Skip to content

DNS checks

Create a DNS check for the record name you want to observe, such as example.com or _dmarc.example.com. Use an ASCII DNS name without a scheme or path. Names are lowercased and a final dot is removed.

Option Meaning and constraints
Record type A, AAAA, CNAME, MX, TXT, NS or CAA
Match mode Resolves, exact or includes
Expected records One per line in the UI; required for exact/includes; at most 100 records of at most 4096 bytes each
Interval Plan-constrained positive seconds
Resolvers required for healthy Blank means all three; otherwise 1-3
Resolvers required to avoid failing 1-3; default two; must not exceed the healthy requirement
Notification groups Existing account groups

The three resolvers are Cloudflare (1.1.1.1), Google (8.8.8.8) and Quad9 (9.9.9.9). They are created automatically; this is not a configurable list of private DNS servers.

Resolves requires a nonempty answer, without comparing expected values. Exact requires the complete normalized answer set to equal the expected set. Includes allows additional records but requires every expected record.

For newly created records without an explicit mode, A/AAAA/TXT use includes; other record types use exact. Review the selection shown by the form rather than assuming one mode applies to every type.

Use the form’s current-answer preview to populate expectations, then review them before saving. A preview captures existing answers, not the desired future state. Addresses are normalized; DNS-name values are case-insensitive and trailing dots are removed. MX values include priority; TXT values preserve their content. Do not use includes to match a substring inside a TXT record.

Type Example expected record Normalization / constraint
A 203.0.113.10 IPv4 address, no CIDR suffix
AAAA 2001:db8::10 IPv6 address, no CIDR suffix
CNAME / NS target.example.com ASCII name; lowercased, final dot removed
MX 10 mail.example.com Priority 0-65535 plus hostname; null MX 0 . is supported
TXT v=spf1 -all Nonempty literal text; content is preserved
CAA 0 issue "ca.example" Flags 0-255, alphanumeric tag and value; tag lowercased

Duplicate normalized values are removed and ordering is normalized. The addresses above are documentation examples, not live resolver answers.

When you edit only expected records, prior expected answers can temporarily count as lagging while caches expire. The lag window uses observed TTLs, bounded between five minutes and 48 hours. Lagging resolvers count as healthy. Changing hostname, type or match mode resets the target instead of reusing old-answer tolerance.

Inspect answers, TTL and errors by resolver. A failed answer may be a lookup error, a genuine mismatch or an infrastructure-suspect result; these are not interchangeable. See DNS troubleshooting.