DNS monitoring across 20+ record types
Detect unexpected changes and misconfigurations across your DNS records, with the old and new value side by side. Daily checks via the authoritative DNS server, with public resolvers as fallback.
20+ DNS record types in one daily check
The same daily check covers name resolution, email authentication, certificate authority restrictions, DNS security, and reverse DNS.
Authoritative-first, with resolver fallback for resilience
WebPixie queries the authoritative DNS server for each check. If it does not respond, the check automatically falls back to a public resolver, so an unreachable authoritative source does not block detection.
The authoritative server answers first; public resolvers only step in when it is unreachable.
DNS analysis flags issues by severity
Each daily check scores your DNS configuration and flags problems, from a missing AAAA record to a soft-fail SPF policy and a single point of nameserver failure.
No AAAA record, IPv6 clients cannot resolve
SPF policy ends in ~all (SoftFail)
Single nameserver provider, no redundancy
Nameserver TTL longer than recommended
DNSSEC status is secure
How WebPixie watches your DNS
WebPixie queries your DNS records daily from the authoritative DNS server, with public resolvers such as Google, Cloudflare, and Quad9 used as fallback if it does not respond, and surfaces any record change, with the previous and new value side by side. The check covers 20+ record types including A, AAAA, MX, CNAME, TXT, CAA, NS, and SOA, plus DNSSEC validation, email authentication and transport-security records (SPF, DMARC, BIMI, TLS-RPT, MTA-STS) for deliverability, and reverse DNS (PTR) for IPv4 and IPv6.
When a record changes, WebPixie shows the previous value, the new value, the record type, and the timestamp. That makes it easy to tell an authorized update from your team apart from an unexpected modification that needs investigation.
There is nothing to install. WebPixie does not need access to your DNS panel; it queries public DNS like any other client and surfaces the changes you need to know about.
Surface DNS misconfigurations
Daily checks for missing and invalid records, with a change diff
A missing or misconfigured DNS record can take a site offline or break email delivery. WebPixie checks every monitored DNS record daily from the authoritative DNS server and surfaces configuration problems for review. When a record changes, WebPixie shows the old value, the new value, the record type, and the detection timestamp.
Monitor 20+ record types in one place
From A and AAAA to CAA, DNSSEC, SPF, DMARC, BIMI
DNS is more than A records. WebPixie monitors name resolution (A, AAAA, CNAME, NS, SOA), email authentication and transport security (MX, SPF, DMARC, BIMI, plus TLS-RPT and MTA-STS), certificate authority restrictions (CAA, which limits which certificate authorities may issue for your domain), service and security records (SRV, TLSA, SSHFP, HTTPS, SVCB), and DNS security (DNSSEC chains). It also runs reverse DNS (PTR) lookups for IPv4 and IPv6. The same daily check covers your A record, your CAA, and your DNSSEC chain together.
Validate DNSSEC chains daily
Spot a broken DNSSEC chain on the daily check
When DNSSEC breaks, validating resolvers refuse to return the record at all, making the domain unreachable for users on those resolvers. WebPixie validates the full DNSSEC chain daily (DNSKEY, DS, RRSIG, NSEC). If a signature has expired or a key rotation has left the chain broken, the daily check flags it as bogus so you can fix it quickly instead of waiting for user reports.
Stay covered even if a resolver has trouble
Authoritative-first checks, with public resolver fallback
WebPixie queries the authoritative DNS server for each check. If it does not respond, the check automatically falls back to a public resolver such as Google, Cloudflare, or Quad9, so a single resolver outage does not stop detection. This is a resilience measure, not a cross-resolver comparison: WebPixie does not treat resolver disagreement as a signal on its own.
Set up DNS monitoring in 60 seconds
Free plan, no credit card. Daily DNS checks on every plan.
Everything you need to monitor a website. In one workspace.
A quick look at other WebPixie features.
Why teams choose WebPixie for DNS
Set up in 60 seconds
No agent to install and no access to your DNS panel needed. Enter a domain and daily DNS checks start running.
Your whole site in one workspace
DNS monitoring sits next to uptime, SSL, domain, and link health in one dashboard. Scored technical checks across the data WebPixie collects, such as security headers, SSL security and configuration validation, and DNS configuration validation, roll into your WebPixie Site Score.
See exactly what changed
Every monitored record is checked daily and scored, so a changed value or a new DNS problem shows up with the previous and new value side by side.
Frequently Asked Questions
Common questions about DNS monitoring.
DNS monitoring is the practice of checking your domain's DNS records on a schedule and surfacing unexpected changes for review. Those records include A, AAAA, MX, CNAME, TXT, CAA, NS, and SOA, along with DNSSEC validation and email authentication like SPF, DMARC, and BIMI. WebPixie runs these checks daily via the authoritative DNS server, with public resolvers as fallback, across 20+ record types, so an edited record or a broken DNSSEC chain shows up with the old and new value, instead of a silent change you discover later. DNS changes are visible in logs but do not create incidents. It works alongside domain monitoring and uptime monitoring in one workspace, and you can start on the free plan with the limits on the pricing page.
WebPixie monitors more than 20 DNS record types, grouped by what they control. Name resolution covers A, AAAA, CNAME, NS, and SOA; email authentication covers MX, SPF, DMARC, and BIMI; certificate authority restrictions use CAA; and DNS security covers the DNSSEC records DNSKEY, DS, CDNSKEY, and CDS. General purpose records like TXT and SRV are included too, along with reverse DNS (PTR) lookups for IPv4 and IPv6. Each type is checked daily, and a changed value is flagged with its old and new value. This is the same data that feeds DNS monitoring findings and your WebPixie Site Score, and it works next to SSL monitoring and domain monitoring in one workspace.
WebPixie queries every monitored DNS record daily from the authoritative DNS server, then compares each response to the previous one. When a response changes, WebPixie flags it with the previous value, the new value, the record type, and the detection timestamp. If the authoritative server does not respond, the check falls back to a public resolver such as Google, Cloudflare, or Quad9, so a temporary outage on one source does not block detection. That context helps you tell an authorized update from your team apart from an unexpected modification worth investigating. DNS changes are visible in your logs but do not create incidents; they sit next to uptime monitoring in the same workspace. For a one-off manual check right now, use the free DNS Lookup tool.
Yes. WebPixie validates the full DNSSEC chain on every daily check, covering the DNSKEY records, the DS records in the parent zone, the RRSIG signatures, and the NSEC negative-response records. The result is reported as secure, insecure, bogus, or indeterminate, so you can tell a correctly signed zone from an unsigned one or a broken one. This matters because when DNSSEC breaks, validating resolvers refuse to return the record at all, and the domain goes dark for users on those resolvers. The daily check flags a bogus chain so you can fix it quickly instead of waiting for user reports. DNSSEC checks run on every plan, including the free one on the pricing page, and are part of DNS monitoring.
No. WebPixie monitors DNS records; it does not host them. Your records stay wherever you run them today, whether that is Cloudflare, AWS Route 53, NS1, your registrar, or another provider, and you keep managing them there. WebPixie adds an independent daily check via the authoritative DNS server, with public resolvers as fallback, so when a record changes or a DNSSEC chain breaks, you see it with the old and new value without moving anything. Keeping hosting and monitoring separate is deliberate, because an outside observer can flag a misconfiguration that the system serving the records would not catch on its own. To see what is tracked, visit DNS monitoring; it pairs with domain monitoring for the registration layer, and you can start on the free plan on the pricing page.
Ready to watch your DNS?
Free plan, no credit card. Daily checks across 20+ record types.