Privacy controls
CyberFurl can load analytics only after you opt in. Core product features work without analytics consent.
Perform a comprehensive, RFC-compliant deep inspection of your domain's DNS zone. Identify subtle misconfigurations, propagation anomalies, and security vulnerabilities across SOA, NS, MX, TXT, and A/AAAA records before they cause service degradation.
A DNS Health Check is a comprehensive, RFC-compliant audit of your domain's entire DNS zone. It validates nameserver redundancy, SOA timer accuracy, DNSSEC chain integrity, MX record structure, and IPv6 readiness — catching subtle misconfigurations before they cause deliverability failures or service outages.
DNS is the foundation of all internet services. A single misconfigured SOA TTL, lame delegation, or missing glue record can cause intermittent resolution failures, email delivery drops, and website downtime.
Lame delegations, NS records on different subnets, missing AAAA glue for IPv6, stale SOA serials, and absent DNSSEC signatures are the most common causes of DNS health check failures.
Queries root servers down to the TLD to verify the complete delegation chain and identify lame or broken NS referrals.
Polls all authoritative nameservers to compare SOA serial numbers and detect zone transfer failures or stale secondaries.
Validates individual record syntax, SOA timer values (Refresh, Retry, Expire), and MX priority weighting against RFC standards.
Measures UDP/TCP query latency to each nameserver, checks IPv6 AAAA glue, and validates DNSSEC chain of trust.
Cross-references NS records served by the parent TLD against those returned by your authoritative nameservers, detecting parent-child delegation mismatches that cause resolution failures.
Evaluates Start of Authority (SOA) parameters including Refresh, Retry, Expire, and Minimum TTL against RFC 1912 recommendations to prevent stale caches and slave synchronization failures.
Traces the cryptographic chain of trust from the root zone DS record through your zone's DNSKEY and RRSIG records, identifying broken or missing signatures that disable DNSSEC protection.
Validates dual-stack compatibility by verifying all authoritative nameservers have reachable AAAA records and glue, ensuring your zone resolves correctly over IPv6-only networks.
Analyzes MX record priority structures and associated reverse DNS (PTR) alignment to ensure mail routing is correctly configured and consistent across all nameservers.
Identifies latency discrepancies and routing anomalies across geographically distributed nameservers, highlighting potential anycast misconfiguration or regional resolution failures.
Execute a full-stack cryptographic and syntactical audit of your domain's namespace. Identify single points of failure before they manifest into critical outages.