DNS Propagation Checker
Check how a DNS record resolves from resolvers around the world and understand why changes appear at different times in different places.
Last reviewed by the Radiatus Cloud team
Need this monitored 24/7?
Radiatus delivers managed cloud & network operations.
Propagation is really caching
DNS changes do not travel outward from your authoritative server. The moment you save a record, the authoritative server serves the new value to anyone who asks. What creates the delay is that most of the world does not ask: recursive resolvers at ISPs, offices and public services hold a cached copy and keep serving it until it expires. "Propagation" is just the staggered expiry of thousands of independent caches.
TTL controls the wait
Each record carries a time to live in seconds telling resolvers how long to cache it. A record with a 86,400 second TTL can be served from cache for a full day after you change it. The practical technique is to lower the TTL to 300 seconds at least one full old-TTL period before a planned migration, make the change, confirm it, then raise the TTL again. Lowering it at the same time as changing the record does not help, because resolvers are still holding the old record with the old long TTL.
Why you see the old value and someone else sees the new one
Two people using different resolvers are querying different caches with different expiry times. Even one person can get inconsistent answers, because large public resolvers run many nodes and your queries may land on different ones. This is normal and resolves itself as caches expire.
Negative caching bites hardest
If a name is queried before the record exists, the NXDOMAIN response is itself cached, for a duration set by the SOA record's minimum field rather than by the record's own TTL. That value is frequently much longer than people expect. Creating a record then immediately testing it, getting a failure, and having that failure cached is a common and frustrating sequence. Set up records before you point anything at them.
Checking properly
Query the authoritative nameserver directly to confirm what you published: dig @ns1.example.com example.com A. Then query public resolvers to see what the world currently gets. If the authoritative answer is right and public resolvers disagree, you are simply waiting on cache expiry. If the authoritative answer is wrong, the change did not save or you edited the wrong zone.
Related tools
- Port Scanner — Check which common ports respond on a host and understand what each exposed service means. Scan only systems you are authorised to test.
- DNS Misconfiguration — Analyze DNS records (TXT, SPF) for security gaps.
- TLS Compat Tester — Check client-server compatibility for TLS versions.
- Firewall Rule Risk — Evaluate firewall rules for over-permissive exposure.
Frequently Asked Questions
How long does DNS propagation take?
As long as the previous TTL, in the worst case. If the old record had a 24-hour TTL, some resolvers will serve it for 24 hours after your change. Lower the TTL well before a planned migration to shorten this.
Why do different checkers show different results?
Each queries a different recursive resolver with its own independent cache and expiry time. Disagreement during a change is expected. What matters is that the authoritative nameserver returns the correct value.
Can I force propagation to complete?
Not globally. You can flush your own resolver and some public resolvers offer a cache-flush form for a specific name, but there is no way to clear every cache worldwide. Lowering TTL in advance is the only real control.
Why does my new record still return NXDOMAIN?
Negative caching. A lookup made before the record existed cached the not-found answer, for a period set by the SOA minimum field rather than the record's TTL. Avoid querying a name before you create it.
How do I check what I actually published?
Query the authoritative nameserver directly with dig @nameserver domain TYPE. That bypasses all caches. If it returns the right value, you are only waiting on cache expiry elsewhere.
Privacy & Security
Queries made from your browser.
About This Tool
This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
Port Scanner
NetworkCheck which common ports respond on a host and understand what each exposed service means. Scan only systems you are authorised to test.
DNS Misconfiguration
NetworkAnalyze DNS records (TXT, SPF) for security gaps.
TLS Compat Tester
NetworkCheck client-server compatibility for TLS versions.