DNS health of hieks.com.
One report on a domain's whole DNS setup, with each name server asked directly and every check explained.
Looking up…
How the servers are tested.
Most DNS tools only ask a public resolver, which hides a broken server behind a working one. Hivex also asks each of the domain's name servers directly, over TCP port 53 and without recursion: does it answer with authority (the AA flag), which SOA serial does it hold, and does it answer questions about other domains for strangers.
The usual problems.
- Lame delegation: a server still listed after a move to a new DNS host. Remove it at the registrar.
- Registry and zone disagree: the NS list at the registrar differs from the NS records in the zone. Update both to the same set.
- Serial drift: one server of a provider holds an older copy of the zone, so some visitors get old answers.
- MX to a CNAME or an address: mail servers must be named hosts with their own A or AAAA records.
Questions people ask.
What does a DNS health check test?
Whether the registry and the zone list the same name servers, whether each server answers with authority, agrees on the zone's serial and refuses to resolve for strangers, and whether SOA, mail, web and DNSSEC records are sound.
What is a lame delegation?
A name server listed for a domain that does not answer for it with authority. Resolvers that try it get nothing useful and retry elsewhere, which slows lookups or breaks them.
Why should name servers not be open resolvers?
A name server that answers recursive questions for anyone can be abused to amplify attacks on others. Authoritative servers should answer only for their own zones.
How many name servers does a domain need?
At least two, ideally on different networks, so the domain stays reachable when one server or network fails. Large anycast providers spread one address over many places.
Why can't Hivex ask Cloudflare's name servers directly?
Cloudflare Workers, where Hivex runs, cannot connect to Cloudflare's own addresses. For domains on Cloudflare DNS, the report uses Cloudflare's resolver instead.
Hivex index
Short names, still free to register.
Starting something new? Hivex keeps a live index of short, brandable .si names nobody has claimed yet, each checked with the registry.
From code, or an AI assistant.
Hivex's free JSON API and MCP server check domains, DNS and registration records from your own code or from AI assistants that speak MCP. No key needed.
More DNS tools
- DNS lookupAll records at once: A, AAAA, CNAME, MX, NS, TXT, CAA, SOA.
- MX lookupMail servers in priority order, the provider, SPF and DMARC at a glance.
- NS lookupName servers, the DNS host, SOA settings, and marketplace parking.
- TXT lookupSPF, DMARC, DKIM and verification tokens, joined and labelled.
- CNAME lookupThe full alias chain, the final addresses, and the platform behind it.
- CAA lookupAllowed certificate authorities, wildcard rules and report addresses.
- DNS propagation checker13 public resolvers side by side, with how long each keeps its copy.
- Reverse DNSThe PTR hostname of an IPv4 or IPv6 address, checked both ways.
- DNSSEC checkerDS, keys and validation: where the chain of trust holds or breaks.
- Subdomain finderSubdomains from certificate logs, DNS and the archive.
- DNS historyPast IP addresses and hosts, from passive DNS.
- DNS setup helperThe records each platform asks for, checked live.
- Domain checkerIs a name free to register? Checked live on any extension.
Sources
- RFC 1034: Domain names: concepts (delegation, authority)
- RFC 1912: Common DNS operational and configuration errors
- RFC 7766: DNS transport over TCP
- RFC 2181: Clarifications to the DNS specification (MX and CNAME)
- RFC 2308: Negative caching of DNS queries
By Hivex. Updated 10 October 2026. Lookups run live through Cloudflare's public resolver and are kept for at most five minutes.