DNS Propagation Checker
Is your new DNS record visible yet? Compare public resolvers and locations at once.
Check DNS propagation
Propagation
Public resolvers
Google Public DNS from 20 locations
These are the caches of six public resolvers and the answers name servers give to networks in these cities — not every internet provider’s resolver. A different answer goes away once its remaining TTL has run out.
About the DNS Propagation Checker
After you change a DNS record, the old value lives on in resolver caches until its TTL runs out — that is what “DNS propagation” really is. This checker asks six large public resolvers (Cloudflare, Google, Quad9, AliDNS, Control D and CleanBrowsing) and Google Public DNS on behalf of networks in 20 cities, from N. Virginia to Mumbai and Sydney, for the same record — and puts identical answers in the same group, so differences stand out at once.
Enter the value you just published to see where it is already visible. For every answer you see how many seconds the resolver may keep it (the remaining TTL), so you know the longest you still have to wait, plus each resolver’s copy of the zone’s SOA serial. It shows the caches of these public resolvers and the answers GeoDNS and CDNs give to those networks — not the cache of every internet provider.
How to use it
- Enter the name you changed (for example
www.example.com) and pick the record type. - Optional: enter the new value you published — an IP address, a mail server such as
10 mail.example.com, or the TXT text. - Press Check propagation. Rows fill in as each resolver answers; identical answers share a letter (A, B, …).
- Read the summary: how many show the expected value, and within how long the others should refresh. Press Check again later to see the change spread.
- Use Copy summary or CSV to keep the results.
Examples
d1.awsstatic.com — A
Answers depend on location — 20+ different answer sets (GeoDNS or CDN)
CloudFront answers each location with nearby edge servers, and Google reports the answers as specific to each /24 subnet.
google.com — MX
All answers agree: 10 smtp.google.com.
Common uses
- Checking that a website move to a new server or host is visible worldwide.
- Confirming a new MX, SPF or verification TXT record before you switch mail or verify a domain.
- Seeing how long the old value can linger, from the remaining TTLs.
- Spotting a name server that still serves an old copy of the zone (different SOA serials).
What “propagation” really is
DNS has no push: when you change a record, your DNS host’s name servers answer with the new value at once, but every resolver that fetched the record earlier keeps its copy until the TTL it came with runs out (RFC 1035 §3.2.1). The TTL shown for each resolver is the time left on its copy — the longest it can still return the old value. A name that did not exist before can be cached as “does not exist” for the SOA’s negative-caching time (RFC 2308). Lower the TTL a day before a planned change, and the switch takes minutes.
How the 20 locations work
Browsers cannot send DNS from other countries, so the checker uses EDNS Client Subnet (RFC 7871): it asks Google Public DNS to resolve the name as it would for a user in a given network. Each location is a /24 network from the IP ranges Amazon Web Services publishes for that region (ip-ranges.amazonaws.com), and each was checked against a CDN that answered with an edge in that city. When the name servers say an answer applies to that subnet only (scope above /0), different answers per location are GeoDNS at work, not stale caches.
The resolvers
- Cloudflare (1.1.1.1) — does not send client-subnet information on, so it answers as for its own nearest data centre.
- Google Public DNS (8.8.8.8) — also used for the 20 locations.
- Quad9 (9.9.9.9) — blocks domains on its threat list and then answers “does not exist” (NXDOMAIN), per the Quad9 FAQ.
- CleanBrowsing (security filter) — also filters malicious domains, so a blocked domain does not show its real records there.
- AliDNS (223.5.5.5, Alibaba Cloud) and Control D (free unfiltered resolver).
All six answered DNS-over-HTTPS requests from web pages.
Sources
- RFC 1035 — TTL and caching; RFC 2308 — negative caching.
- RFC 7871 — EDNS Client Subnet; RFC 8484 — DNS over HTTPS.
- Google Public DNS JSON API — the edns_client_subnet option.
- AWS IP address ranges and AWS Regions — the networks used for the locations.
Limitations
- Only these public resolvers are asked. Your internet provider’s resolver, your router and your computer have their own caches, and can keep an old answer until its TTL runs out.
- The locations are simulated through Google Public DNS; they show what GeoDNS answers for those networks, not what each country’s internet providers have cached.
- Browsers cannot ask a domain’s own name servers directly, so the authoritative answer is not shown separately.
- Resolvers may limit how often they answer one visitor; if rows show errors, wait a minute and check again.
Privacy
The name you check is sent from your browser to the six resolvers listed above, without cookies; each sees your IP address and the name, as for any DNS query. The location checks send Google one of the fixed AWS subnets listed on this page, not your own address. MySmartCoPilot’s servers are not involved and store nothing.
Frequently asked questions
How long does DNS propagation take?
As long as the old record’s TTL, counted from when each resolver last fetched it — minutes for a TTL of 300, up to a day for 86400. Changing name servers takes longer, because the registry’s delegation has its own TTL: 172,800 seconds (2 days) for .com. The remaining TTLs on this page show the longest wait for these resolvers.
Why do some locations show different IP addresses?
Many sites use a CDN or GeoDNS that sends each region to nearby servers. When the name servers mark an answer as specific to a network (scope above /0), the checker says so — that is expected. Enter the value you set to check one address.
Can I make propagation faster?
Lower the TTL of the record a day or more before you change it (for example to 300 seconds), then raise it again afterwards. Google and Cloudflare also let anyone refresh one name in their cache: Google Public DNS Flush Cache and Cloudflare Purge Cache.
Why does a resolver say the name does not exist?
Either it cached “does not exist” before you created the record (it expires after the negative-caching time shown), the record is in the wrong zone, or — for Quad9 — the domain is on its threat list, which Quad9 answers with NXDOMAIN.
What does the SOA serial tell me?
The version number of the zone’s SOA record as each resolver has it cached. A lower serial from the same primary name server usually means an older copy, or a name server that has not received the latest zone yet — but every record is cached on its own, so it does not prove that the record you checked is old. Domains served by two DNS providers have two SOA records with unrelated serials; the checker says so instead of comparing them.