NetLeakCheck
CLIENT-SIDE DOH • ZERO INTERMEDIARY

Global DNS Propagation & Security Auditor

Perform real-time DNS queries directly from your browser via Cloudflare (1.1.1.1) and Google (8.8.8.8) encrypted DNS-over-HTTPS. Inspect A, AAAA, MX, TXT, NS, and audit SPF & DMARC policies.

A Records (IPv4) TYPE 1
AAAA Records (IPv6) TYPE 28
MX Records (Mail Servers) TYPE 15
TXT Records & SPF / DMARC Security TYPE 16
🛡️
SPF Security: Checking SPF configuration...
🔒
DMARC Policy: Checking DMARC policy...
Authoritative Name Servers (NS) TYPE 2

Understanding DNS-over-HTTPS (DoH) & Domain Hygiene

Traditional DNS queries are broadcast over plaintext UDP port 53, leaving them vulnerable to ISP interception, Wi-Fi eavesdropping, and Man-in-the-Middle (MITM) spoofing. DNS-over-HTTPS (DoH) wraps DNS requests in TLS encryption (RFC 8484), guaranteeing query privacy and cryptographic integrity.

1. The Critical Importance of SPF, DKIM, and DMARC

Email spoofing remains the leading vector for phishing and CEO fraud. Publishing correct DNS records protects your domain reputation:

  • SPF (Sender Policy Framework): Specifies which mail servers (e.g. Google Workspace, Sendgrid) are authorized to send email on behalf of your domain.
  • DMARC (Domain-based Message Authentication): Tells receiving mailboxes whether to accept, quarantine, or outright reject spoofed emails that fail SPF or DKIM signatures.

2. DNS Propagation Delays Explained

When you update DNS records at your registrar, the changes must propagate across thousands of recursive resolvers worldwide. The speed of propagation is determined by your record's Time-to-Live (TTL). Setting a low TTL (e.g. 300 seconds) prior to a server migration ensures near-instant switchover.