DNS Monitoring for Every Nameserver
DmarcDkim's DNS Monitoring checks each of your authoritative nameservers and alerts you when one serves a stale, missing or broken record.
| Baseline | |||
|---|---|---|---|
| Name | Type | Value | TTL |
| @ | MX |
|
1 hour |
| @ | TXT |
|
1 hour |
| _dmarc | TXT |
|
1 hour |
| _mta-sts | TXT |
|
1 hour |
| _smtp._tls | TXT |
|
1 hour |
| google._domainkey | TXT |
|
1 hour |
| Nameservers out of sync | |||
|---|---|---|---|
| Name | Type | Value | TTL |
| _dmarc | TXT |
ns1.example-dns.net
ns2.example-dns.net
ns3.backup-dns.example
|
1 hour |
| Modified | |||
|---|---|---|---|
| Name | Type | Value | TTL |
| _dmarc | TXT |
Changed on
ns3.backup-dns.example
|
1 hour |
| Modified | |||
|---|---|---|---|
| Name | Type | Value | TTL |
| google._domainkey | TXT |
|
1 hour |
| Modified | |||
|---|---|---|---|
| Name | Type | Value | TTL |
| google._domainkey | TXT |
|
1 hour |
| Modified | |||
|---|---|---|---|
| Name | Type | Value | TTL |
| @ | TXT |
|
1 hour |
| Modified | |||
|---|---|---|---|
| Name | Type | Value | TTL |
| @ | TXT |
|
1 hour |
| Modified | |||
|---|---|---|---|
| Name | Type | Value | TTL |
| _dmarc | TXT |
|
1 hour |
| Modified | |||
|---|---|---|---|
| Name | Type | Value | TTL |
| _dmarc | TXT |
|
1 hour |
| Name | Type | Values | Last Changed | ||
|---|---|---|---|---|---|
| Monitored | @ | TXT |
|
7 days ago | |
| Monitored | @ | MX |
|
— | |
| Monitored | _dmarc | TXT |
|
3 days ago | |
| Monitored | _mta-sts | TXT |
|
— | |
| Monitored | _smtp._tls | TXT |
|
— | |
| Monitored | google._domainkey | TXT |
|
10 days ago |
DNS monitoring for SOC teams, IT admins and MSPs
Every alert says what is wrong and how to fix it. This is what each team gets out of it.
Enterprise SOC teams
Confirm or rule out DNS in an outage investigation: every change on a timeline, per nameserver, with a diff for the incident ticket.
SMB and Mittelstand IT teams
DNS watched full time without hiring a DNS expert. Each alert explains the problem in plain words and names the fix.
MSPs and IT service providers
Clients edit their own DNS. You hear about every slip on every client domain, often before the client does.
One record, every nameserver, one table
For every monitored record you see how each authoritative nameserver answered the last check, with the TTL it served and the network it sits in.
_dmarc.example.com
Current value
| Nameserver | TTL | IP address | ASN | Organization |
|---|---|---|---|---|
| ns1.example-dns.net | 1 hour | 🇩🇪 192.0.2.53 | AS64496 | Example DNS GmbH |
| ns2.example-dns.net | 1 hour | 🇩🇪 198.51.100.53 | AS64496 | Example DNS GmbH |
| ns3.old-provider.com | 1 day | 🇺🇸 203.0.113.7 | AS64511 | Old Provider Inc. |
| ns4.old-provider.com | — | 🇺🇸 203.0.113.8 | AS64511 | Old Provider Inc. |
| ns5.backup-dns.example | — | 🇳🇱 192.0.2.254 | AS64500 | Backup DNS B.V. |
| ns6.backup-dns.example | — | — | — | — |
- Agrees with the majority
- Answers differently
- Nameserver returned SERVFAIL
- Timed out
- Nameserver unreachable
Here ns3 still serves a different value and ns4 answers SERVFAIL. A resolver may hit either one, so some recipients get a different record than dig on your laptop shows.
When nameservers disagree, you see every answer
Each check is a diff. When the nameservers disagree, every answer is listed with the servers that gave it, and a server that failed is named.
