WebPixie
Skip to main content
Back to Features
DNS monitoring

DNS monitoring across 20+ record types, with DNSSEC validation

Catch unexpected DNS changes and DNSSEC failures, with the old and new value side by side. Daily checks from multiple resolvers.

20+ record types
DNSSEC included
Free plan, no credit card
4 sites monitored · daily DNS across 3 resolvers
SiteDNSSECResolversScore
shop.acme.ioBogus3/358
blog.acme.devSecure2/380
acme-store.comSecure3/396
mail.acme.comInsecure3/391
2 sites need attention · DNSSEC bogus on shop.acme.io
DNS monitoring is included in the free plan.Compare all plans

20+ record types, not just A and CNAME

The same daily check covers name resolution, email authentication, certificate authority restrictions, DNS security, and reverse DNS.

Name resolution
AAAAACNAMENSSOA
Email & text
MXTXTSPFDMARCBIMITLS-RPTMTA-STSSMIMEA
Security
DNSSECDSDNSKEYCDNSKEYCDSCAATLSASSHFP
Service
SRVHTTPSSVCBNAPTRHIP
Reverse DNS
PTR (IPv4)PTR (IPv6)

Checked from the authoritative server, Google, and Cloudflare

WebPixie queries each record from several resolvers, so you can tell a real change apart from a propagation delay and know when an update is fully live.

QueryA · acme.io
Authoritative (ns1.acme.io)203.0.113.10
Google (8.8.8.8)203.0.113.10
Cloudflare (1.1.1.1)203.0.113.10

All three sources agree, so the record has fully propagated.

DNS analysis flags issues by severity

Each daily check scores your DNS configuration and flags problems, from a missing AAAA record to a soft-fail SPF policy and a single point of nameserver failure.

Medium

No AAAA record, IPv6 clients cannot resolve

-10
Medium

SPF policy ends in ~all (SoftFail)

-8
Low

Single nameserver provider, no redundancy

-4
Low

Nameserver TTL longer than recommended

-3
Pass

DNSSEC chain valid

0 Critical0 High2 Medium2 Low1 Info
73DNS ScoreRolls into your composite Site Score.

How WebPixie watches your DNS

WebPixie queries your DNS records daily from the authoritative DNS server plus the Google and Cloudflare resolvers and surfaces any record change, with the previous and new value side by side. The check covers 20+ record types including A, AAAA, MX, CNAME, TXT, CAA, NS, and SOA, plus DNSSEC validation, email authentication and transport-security records (SPF, DMARC, BIMI, TLS-RPT, MTA-STS) for deliverability, and reverse DNS (PTR) for IPv4 and IPv6.

When a record changes, WebPixie shows the previous value, the new value, the record type, and the timestamp. That makes it easy to tell an authorized update from your team apart from an unexpected modification that needs investigation.

There is nothing to install. WebPixie does not need access to your DNS panel; it queries public DNS like any other client and surfaces the changes you need to know about.

01

Catch unexpected record changes

Daily checks across multiple resolvers, with a change diff

A small change to a DNS record can take a site offline or break email delivery. WebPixie queries every monitored DNS record daily from multiple resolvers. When the response changes, WebPixie shows the old value, the new value, the record type, and the detection timestamp. An unexpected change to an NS or A record can be the first sign of a hijack, and the same daily check surfaces it with the old and new values.

02

Monitor 20+ record types in one place

From A and AAAA to CAA, DNSSEC, SPF, DMARC, BIMI

DNS is more than A records. WebPixie monitors name resolution (A, AAAA, CNAME, NS, SOA), email authentication and transport security (MX, SPF, DMARC, BIMI, plus TLS-RPT and MTA-STS), certificate authority restrictions (CAA, which limits which certificate authorities may issue for your domain), service and security records (SRV, TLSA, SSHFP, HTTPS, SVCB), and DNS security (DNSSEC chains). It also runs reverse DNS (PTR) lookups for IPv4 and IPv6. The same daily check covers your A record, your CAA, and your DNSSEC chain together.

03

Validate DNSSEC chains daily

Spot a broken DNSSEC chain on the daily check

When DNSSEC breaks, validating resolvers refuse to return the record at all, making the domain unreachable for users on those resolvers. WebPixie validates the full DNSSEC chain daily (DNSKEY, DS, RRSIG, NSEC). If a signature has expired or a key rotation has left the chain broken, the daily check flags it as bogus so you can fix it quickly instead of waiting for user reports.

