sysadmintools

DNS Propagation Checker

Just changed a DNS record? Query your domain against 8 public resolvers at once to see whether the new answer has propagated. Full agreement = propagated.

Propagation is mostly caching

The tool resolves one record name and type against several public resolvers in parallel and lists each answer side by side. It is a cache comparison, not a broadcast. Nothing is pushed anywhere; each resolver either answers from its cache or goes and asks upstream, and the panel shows the difference between those two states.

Real propagation lag is rarer than the term implies. With short TTLs, anycast, and providers that serve changes quickly, a new value is often visible everywhere within the old TTL window. Most reported propagation failures are one resolver holding a stale entry, the operating system's stub cache on the machine doing the lookup, or a browser's DNS-over-HTTPS cache that ignores the system resolver entirely. Clear the local cache first, then repeat the check from a network you do not control.

Resolvers that refuse the query or time out appear as blanks. A blank is not disagreement, and counting blanks as stale answers inflates the problem. Where answers genuinely differ by region, the usual cause is views or GeoDNS, a deliberate setup serving per-region records for CDNs, mail, and failover. That is working as configured, not a broken zone. If every resolver agrees yet one client still sees the old address, the resolver is not the culprit.

Lowering the TTL is the real mitigation, and it has to happen before the change rather than after. Drop the record to 60 seconds, let the previous, longer TTL age out of caches, make the change, then restore the normal TTL. Setting a short TTL at the same moment you edit the value does nothing for any resolver already holding the old long-lived answer.

Related reading