Big protection. Even on the free plan. Meet your new DNS home
KumoDNS
Documentation

The free DNS checking tools

Four tools that ask the internet what it can actually see — delegation, records, mail and SPF — and when each one is the right question.

Four checkers are free, need no account, and ask the public internet rather than this portal. That difference is the whole point: the portal shows you what you have saved, and these show you what the world can see.

They are all under Playground in the site footer, and the same four appear under Tools in the portal once you are signed in.

Which one answers which question

ToolAnswers
DNS lookupWhat does a record resolve to right now?
Delegation checkIs this domain actually pointed at us?
Mail health checkDo the mail records hang together?
SPF checkerIs the SPF record valid, and within its limits?

DNS lookup

Asks for one record type on one name and shows what comes back. It queries fresh every time, which is why it is a better test than checking from your own machine — your computer is the most likely thing in the chain to be holding a stale answer.

Use it after any change, once the old TTL has had time to expire.

Delegation check

Compares the nameservers the registry publishes for your domain against the ones actually answering. This is the first thing to run when a change in the portal appears to do nothing — nine times out of ten the answer is that the domain is still delegated somewhere else, so nobody is asking us.

⚠️ This is the check that explains the most confusing failure in DNS: records that are correct, saved, published to every nameserver, and completely invisible. See pointing your registrar at KumoDNS.

Mail health check

Looks at the records mail depends on together rather than one at a time — MX, SPF, DKIM and DMARC — because a mail problem is usually a disagreement between them rather than a single record being wrong.

It reports what is present and what is missing. It does not send mail and cannot tell you whether a particular message was delivered.

SPF checker

SPF has a rule that catches almost everyone: a record may cause at most ten DNS lookups while it is being evaluated, and a record that exceeds it does not fail safely — it is treated as an error, and receivers may ignore the record entirely.

The checker counts those lookups the way RFC 7208 counts them — terms, not queries, include: and a and mx and redirect= each costing one, exp= excluded — and shows the running total so you can see which term pushed you over.

It also reports void lookups, a separate limit of two: terms that resolve to nothing, usually an include: for a service you stopped using.

What none of them do

They are read-only and see only public data. They cannot change a record, they cannot see a zone that is not delegated to public nameservers, and they have no access to your account — which is why they need no sign-in.

Last reviewed 2026-09-24.

Not what you needed?

Open a ticket from the control panel, or use the contact form if you cannot sign in. If a domain is down, the status page is the fastest way to find out whether it is us.

Top