04

Query from multiple resolvers, not just one

Catches resolver-specific inconsistencies

Different DNS resolvers can return different results for the same record because of caching and propagation delays. WebPixie queries every monitored record from the authoritative DNS server plus the Google and Cloudflare resolvers on every check. Inconsistencies surface in the dashboard, so you know when propagation is actually complete instead of guessing.

Set up DNS monitoring in 60 seconds

Free plan, no credit card. Daily DNS checks on every plan.

Everything you need to monitor a website. In one workspace.

A quick look at other WebPixie features.

Why teams choose WebPixie for DNS

Set up in 60 seconds

No agent to install and no access to your DNS panel needed. Enter a domain and daily checks from multiple resolvers start running.

Your whole site in one workspace

DNS monitoring sits next to uptime, SSL, domain, and link health in one dashboard. Scored technical checks such as domain, DNS, SSL, headers, and indexability roll into your WebPixie Site Score.

See exactly what changed

Every monitored record is checked daily and scored, so a changed value or a new DNS problem shows up with the previous and new value side by side.

Frequently Asked Questions

Common questions about DNS monitoring.

DNS monitoring is the practice of checking your domain's DNS records on a schedule and alerting you when something changes unexpectedly. Those records include A, AAAA, MX, CNAME, TXT, CAA, NS, and SOA, along with DNSSEC validation and email authentication like SPF, DMARC, and BIMI. WebPixie runs these checks daily from multiple resolvers across 20+ record types, so an edited record or a broken DNSSEC chain shows up with the old and new value, instead of a silent change you discover later. It works alongside domain monitoring and uptime monitoring in one workspace, and you can start on the free plan with the limits on the pricing page.

WebPixie monitors more than 20 DNS record types, grouped by what they control. Name resolution covers A, AAAA, CNAME, NS, and SOA; email authentication covers MX, SPF, DMARC, and BIMI; certificate authority restrictions use CAA; and DNS security covers the DNSSEC records DNSKEY, DS, CDNSKEY, and CDS. General purpose records like TXT, PTR, and SRV are included too. Each type is checked daily, and a changed value is flagged with its old and new value. This is the same data that feeds DNS monitoring alerts and your DNS sub-score, and it works next to SSL monitoring and domain monitoring in one workspace.

WebPixie queries every monitored DNS record daily from multiple resolvers, then compares each response to the previous one. When a response changes, WebPixie flags it with the previous value, the new value, the record type, the detection timestamp, and the resolver path that saw the change. Querying several resolvers also separates a real change from propagation lag, because a value that differs on only one resolver is usually still propagating rather than newly broken. That context helps you tell an authorized update from your team apart from an unexpected modification worth investigating. DNS changes are tracked separately from incident records and sit next to uptime monitoring in the same workspace.

Yes. WebPixie validates the full DNSSEC chain on every daily check, covering the DNSKEY records, the DS records in the parent zone, the RRSIG signatures, and the NSEC negative-response records. The result is reported as secure, insecure, bogus, or indeterminate, so you can tell a correctly signed zone from an unsigned one or a broken one. This matters because when DNSSEC breaks, validating resolvers refuse to return the record at all, and the domain goes dark for users on those resolvers. The daily check flags a bogus chain so you can fix it quickly instead of waiting for user reports. DNSSEC checks run on every plan, including the free one on the pricing page, and are part of DNS monitoring.

No. WebPixie monitors DNS records; it does not host them. Your records stay wherever you run them today, whether that is Cloudflare, AWS Route 53, NS1, your registrar, or another provider, and you keep managing them there. WebPixie adds an independent daily check from multiple resolvers, so when a record changes or a DNSSEC chain breaks, you see it with the old and new value without moving anything. Keeping hosting and monitoring separate is deliberate, because an outside observer can flag a misconfiguration that the system serving the records would not catch on its own. To see what is tracked, visit DNS monitoring; it pairs with domain monitoring for the registration layer, and you can start on the free plan on the pricing page.

Ready to watch your DNS?

Free plan, no credit card. Daily checks across 20+ record types.