tarsolutiontools

Inspect DNS answers and compare independent resolver observations.

01 Input

Processed on demand. Never saved.

02 Output

⌘

A little clarity awaits.

Start with a sample or add your own input.
Your result will appear here.

Ready when you areJSON API · no cache
A CLOSER LOOK

The details behind
the result.

Understand the format, the calculation, and what to look for.

Observations

TTL, answer/authority/additional sections and DNS response codes come from controlled DoH resolvers. No custom resolver URL is accepted.

Propagation

Results represent these two resolver services, not every country or the whole internet. CDN, split-horizon and caches can explain differences.

DNSSEC

AD means the resolver reports authenticated data. SERVFAIL is not automatically labelled a DNSSEC failure; it can have other causes.

Inputs explained

Diagnostic
Diagnostic
Domain
DNS name, not a URL. Internationalized domains are converted to IDNA.
Record type
Record type
DKIM selector
For TXT queries only: query selector._domainkey.domain.
Resolver
Resolver
Request DNSSEC
Requests DNSSEC records. AD is a resolver assertion, not local chain validation.