DNS Monitoring for Every Nameserver

DmarcDkim's DNS Monitoring checks each of your authoritative nameservers and alerts you when one serves a stale, missing or broken record.

Baseline
Name Type Value TTL
@ MX
  • 1 smtp.google.com.
1 hour
@ TXT
  • v=spf1 include:_spf.google.com include:amazonses.com include:servers.mcsv.net include:sendgrid.net include:mailgun.org -all
1 hour
_dmarc TXT
  • v=DMARC1; p=quarantine; rua=mailto:dmarcdkim.com@rua.dmarcdkim.io
1 hour
_mta-sts TXT
  • v=STSv1; id=20260412091500Z;
1 hour
_smtp._tls TXT
  • v=TLSRPTv1; rua=mailto:dmarcdkim.com@tls.dmarcdkim.io
1 hour
google._domainkey TXT
  • v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAs3Nd8LqW1fJp…IDAQAB
1 hour
Nameservers out of sync
Name Type Value TTL
_dmarc TXT
ns1.example-dns.net ns2.example-dns.net
  • v=DMARC1; p=quarantine; rua=mailto:dmarcdkim.com@rua.dmarcdkim.io
  • v=DMARC1; p=reject; rua=mailto:dmarcdkim.com@rua.dmarcdkim.io
ns3.backup-dns.example
  • v=DMARC1; p=quarantine; rua=mailto:dmarcdkim.com@rua.dmarcdkim.io
Your authoritative nameservers returned different DNS records for the same name. Some resolvers will see stale or incorrect records, which can break email authentication and delivery. Check your DNS provider and make sure every nameserver serves the same up-to-date zone. September 22, 2026 at 14:42 UTC
1 hour
Modified
Name Type Value TTL
_dmarc TXT
Changed on ns3.backup-dns.example
  • v=DMARC1; p=quarantine; rua=mailto:dmarcdkim.com@rua.dmarcdkim.io
  • v=DMARC1; p=reject; rua=mailto:dmarcdkim.com@rua.dmarcdkim.io
1 hour
Modified
Name Type Value TTL
google._domainkey TXT
  • v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAs3Nd8LqW1fJp…IDAQAB
  • v=DKIM1; k=rsa; p=-----BEGIN PUBLIC KEY-----MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAx7Kc2VtQ9mLr…IDAQAB
1 hour
Modified
Name Type Value TTL
google._domainkey TXT
  • v=DKIM1; k=rsa; p=-----BEGIN PUBLIC KEY-----MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAx7Kc2VtQ9mLr…IDAQAB
  • v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAx7Kc2VtQ9mLr…IDAQAB
1 hour
Modified
Name Type Value TTL
@ TXT
  • v=spf1 include:_spf.google.com include:amazonses.com include:servers.mcsv.net include:sendgrid.net include:mailgun.org -all
  • v=spf1 include:_spf.google.com include:amazonses.com include:servers.mcsv.net include:sendgrid.net include:mailgun.org include:_spf.salesforce.com include:mail.zendesk.com -all
1 hour
Modified
Name Type Value TTL
@ TXT
  • v=spf1 include:_spf.google.com include:amazonses.com include:servers.mcsv.net include:sendgrid.net include:mailgun.org include:_spf.salesforce.com include:mail.zendesk.com -all
  • v=spf1 include:_spf.google.com include:amazonses.com include:servers.mcsv.net include:_spf.salesforce.com include:mail.zendesk.com -all
1 hour
Modified
Name Type Value TTL
_dmarc TXT
  • v=DMARC1; p=reject; rua=mailto:dmarcdkim.com@rua.dmarcdkim.io
  • v=DMARC1; p=none; rua=mailto:dmarc@reports.example.net
1 hour
Modified
Name Type Value TTL
_dmarc TXT
  • v=DMARC1; p=reject; rua=mailto:dmarcdkim.com@rua.dmarcdkim.io
  • v=DMARC1; p=none; rua=mailto:dmarc@reports.example.net
1 hour
Name Type Values Last Changed
Monitored @ TXT
  • v=spf1 include:_spf.google.com include:amazonses.com include:servers.mcsv.net include:_spf.salesforce.com include:mail.zendesk.com -all
7 days ago
Monitored @ MX
  • 1 smtp.google.com.
—
Monitored _dmarc TXT
  • v=DMARC1; p=reject; rua=mailto:dmarcdkim.com@rua.dmarcdkim.io
3 days ago
Monitored _mta-sts TXT
  • v=STSv1; id=20260412091500Z;
—
Monitored _smtp._tls TXT
  • v=TLSRPTv1; rua=mailto:dmarcdkim.com@tls.dmarcdkim.io
—
Monitored google._domainkey TXT
  • v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAx7Kc2VtQ9mLr…IDAQAB
10 days ago
Monitoring starts E-mail records are found automatically, and every nameserver gives the same answers.
Nameservers out of sync DMARC moves to p=reject, but ns3 missed the zone transfer and still answers p=quarantine.
Alert sent by Email Webhook
Back in sync The zone transfer is fixed, and all three nameservers answer p=reject.
DKIM record broken The rotated key was published with its PEM header, so DKIM signatures fail.
Alert sent by Email Webhook
DKIM fixed The key is published again without the header, and signatures verify.
SPF over the lookup limit Adding Salesforce and Zendesk takes SPF past 10 DNS lookups, so SPF fails.
Alert sent by Email Webhook
SPF fixed Unused SendGrid and Mailgun includes are removed, and SPF is back within the limit.
Two DMARC records A vendor's setup guide added a second record, so receivers ignore DMARC.
Alert sent by Email Webhook
DMARC fixed The extra record is deleted, and one DMARC record with p=reject remains.
All clear today Every record is valid, and every nameserver gives the same answers.

