My Tool Studio
Webmaster

DNS Propagation Checker

A DNS propagation checker shows whether a DNS change has reached the resolvers people actually use. Enter a domain, pick a record type such as A, MX, TXT or NS, and press Check propagation. The tool asks up to 13 resolvers at once, including Google, Cloudflare, Quad9, OpenDNS, AdGuard, Mullvad, AliDNS, DNSPod and our own server, and shows each answer with its TTL and response time. Type the value you expect, such as your new server's IP address, and every row is marked as a match or not, with a count of how many resolvers already agree. Identical answers are grouped, so a split between old and new values is easy to see. Auto re-check repeats the test while you wait, you can add your own DoH resolver, and the results export as CSV.

Always freeNo sign upRuns in your browser
Record type

For example the new IP address, mail server or TXT token you just published.

Resolvers (13 selected)

How to use

01

Enter the domain and record type

Type the name you changed, such as example.com or mail.example.com, and pick the record type: A or AAAA for a new server, MX for an email move, TXT for a verification token or SPF, NS for a nameserver change.

02

Add the value you expect

Paste the new value, such as 203.0.113.10, and choose Contains, Exact or Regex matching. Leave it empty if you only want to see what each resolver returns right now.

03

Check, then watch

Press Check propagation and read the match count and answer groups. Turn on auto re-check until every resolver shows the new value, then download the CSV if you need a record.

Why DNS Propagation Checker

How long old DNS answers can stay cached

The TTL of the record before your change sets the longest time any resolver can keep serving the old value. The table shows common TTLs and what they mean in practice. The checker shows each resolver's remaining TTL, which counts down, so a low number means that resolver will fetch a fresh answer soon.

TTL before the changeOld answers can last up toTypical use
3005 minutesRecords you plan to change soon
36001 hourCommon default at many DNS hosts
144004 hoursSome shared hosting panels
864001 dayStable records that rarely change
NS change at the registrarUp to about 48 hoursMoving to a new DNS provider

A checklist for a smooth DNS change

Most propagation stress comes from changing a record with a long TTL at the last minute. Plan the change a little ahead and the switch takes minutes instead of a day.

  • Two days before: lower the TTL of the records you will change to 300 seconds.
  • Keep the old server or mailbox running until the old TTL has fully passed.
  • Make the change, then run this checker with the new value in the expected field.
  • Turn on auto re-check and wait until every reachable resolver shows a match.
  • If only you still see the old value, flush your computer's DNS cache or restart your router.
  • Once everything matches, raise the TTL back to an hour or more.

Common questions

What does DNS propagation actually mean?
Nothing is pushed around the world. When you change a record, your DNS host serves the new value at once. Resolvers keep handing out the old answer from their cache until its TTL runs out, then fetch the new one. Propagation is simply the time it takes for those caches to expire.
How long does DNS propagation take?
At most as long as the old record's TTL. A TTL of 300 means about five minutes, 3600 means an hour, and 86400 means up to a day. A nameserver change made at the registrar can take up to 48 hours, because the NS records in the parent zone often carry long TTLs.
Which DNS resolvers does the propagation checker ask?
Google Public DNS, Cloudflare, Quad9, OpenDNS, unfiltered AdGuard DNS, Mullvad, DNS.SB, Control D, CIRA Canadian Shield, NextDNS, AliDNS, DNSPod and our own server's resolver. You can untick any of them, or add your own DNS over HTTPS endpoint.
Why do resolvers still disagree a day after my change?
If the domain uses a CDN or GeoDNS, resolvers get different addresses on purpose, based on where they are. That is not a propagation problem. Check the answer groups: if every group belongs to the same provider, the setup is working as designed.
Why does a resolver show as unreachable from my browser?
The checks run in your browser using DNS over HTTPS. Some resolvers do not accept requests from web pages, and a firewall, school network or browser extension can block others. An unreachable row says nothing about your domain; it only means that resolver could not be asked from here.
Is checking public resolvers the same as checking DNS from different countries?
Not quite. These resolvers are anycast networks, so the node that answers is the one nearest to you. For ordinary cache-based propagation the result is the same, because a record changes everywhere once the TTL runs out. Sites that list cities run their own servers in each place, which matters mainly for GeoDNS setups.
How can I make a DNS change spread faster?
Lower the record's TTL to 300 seconds a day or two before the change, wait for the old TTL to pass, then make the change. Raise the TTL again once everything points to the new value. A TTL that resolvers have already cached cannot be shortened after the fact.
Can I clear the cache of Google or Cloudflare DNS?
Yes, for those two. Google Public DNS and Cloudflare 1.1.1.1 both run a public cache purge page where you enter a domain and record type. Other resolvers do not offer one. Your own computer and router cache answers too, so flushing the local DNS cache helps when only you still see the old value.
What should I type in the expected value field?
The new value, or a unique part of it. For an A record that is the IP address. For MX you can type just the mail server name, such as mail.example.com, with Contains matching. For a TXT verification token, paste the token. Regex matching helps when several values are acceptable.
Can I add my own DNS server to the propagation check?
You can add any DNS over HTTPS endpoint that follows the standard RFC 8484 format, such as a company resolver's DoH address. Classic DNS servers on port 53 cannot be reached from a web page, so a plain IP address like 192.0.2.53 will not work.

More Webmaster tools

View all