What DNSLint checks
28 checks across five areas of your DNS, and why each one matters.
Parent zone
- Glue records
- When a domain's nameservers live inside the domain itself, the parent zone must publish their addresses as glue. Without glue, resolvers cannot find the nameservers and the domain does not resolve.
- Nameserver address records
- Every nameserver listed at the registry needs an A or AAAA record so resolvers can reach it.
- DNSSEC
- Looks for DS records at the parent zone. DNSSEC signs your records to protect against spoofing and cache poisoning.
Nameservers
- Matching nameservers
- The nameservers listed at the parent zone must match the NS records inside your zone. A mismatch causes inconsistent answers depending on which resolver asks.
- Servers respond
- Each nameserver must answer queries. A dead server slows lookups and loses redundancy.
- Lame delegation
- A nameserver that is listed for your domain but does not answer authoritatively is lame. It is a common cause of intermittent resolution failures (RFC 1912).
- Redundancy
- Two or more nameservers are required so one failure does not take the domain offline. More than seven can overflow the 512-byte UDP response limit.
- Public addresses
- Nameserver addresses must be publicly routable. Private or reserved addresses are unreachable from the internet.
- IPv6 for nameservers
- Checks whether nameservers are reachable over IPv6, which keeps the domain resolvable from IPv6-only networks.
- TCP connectivity
- DNS must work over TCP as well as UDP. Large responses, DNSSEC and zone transfers all depend on it.
SOA record
- Matching serials
- All nameservers should report the same SOA serial. A mismatch signals zone transfers that are failing or lagging (RFC 1912).
- Primary nameserver (MNAME)
- MNAME should name one of your real nameservers, not the domain itself.
- Contact address (RNAME)
- The SOA contact is an email address with the @ written as a dot. The check confirms it is formatted correctly.
- Serial format
- Serial numbers should increase with every change. The conventional YYYYMMDDnn format makes that easy to follow.
- Refresh, retry, expire and minimum
- These timers control how often secondary servers sync and how long cached data lives. Each is compared against the ranges recommended by RFC 1912.
Mail (MX)
- Multiple mail servers
- Two or more MX records let mail queue and deliver when one server is down.
- Hostnames, not IP addresses
- MX records must point to hostnames. An IP address in an MX record is invalid and breaks delivery.
- No CNAMEs
- An MX target must not be a CNAME alias (RFC 974, RFC 1912). Some mail servers refuse to deliver to it.
- Targets resolve
- Each MX hostname must resolve to a public IP address, or mail cannot be delivered.
- Reverse DNS
- Mail server addresses should have a PTR record that matches their hostname. Receivers use it to judge whether mail is legitimate.
Domain
- No CNAME at the apex
- A CNAME at the root of a domain conflicts with the required SOA and NS records and can break mail and other services.
- IPv6 for the domain
- An AAAA record lets IPv6-only visitors reach your site.