Public DNS observatory

See what yourdomain reveals.

Inspect the public addresses, verification records and certificate permissions behind a domain.

Public recordsPublic records · Query and inspect
PUBLIC RECORDS

Inspect public records

DNS / LIVE
Quick typesNo https:// or path

Enter a name to inspect the information it returns publicly.

01TXTReview verification text
02CAACheck certificate permissions
03NSIdentify nameservers
OBSERVATIONS

Understand public visibility

Record notes ↗
01

Public records do not reveal an entire DNS zone

Understand the difference between querying one name and enumerating subdomains.

Read the guide →
02

Check certificate permissions with CAA

Read flags, tags and values without confusing permissions with issued certificates.

Read the guide →

About public lookups

Does this reveal every subdomain?

A lookup for example.com is different from a lookup for app.example.com. DNS answers a question about a specific name and type. Looking up the apex does not list every subdomain; “All types” covers common types for the name you entered.

Does “All types” include every subdomain?

No. It queries common types for the name you enter. Subdomains, service records and email authentication records require their own complete names.

Why can this differ from my DNS control panel?

These answers come from a recursive resolver and can reflect its cache, proxy settings or provider-specific features. Compare TTL and the actual configuration; a single lookup is not a global propagation test.