October 05, 2026 at 21:45 UTC (about 2 hours ago) 2 values added, 2 values removed
| Nameservers out of sync | |||
|---|---|---|---|
| Name | Type | Value | TTL |
| _dmarc | TXT |
ns1.example-dns.net
ns2.example-dns.net
ns3.old-provider.com
ns4.old-provider.com
Nameserver is not authoritative for this name
|
1 hour – 1 day |
| Modified | |||
| Name | Type | Value | TTL |
| @ | TXT |
|
1 hour |
What each answer means, and what to do
These are the responses shown per nameserver, with the usual cause and fix.
Likely cause: the zone is not in sync. A secondary stopped receiving zone transfers, or a provider you left is still in your NS records.
What to do: fix the transfer or remove the stale server from the delegation. Until every server agrees, recipients get different answers.
Likely cause: the server knows the zone but cannot answer, for example after a failed zone load or with a broken DNSSEC signature.
What to do: check the provider's status and the zone on that server. Resolvers move on to the next server, so e-mail keeps flowing while only one fails.
Likely cause: the server is not configured for this zone, or blocks queries from outside its network.
What to do: add the zone to the server or remove it from your NS records.
Likely cause: a lame delegation. Your NS records name a server that does not host the zone, typically left over from a provider switch.
What to do: update the NS records at your registrar and in the zone so they list only servers that serve it.
Likely cause: the name exists on the other nameservers but not on this one, usually a half-deployed change such as a new DKIM selector added at one provider only.
What to do: add the record on the lagging server or wait for the zone transfer. Until then, recipients that hit this server do not find it.
Likely cause: a network issue, a firewall dropping UDP port 53, or an overloaded nameserver. Each lookup is retried once with a longer timeout before it is shown as timed out.
What to do: if the same server times out check after check, look at its reachability. A timeout never counts as a removed record.
Built for daily operations, not just audits
You decide what is monitored
SPF, DMARC, DKIM, MX, MTA-STS, TLS-RPT and BIMI records are found automatically. Your DMARC reports also show which subdomains send e-mail, and we add them for you. Every record stays under your control: add any A, AAAA, CNAME, MX, NS or TXT record by hand or import a zone file, pause what you do not need, or mute notifications for a record while keeping its history.
History you can show
Every change is a point on the timeline, with a line-by-line diff and a link you can share. Data retention is how far back your plan lets you open this history: 30 days on Mini, 90 days on Basic, a full year on Pro and Enterprise. Older changes are not deleted. They stay on the timeline, locked, and open as soon as you upgrade to a plan that covers them.
No false alarms
Timeouts and SERVFAIL never count as a change. A record is reported as removed only when the nameservers that answer say it is gone. If none of them answers, the check is marked inconclusive and the last known values stay.
Alerts where you work
Nameservers out of sync and DMARC, SPF and DKIM issues reach you by email. Every notification, including record changes, is in the dashboard. On Basic and higher it also goes to your webhooks, and on Pro and Enterprise you can read it through the REST API and the MCP server.
Frequently asked questions
It depends on your plan, from every few minutes to once a day, always on every authoritative nameserver. Large zones are checked over several runs. "Check DNS now" runs a check on demand and shows its progress. Each record's details page shows the exact number of checks, when the last one ran and when the next one is due.
A, AAAA, CNAME, MX, NS and TXT records. SPF and DMARC are always monitored. Records behind a CNAME or in a delegated subzone are followed to the nameservers that actually serve them.
Every paid plan, starting with Mini. Plans differ in data retention, which is how far back you can open the history: 30 days on Mini, 90 days on Basic, a full year on Pro and Enterprise. Older changes are kept, locked, and open when you upgrade. Webhooks come with Basic and higher, the REST API and the MCP server with Pro and Enterprise.
Proxied A and AAAA records point at Cloudflare's edge and change on their own. Discovery skips them, and records tagged as proxied in an imported zone file are added paused.
Yes. Discovery adds SPF, DMARC, DKIM selectors, MX, MTA-STS, TLS-RPT and BIMI records automatically, and you can add any other A, AAAA, CNAME, MX, NS or TXT record by hand or import a zone file. Each record has its own monitoring state: monitored, paused (not checked), or muted (checked and kept in the history, without warnings or notifications). SPF and DMARC stay monitored; every other record you can pause, mute or remove at any time.
Check your domain first
See where your SPF, DKIM and DMARC records stand today and what to fix first. DNS Monitoring then watches every nameserver, so you hear about the next broken change first.
DmarcDkim.com trusted by 2000+ companies