Network Diagnostics and More
Tool guide limitationsGuides explain the intended workflow but cannot cover every device, provider or operating condition.

Interfaces and external services can change. Follow the current on-screen controls, check dates and vendor documentation, and verify important results independently before acting on them.

Important: Do not rely on this result alone for purchasing, configuration, security, safety, compliance, contractual or fault-diagnosis decisions. Results can be incomplete, delayed, misleading or wrong. Verify important findings with the relevant provider, manufacturer documentation and an appropriate independent test or qualified professional.

← All tool guides

DNS and email

Authoritative DNS Trace guide

Visualise public delegation and DNSSEC evidence from the root and TLD levels through the requested name.

Open Authoritative DNS Trace

What you need

  • Public domain or hostname

How to use it

  1. 1Enter the fully qualified name.
  2. 2Run the delegation trace.
  3. 3Review nameservers at each zone step.
  4. 4Inspect DS, DNSKEY and resolver-authentication evidence.

Understanding the results

  • A parent DS and child DNSKEY support a signed delegation; resolver authentication shows whether the observed response validated.
  • Missing NS data at an intermediate step needs confirmation at the registrar or DNS host.

Recommended next actions

  • Compare with another validating resolver and confirm registrar and authoritative-provider settings.

Common problems

  • Caches and recent delegation changes can produce temporary differences.
  • Complex public suffixes can require provider confirmation.

Privacy and security

  • Only public lookup data is requested. Avoid entering internal names, credentials or confidential notes.

Worked example

Scenario
Checking a DNSSEC change
Example input
www.example.com
How to read it
The trace shows DS evidence at the parent and DNSKEY evidence at the zone, helping identify which side of the delegation needs review.

Limitations

  • The trace uses a public recursive resolver rather than direct packets from the visitor to every authority.

Do not rely on one result for a production, security, safety, purchasing or contractual decision. Verify important findings independently.