Using DNSReach
Quick answers first, with deeper DNS detail when you need it.
Getting started
Enter a domain or hostname, choose a DNS record type and select Check DNS. You may paste a full URL. DNSReach removes the protocol and path automatically. PTR checks accept an IPv4 or IPv6 address.
For a normal check, leave Expected value blank. During a DNS change, open Advanced options and enter the new value you expect.
Understanding the results
Resolver agreement
The number of responding recursive resolvers which return the same normalised answer. Agreement tells you whether public resolver caches are consistent.
Geographic DNS view
DNSReach distinguishes three source types. A geographic probe runs the DNS query from a real location. A fixed-location resolver is a DNS server known to be in a specific country or city, even though the query originates from the DNSReach server. Anycast resolvers such as Google or Cloudflare are shown as global resolver networks rather than pinned to a false city.
Authoritative DNS
DNSReach finds the authoritative nameserver set for the zone, resolves the available IPv4 and IPv6 endpoints and queries each endpoint directly. Every nameserver found is listed. If one cannot be resolved or queried, it stays visible with its failure status instead of disappearing from the result.
TTL
TTL is the remaining cache lifetime reported by a resolver. A low TTL often means the resolver is close to asking the authoritative DNS again.
DNS record types
Resolvers and geographic nodes
A recursive resolver answers DNS questions on behalf of users and normally caches results. Google Public DNS, Cloudflare, Quad9 and OpenDNS are examples.
Pairing a Shell Node
Set the Shell Node up once on the remote server. In DNSReach, open Admin > Nodes and create a one-time pairing code. Run the exact pairing command shown there on the existing node, then start the dnsreach-node service. You do not repeat node setup when pairing or updating DNSReach.
Shell Nodes connect outbound to the DNSReach HTTPS URL. The node needs no Apache, Nginx, PHP or inbound firewall port. Once connected, Admin > Nodes shows its last check-in and the public map identifies its results as a geographic probe.
An authoritative DNS server answers for domains it hosts and normally does not provide open recursion. If a DNS server replies REFUSED to a recursive test, DNSReach now marks the server as reachable with recursion disabled or restricted instead of calling the server broken.
A resolver with a known fixed location also appears on the world map, but DNSReach labels it as a located resolver because the query still originates from the DNSReach server. Geographic probes use a different marker because the query itself originates from that location.
Anycast resolver networks have no single fixed physical location. DNSReach shows them in the map's global anycast rail so their results stay visible without inventing a country or city.
Propagation checks
Enter the new DNS value in Expected value. DNSReach then compares every resolver answer with that value and calculates progress. A different answer is not always an error. During a change it often means an older cache has not expired yet.
Common DNS statuses
- REFUSED
- The DNS server received the query but declined to answer it. Recursion may be disabled or limited to trusted clients.
- SERVFAIL
- The DNS server could not complete the query. Common causes include upstream failures, DNSSEC problems or unavailable authoritative servers.
- NXDOMAIN
- The DNS server reports that the requested hostname does not exist.
- Timeout
- No usable DNS reply arrived within the configured time limit.
- No record
- The hostname exists, but the requested record type was not returned.
Privacy and cookies
DNS queries are sent to the resolvers or nodes configured by the site operator. Optional analytics or other custom code follows the configured consent settings. See the Privacy Policy and Cookie Policy for this installation.
Mobile and PWA
DNSReach uses the same responsive interface in the browser and as an installed PWA. Live DNS results always require a network connection. The app shell and selected interface assets may be cached for faster loading.
Administration
The standalone edition uses a named administrator account, email address, password and TOTP two-factor authentication. Resolver Admin lets you add DNS servers, test their capabilities and manage which resolvers are used by the checker.