DNS monitoring for SOC teams, IT admins and MSPs

Every alert says what is wrong and how to fix it. This is what each team gets out of it.

Enterprise SOC teams

Confirm or rule out DNS in an outage investigation: every change on a timeline, per nameserver, with a diff for the incident ticket.

  • Per-nameserver diffs
  • Webhooks for your SIEM
  • REST API and MCP server

SMB and Mittelstand IT teams

DNS watched full time without hiring a DNS expert. Each alert explains the problem in plain words and names the fix.

  • Finds SPF, DKIM, DMARC and MX
  • Alerts that name the fix
  • No DNS provider login needed

MSPs and IT service providers

Clients edit their own DNS. You hear about every slip on every client domain, often before the client does.

  • All clients under one login
  • Webhooks for Slack and Teams
  • Shareable change history

One record, every nameserver, one table

For every monitored record you see how each authoritative nameserver answered the last check, with the TTL it served and the network it sits in.

TXT _dmarc.example.com Current value
Nameserver TTL IP address ASN Organization
ns1.example-dns.net 1 hour 🇩🇪 192.0.2.53 AS64496 Example DNS GmbH
ns2.example-dns.net 1 hour 🇩🇪 198.51.100.53 AS64496 Example DNS GmbH
ns3.old-provider.com 1 day 🇺🇸 203.0.113.7 AS64511 Old Provider Inc.
ns4.old-provider.com — 🇺🇸 203.0.113.8 AS64511 Old Provider Inc.
ns5.backup-dns.example — 🇳🇱 192.0.2.254 AS64500 Backup DNS B.V.
ns6.backup-dns.example — — — —
  • Agrees with the majority
  • Answers differently
  • Nameserver returned SERVFAIL
  • Timed out
  • Nameserver unreachable

Here ns3 still serves a different value and ns4 answers SERVFAIL. A resolver may hit either one, so some recipients get a different record than dig on your laptop shows.

When nameservers disagree, you see every answer

Each check is a diff. When the nameservers disagree, every answer is listed with the servers that gave it, and a server that failed is named.

October 05, 2026 at 21:45 UTC (about 2 hours ago) 2 values added, 2 values removed
Nameservers out of sync
Name Type Value TTL
_dmarc TXT
ns1.example-dns.net ns2.example-dns.net
  • v=DMARC1; p=none; rua=mailto:dmarc@example.com
  • v=DMARC1; p=reject; rua=mailto:dmarc@example.com; adkim=s; aspf=s
ns3.old-provider.com
  • v=DMARC1; p=none; rua=mailto:dmarc@example.com
ns4.old-provider.com
Nameserver is not authoritative for this name
1 hour – 1 day
Modified
Name Type Value TTL
@ TXT
  • v=spf1 include:_spf.example.net include:sendgrid.net ~all
  • v=spf1 include:_spf.example.net include:sendgrid.net include:servers.mcsv.net -all
1 hour

What each answer means, and what to do

These are the responses shown per nameserver, with the usual cause and fix.

