Skip to main content

DNS Records Endpoints

15 endpoints available

Foundational DNS tooling that goes well beyond `dig`-equivalent lookups. Query 22 record types including modern HTTPS / SVCB records (RFC 9460) for HTTP/3 and Encrypted Client Hello readiness. Verify DNSSEC cryptographically — DS digest reconstruction (RFC 4034 §5.1.4) and RRSIG signature verification across RSA-SHA256/512, ECDSA P-256/P-384, and Ed25519 — rather than trusting an upstream resolver's AD bit. Cross-reference CAA policy against Certificate Transparency logs (RFC 6962). Distinguish botnet fast-flux from CDN rotation via ASN diversity, residential-PTR signature, and double-flux NS-rotation detection (MITRE T1568.001). Audit zone health in a single call via the zone-hygiene composite — DNSSEC, CAA, AXFR, NSEC3, open-resolver, SOA, and subdomain-exposure checks aggregated into a weighted score. Domain registration via RDAP (RFC 7480) with port-43 WHOIS fallback (RFC 3912) for ccTLDs. Essential for security engineers, deliverability teams, fraud / threat-intel analysts, and anyone responsible for a production zone.

Try These Endpoints

Test DNS Records endpoints live in the playground. No signup required.