HIERARCHICAL DNS DELEGATION & DAG TRACER

Live DNS Delegation Trace

Query the real DNS response for a domain and inspect its authoritative nameservers. Results come from the resolver used by the application host.

Status healthy
DNSSEC indeterminate
Hierarchy Depth 2 Layers
Cross-resolver comparison Not performed

Live DNS Response

Layer 0: RESOLVER

System Resolver Response

Resolver used by the StackHal application host
Application resolver
62.238.1.164
TTL: 3600s NOERROR
Layer 1: AUTHORITATIVE

Authoritative Nameservers

Nameservers returned by the live NS query for this domain
ns106.ovh.net
IP: 5.135.65.21
(No resource records returned)
TTL: 3600s NOERROR
dns106.ovh.net
IP: 5.196.41.1
(No resource records returned)
TTL: 3600s NOERROR

Delegation & DNSSEC Diagnostics

[INFO_LIVE_LOOKUP] Live DNS response: Answers and TTL values below were returned by the server resolver at request time. DNSSEC cryptographic validation and cross-resolver comparison are not performed by this lookup.

Frequently Asked Questions

How does hierarchical DNS delegation work?

DNS resolution traverses from the 13 IANA Root Clusters (.) to the TLD nameservers (e.g. .com or .pl), then to the domain's Authoritative nameservers, and finally to public recursive resolvers at the edge.

What does DNSSEC validation verify?

DNSSEC verifies the cryptographic chain of trust by matching the parent zone's Delegation Signer (DS) record against the child zone's DNSKEY and verifying RRSIG digital signatures.

What causes DNS propagation divergence during migrations?

High TTL values (>14,400s / 4 hours) cause caching recursive resolvers to retain stale records until their TTL expires, resulting in divergent answers across global regions.

What is a Lame Delegation?

A lame delegation occurs when a parent zone designates a nameserver that refuses queries or is not configured as authoritative for the zone.