Likely cause: the zone is not in sync. A secondary stopped receiving zone transfers, or a provider you left is still in your NS records.

What to do: fix the transfer or remove the stale server from the delegation. Until every server agrees, recipients get different answers.

Likely cause: the server knows the zone but cannot answer, for example after a failed zone load or with a broken DNSSEC signature.

What to do: check the provider's status and the zone on that server. Resolvers move on to the next server, so e-mail keeps flowing while only one fails.

Likely cause: the server is not configured for this zone, or blocks queries from outside its network.

What to do: add the zone to the server or remove it from your NS records.

Likely cause: a lame delegation. Your NS records name a server that does not host the zone, typically left over from a provider switch.

What to do: update the NS records at your registrar and in the zone so they list only servers that serve it.

Likely cause: the name exists on the other nameservers but not on this one, usually a half-deployed change such as a new DKIM selector added at one provider only.

What to do: add the record on the lagging server or wait for the zone transfer. Until then, recipients that hit this server do not find it.

Likely cause: a network issue, a firewall dropping UDP port 53, or an overloaded nameserver. Each lookup is retried once with a longer timeout before it is shown as timed out.

What to do: if the same server times out check after check, look at its reachability. A timeout never counts as a removed record.

Built for daily operations, not just audits

You decide what is monitored

SPF, DMARC, DKIM, MX, MTA-STS, TLS-RPT and BIMI records are found automatically. Your DMARC reports also show which subdomains send e-mail, and we add them for you. Every record stays under your control: add any A, AAAA, CNAME, MX, NS or TXT record by hand or import a zone file, pause what you do not need, or mute notifications for a record while keeping its history.

History you can show

Every change is a point on the timeline, with a line-by-line diff and a link you can share. Data retention is how far back your plan lets you open this history: 30 days on Mini, 90 days on Basic, a full year on Pro and Enterprise. Older changes are not deleted. They stay on the timeline, locked, and open as soon as you upgrade to a plan that covers them.

No false alarms

Timeouts and SERVFAIL never count as a change. A record is reported as removed only when the nameservers that answer say it is gone. If none of them answers, the check is marked inconclusive and the last known values stay.

Alerts where you work

Nameservers out of sync and DMARC, SPF and DKIM issues reach you by email. Every notification, including record changes, is in the dashboard. On Basic and higher it also goes to your webhooks, and on Pro and Enterprise you can read it through the REST API and the MCP server.

Frequently asked questions

It depends on your plan, from every few minutes to once a day, always on every authoritative nameserver. Large zones are checked over several runs. "Check DNS now" runs a check on demand and shows its progress. Each record's details page shows the exact number of checks, when the last one ran and when the next one is due.

A, AAAA, CNAME, MX, NS and TXT records. SPF and DMARC are always monitored. Records behind a CNAME or in a delegated subzone are followed to the nameservers that actually serve them.

Every paid plan, starting with Mini. Plans differ in data retention, which is how far back you can open the history: 30 days on Mini, 90 days on Basic, a full year on Pro and Enterprise. Older changes are kept, locked, and open when you upgrade. Webhooks come with Basic and higher, the REST API and the MCP server with Pro and Enterprise.

Proxied A and AAAA records point at Cloudflare's edge and change on their own. Discovery skips them, and records tagged as proxied in an imported zone file are added paused.

Yes. Discovery adds SPF, DMARC, DKIM selectors, MX, MTA-STS, TLS-RPT and BIMI records automatically, and you can add any other A, AAAA, CNAME, MX, NS or TXT record by hand or import a zone file. Each record has its own monitoring state: monitored, paused (not checked), or muted (checked and kept in the history, without warnings or notifications). SPF and DMARC stay monitored; every other record you can pause, mute or remove at any time.

Check your domain first

See where your SPF, DKIM and DMARC records stand today and what to fix first. DNS Monitoring then watches every nameserver, so you hear about the next broken change first.

DmarcDkim.com trusted by 2000+ companies

Fired Up Space heycater! Carbon One MGIS Seattle Convention Center Woosh Vertical Cable