What DNSLint checks

28 checks across five areas of your DNS, and why each one matters.

Parent zone

Glue records
When a domain's nameservers live inside the domain itself, the parent zone must publish their addresses as glue. Without glue, resolvers cannot find the nameservers and the domain does not resolve.
Nameserver address records
Every nameserver listed at the registry needs an A or AAAA record so resolvers can reach it.
DNSSEC
Looks for DS records at the parent zone. DNSSEC signs your records to protect against spoofing and cache poisoning.

Nameservers

Matching nameservers
The nameservers listed at the parent zone must match the NS records inside your zone. A mismatch causes inconsistent answers depending on which resolver asks.
Servers respond
Each nameserver must answer queries. A dead server slows lookups and loses redundancy.
Lame delegation
A nameserver that is listed for your domain but does not answer authoritatively is lame. It is a common cause of intermittent resolution failures (RFC 1912).
Redundancy
Two or more nameservers are required so one failure does not take the domain offline. More than seven can overflow the 512-byte UDP response limit.
Public addresses
Nameserver addresses must be publicly routable. Private or reserved addresses are unreachable from the internet.
IPv6 for nameservers
Checks whether nameservers are reachable over IPv6, which keeps the domain resolvable from IPv6-only networks.
TCP connectivity
DNS must work over TCP as well as UDP. Large responses, DNSSEC and zone transfers all depend on it.

SOA record

Matching serials
All nameservers should report the same SOA serial. A mismatch signals zone transfers that are failing or lagging (RFC 1912).
Primary nameserver (MNAME)
MNAME should name one of your real nameservers, not the domain itself.
Contact address (RNAME)
The SOA contact is an email address with the @ written as a dot. The check confirms it is formatted correctly.
Serial format
Serial numbers should increase with every change. The conventional YYYYMMDDnn format makes that easy to follow.
Refresh, retry, expire and minimum
These timers control how often secondary servers sync and how long cached data lives. Each is compared against the ranges recommended by RFC 1912.

Mail (MX)

Multiple mail servers
Two or more MX records let mail queue and deliver when one server is down.
Hostnames, not IP addresses
MX records must point to hostnames. An IP address in an MX record is invalid and breaks delivery.
No CNAMEs
An MX target must not be a CNAME alias (RFC 974, RFC 1912). Some mail servers refuse to deliver to it.
Targets resolve
Each MX hostname must resolve to a public IP address, or mail cannot be delivered.
Reverse DNS
Mail server addresses should have a PTR record that matches their hostname. Receivers use it to judge whether mail is legitimate.

Domain

No CNAME at the apex
A CNAME at the root of a domain conflicts with the required SOA and NS records and can break mail and other services.
IPv6 for the domain
An AAAA record lets IPv6-only visitors reach your site.
Check a domain