Enter a domain and pick a record type, then press Look up to query Cloudflare, Google, dns.sb at the same moment.
Related tools
- DNS LookupQuery A, AAAA, MX, TXT, and other DNS records over DNS-over-HTTPS through Cloudflare, Google, or dns.sb, no server needed.
- Browser Privacy CheckSee what your browser leaks: fingerprint surface, exposed APIs, and privacy signal irony, all analyzed on your device.
- HTTP Header InspectorSee exactly which HTTP request headers your browser sends, with a plain English explanation for User-Agent, Sec-CH-UA, and more.
- DMARC Report ViewerDrop a DMARC aggregate report and see who is sending as your domain.
- Email Header AnalyzerSPF, DKIM and DMARC verdicts plus a hop-by-hop delay waterfall from raw email headers.
- User-Agent ParserDecode a raw User-Agent string into browser name and version, rendering engine, operating system, and device type.
What it does
Looks up one record at three public resolvers at once, Cloudflare, Google, and dns.sb, and puts their answers next to each other so you can see whether a DNS change has actually landed. Each resolver reports its own cached copy with its own TTL, so when they all return the same data the record has propagated, and when one still holds the old value it tells you which one and what it is serving. It handles A, AAAA, CNAME, MX, TXT, NS, SOA, and CAA lookups, and reads the DNS status code so an NXDOMAIN or SERVFAIL shows up as plain English instead of a number.
How to use it
Type a domain name, pick the record type, and the page queries all three resolvers over DNS-over-HTTPS from your browser. Paste a full URL if that is what you have on the clipboard; the hostname is pulled out for you. The propagation row is the verdict: all resolvers agree, or answers differ and something is still cached. You can also paste a JSON bundle of saved DoH responses keyed by resolver name to compare a capture you took earlier.
Why this one
The usual propagation checkers wrap a one line answer in banner ads, a newsletter box, and an upsell to a paid monitoring plan, and every lookup goes through their servers first. This one queries the resolvers directly from your browser, so there is no middleman collecting your domain list, no account, and no rate limit beyond what the public resolvers themselves apply. It is honest about the tradeoff: those three resolvers do see the domain you look up, because that is what a DNS query is.
FAQ
- Who sees my lookups?
- Cloudflare, Google, and dns.sb. The queries go from your browser straight to those three public resolvers over DNS-over-HTTPS, so each of them sees the domain you asked about, the same way they would if you had set them as your system resolver. Nothing is sent to this site's server, and no lookup history is stored.
- Why do resolvers disagree?
- Because each one is answering from its own cache. When you change a record, resolvers keep serving the old value until the previous record's TTL runs out, and they all started their timers at different moments. A disagreement usually means one cache has expired and another has not yet. If the difference is still there long after the old TTL should have elapsed, check that every authoritative name server for the zone has the new value.
- Which record types can I check?
- A and AAAA for addresses, CNAME for aliases, MX for mail routing, TXT for SPF, DKIM, DMARC, and domain verification strings, NS for delegation, SOA for the zone serial, and CAA for certificate issuance policy. TXT is the one to use when you are waiting on a verification record to show up.
Keyboard shortcuts: press ? anywhere on this page to see them.