Privacy controls
CyberFurl can load analytics only after you opt in. Core product features work without analytics consent.
Perform an authoritative, step-by-step DNS delegation trace from the root servers down to your zone. Diagnose lame delegations, NS record mismatches, glue record anomalies, and authoritative server latency with surgical precision.
DNS delegation tracing follows the complete iterative resolution path from root servers through TLD nameservers to your authoritative nameservers. It exposes every referral hop, DS record, and glue record in the delegation chain — making broken delegations immediately visible.
DNS delegation failures — lame delegations, missing DS records, broken DNSSEC chains, or parent-child NS mismatches — are invisible to standard lookups but cause intermittent or complete resolution failures that are extremely hard to diagnose without a full trace.
Lame delegations returning SERVFAIL, stale parent NS records after migration, missing or expired DS records breaking DNSSEC, and glue record mismatches are the most common delegation errors exposed by a DNS trace.
The trace begins by querying one of the 13 logical root server clusters to retrieve the authoritative TLD nameservers for the queried domain.
The root server responds with a referral to the TLD nameservers. These servers hold the NS delegation and DS records for your domain.
Queries the TLD nameservers to retrieve your domain's delegated NS records, glue addresses, and DNSSEC DS records.
The authoritative nameservers are queried directly for the requested record type, validating the end-to-end resolution chain.
Bypasses caching resolvers and performs a raw iterative trace from root to authoritative, showing every referral hop and response flag in the delegation chain.
Automatically flags nameservers that return non-authoritative responses or SERVFAIL, indicating misconfigured or abandoned zone delegations.
Compares the NS records served by the parent TLD with the NS records in your own zone file, detecting mismatches that cause resolver confusion.
Inspects the Additional section of referral responses to verify that in-bailiwick glue A/AAAA records are present, correct, and match authoritative data.
Analyzes DS records at the parent zone and DNSKEY records at the child zone to validate the complete DNSSEC chain of trust from root to your domain.
Measures the Round-Trip Time for each iterative query hop, identifying slow or geographically distant nameservers that degrade DNS resolution performance.
Uncover hidden misconfigurations, validate glue records, and ensure your authoritative nameservers are strictly compliant with RFC standards.