democdn.cdn.dnstotal.net
checked 2026-09-18 10:49 UTC · 5.79 s of live queries
Health score
Re-check now Propagation All records Blocklists Check guide
Parent zone and delegation
4 checksWhat the registry for .cdn.dnstotal.net publishes about your domain.
-
OK
Parent name servers
The .cdn.dnstotal.net registry answered from a.gtld-servers.net (192.5.6.30). explain
a.gtld-servers.net 192.5.6.30 b.gtld-servers.net 192.33.14.30 c.gtld-servers.net 192.26.92.30 d.gtld-servers.net 192.31.80.30
-
OK
Delegation at the registry
The registry delegates the domain to 4 name server(s). explain
ns1.dnstotal.net ns2.dnstotal.net ns3.dnstotal.net ns4.dnstotal.net
-
OK
Number of name servers
4 name servers are delegated, which is a healthy number. explain
-
Info
Glue records
All name servers are outside this zone, so no glue record is needed. explain
Name servers
10 checksDirect queries sent to every authoritative server of the zone.
-
Info
Answering servers
4 authoritative servers were queried directly over UDP. explain
Name server Addresses Response Serial Authoritative Answers ns1.dnstotal.net 65.20.110.25 133.5 ms - ✓ ✓ ns2.dnstotal.net 45.63.42.50 110.7 ms - ✓ ✓ ns3.dnstotal.net 216.155.135.196 34.2 ms - ✓ ✓ ns4.dnstotal.net 216.238.95.132 84.8 ms - ✓ ✓ -
OK
All name servers respond
Every delegated name server answered a direct UDP query. explain
-
OK
Authoritative answers
Every server answers authoritatively for the zone. explain
-
OK
Recursion is disabled
No name server offers open recursion to the internet. explain
-
OK
DNS over TCP
Every name server also answers over TCP. explain
-
Warning
EDNS(0) support
These servers ignore EDNS(0), which limits answer size and blocks DNSSEC: ns1.dnstotal.net, ns2.dnstotal.net, ns4.dnstotal.net explain
-
OK
Network diversity
Name servers are spread over 4 different networks. explain
-
Warning
IPv6 reachable name servers
No name server has an AAAA record. IPv6-only clients and networks will depend on a translator to resolve your domain. explain
-
OK
Response time
Average response time 90.8 ms, slowest 133.5 ms. explain
-
Info
Reverse DNS of the name servers
Reverse names resolved for the servers. explain
ns1.dnstotal.net: 65.20.110.25.vultrusercontent.com ns2.dnstotal.net: 45.63.42.50.vultrusercontent.com ns3.dnstotal.net: 216.155.135.196.vultrusercontent.com ns4.dnstotal.net: 216-238-95-132.constant.com
SOA record
1 checksThe Start Of Authority record and its timers.
-
Error
SOA record exists
No SOA record could be retrieved for this zone. Every zone must have exactly one. explain
NoAnswer
Web and address records
7 checksThe records a browser needs to open your site.
-
OK
Address of the domain
democdn.cdn.dnstotal.net resolves to 2 address(es). explain
216.155.135.196 216.238.95.132
-
OK
No CNAME at the zone apex
The zone apex correctly has no CNAME record. explain
- OK
-
Warning
IPv6 (AAAA)
No AAAA record was found. IPv6-only mobile networks reach your site only through a carrier translator, which adds latency. explain
-
Info
HTTPS (SVCB) record
No HTTPS resource record. It is optional, but it removes the initial HTTP redirect and advertises HTTP/3 (ECH also relies on it). explain
-
Info
Wildcard record
A random, non-existent subdomain answers with 216.155.135.196, 216.238.95.132, so the zone has a wildcard. This hides typos and prevents NXDOMAIN answers. explain
-
OK
Web server answers
The web server replied with HTTP 200 over HTTPS. explain
Final URL: https://democdn.cdn.dnstotal.net/
Mail delivery
2 checksMX records and everything a receiving server checks before accepting your mail.
Mail authentication
6 checksSPF, DKIM, DMARC and the modern transport policies.
-
Error
SPF
No SPF record. Anybody can send mail using your domain as the envelope sender and most receivers will accept it. explain
-
Error
DMARC
No DMARC record at _dmarc.democdn.cdn.dnstotal.net. Without it, SPF and DKIM failures have no consequence and you receive no reports about abuse of your domain. explain
-
Warning
DKIM
No DKIM key was found on the selectors we probe. DKIM may still be active on a private selector, but without it DMARC survives no forwarding. explain
-
Info
MTA-STS
No MTA-STS policy. It stops attackers from stripping TLS between mail servers and is supported by the large providers. explain
-
Info
TLS-RPT
No TLS-RPT record. It is the reporting half of MTA-STS and DANE. explain
-
Info
BIMI
No BIMI record. It shows your brand logo next to authenticated mail and requires DMARC at p=quarantine or p=reject first. explain
Security
4 checksDNSSEC, certificate authorisation and exposure of the zone.
-
Warning
DNSSEC
DNSSEC is not enabled. Without it, answers for your domain can be forged on the way to the resolver. explain
-
Warning
CAA
No CAA record. Any certificate authority in the world may issue a certificate for your domain; a CAA record limits that to the ones you choose. explain
-
OK
Zone transfer (AXFR)
No name server allows an anonymous zone transfer. explain
-
OK
Software version disclosure
The name servers do not disclose their software version. explain
Records found
| Name | Type | TTL | Value |
|---|---|---|---|
| democdn.cdn.dnstotal.net | A | 300 | 216.155.135.196 216.238.95.132 |
| www.democdn.cdn.dnstotal.net | A | 300 | 216.155.135.196 216.238.95.132 |
Registry data (RDAP)
The registry did not return RDAP data for this domain.