Live DNS Delegation Trace
Query the real DNS response for a domain and inspect its authoritative nameservers. Results come from the resolver used by the application host.
Live DNS Response
System Resolver Response
Authoritative Nameservers
Delegation & DNSSEC Diagnostics
Frequently Asked Questions
How does hierarchical DNS delegation work?
DNS resolution traverses from the 13 IANA Root Clusters (.) to the TLD nameservers (e.g. .com or .pl), then to the domain's Authoritative nameservers, and finally to public recursive resolvers at the edge.
What does DNSSEC validation verify?
DNSSEC verifies the cryptographic chain of trust by matching the parent zone's Delegation Signer (DS) record against the child zone's DNSKEY and verifying RRSIG digital signatures.
What causes DNS propagation divergence during migrations?
High TTL values (>14,400s / 4 hours) cause caching recursive resolvers to retain stale records until their TTL expires, resulting in divergent answers across global regions.
What is a Lame Delegation?
A lame delegation occurs when a parent zone designates a nameserver that refuses queries or is not configured as authoritative for the zone.