DNS Propagation Checker - Verify Records Across Resolvers

DNS Propagation Checker

Query TXT, A, AAAA, NS or MX records across three independent resolvers and confirm they have propagated.

Try:

About DNS Propagation Checker

The CSR.plus DNS Propagation Checker answers the question every DNS-01 user asks: has my record reached the internet yet? It queries your record type (TXT, A, AAAA, NS, MX) against three independent public resolvers — Cloudflare, Google and AdGuard — and reports per-resolver status.

For ACME DNS-01 challenges, paste the TXT value Let's Encrypt gave you and the checker confirms not only that the record exists but that it matches, resolver by resolver.

Why use

  • Three independent resolvers (Cloudflare 1.1.1.1, Google 8.8.8.8, AdGuard 94.140.14.14)
  • Supports TXT, A, AAAA, NS and MX record types
  • Expected-value matching for _acme-challenge TXT records
  • Per-resolver latency and answer display

How to use

  1. Enter the record name to check, for example _acme-challenge.example.com.
  2. Select the record type (TXT for ACME DNS-01).
  3. Optionally enter the expected value returned by Let's Encrypt.
  4. Run the check and wait until all resolvers report the record.

Frequently asked questions

▸How long does DNS propagation take?

Most records propagate in seconds to minutes, but aggressive caching can keep stale answers for up to 24 hours. This tool tells you when all three resolvers agree.

▸Why does one resolver see my record and another not?

Resolvers cache answers independently and pull from different upstreams. Until all of them return the record, treat propagation as incomplete — Let's Encrypt may hit any resolver.

▸Does the checker verify my TXT value?

Yes. If you enter the expected value, the result shows a green match only when every resolver returns that exact value.

▸Can I check records other than TXT?

Yes — A, AAAA, NS and MX are supported, which is handy when debugging DNS before pointing a domain at a server.

Namecheap

Need a new SSL certificate?

DV, OV, EV and wildcard certificates from just $5.98/yr — issued in minutes.

Get SSL on Namecheap

Affiliate link — we may earn a commission at no extra cost to you.

More free tools

Certificate Viewer

Paste or upload an X.509 certificate to inspect its subject, issuer, validity, key, fingerprints, SAN and extensions — all locally.

Certificate / Key Matcher

Check whether a private key and a certificate belong to the same key pair — computed locally, the key never leaves your browser.

PEM Viewer

Paste a PEM bundle (certificates, keys, CSRs) and see a structured breakdown of every block — locally.

SSL Format Converter

Convert between PEM, PFX/PKCS#12 and P7B/PKCS#7 — all locally in your browser.

SSL Checker (A-F Grade)

Grade any domain from A to F: TLS versions, certificate health, chain trust and HSTS.

SSL Bulk Checker

Check multiple SSL certificates at once

ACME Challenge Preflight

Test HTTP-01 and DNS-01 validation before Let's Encrypt does: DNS, port 443, well-known reachability and TXT records with fix suggestions.

Let's Encrypt Checker

Detect Let's Encrypt certificates (R3/R10/E5/E6), see the 90-day renewal countdown, chain health and renewal advice.

LE Chain Compatibility

See whether your site serves the new ISRG E5/E6 chain or the legacy cross-signed chain and whether old devices trust it.

ACME Command Generator

Generate copy-paste issuance commands for Certbot, acme.sh, lego and win-acme with HTTP-01 or DNS-01.

Certificate Inspector

Enter a domain to inspect certificate validity, expiry, TLS protocol and full chain integrity.

SSL Expiry Checker

Quickly check a domain's SSL certificate expiry date and remaining days.

Certificate Transparency Lookup

List every certificate ever issued for a domain in public CT logs — discover shadow and unauthorized certs.

CAA Record Checker

Query a domain's DNS CAA records to see which Certificate Authorities are allowed to issue certificates for it.

Certificate Revocation Checker

Verify whether a certificate has been revoked via its CRL distribution points, and view embedded OCSP endpoints.

SSL Handshake Tracer

Perform a real TLS handshake and record every step: DNS, TCP, negotiated TLS version and cipher, and each certificate returned.