkers wrap a one line answer in banner ads, a newsletter box, and an upsell to a paid monitoring plan, and every lookup goes through their servers first. This one queries the resolvers directly from your browser, so there is no middleman collecting your domain list, no account, and no rate limit beyond what the public resolvers themselves apply. It is honest about the tradeoff: those three resolvers do see the domain you look up, because that is what a DNS query is.

FAQ
Who sees my lookups?
Cloudflare, Google, and dns.sb. The queries go from your browser straight to those three public resolvers over DNS-over-HTTPS, so each of them sees the domain you asked about, the same way they would if you had set them as your system resolver. Nothing is sent to this site's server, and no lookup history is stored.
Why do resolvers disagree?
Because each one is answering from its own cache. When you change a record, resolvers keep serving the old value until the previous record's TTL runs out, and they all started their timers at different moments. A disagreement usually means one cache has expired and another has not yet. If the difference is still there long after the old TTL should have elapsed, check that every authoritative name server for the zone has the new value.
Which record types can I check?
A and AAAA for addresses, CNAME for aliases, MX for mail routing, TXT for SPF, DKIM, DMARC, and domain verification strings, NS for delegation, SOA for the zone serial, and CAA for certificate issuance policy. TXT is the one to use when you are waiting on a verification record to show up.

Keyboard shortcuts: press ? anywhere on this page to see them.