CloudSpex

Free domain tool

Nameserver Checker

Ask every delegated nameserver directly and find the one that is listed but does not serve the zone.

A resolver hides this problem

Ask a recursive resolver for a domain and it retries nameservers until one answers, so a broken server stays invisible while a share of real lookups quietly slows down or fails. This checker queries each delegated nameserver on its own, which is what makes lame delegation visible.

To see whether the zone is signed and whether a validating resolver accepts the chain, use the DNSSEC Checker.

This reads both sides of the delegation. The child side comes from the domain's own NS records, with each server asked directly. The parent side — the NS records and glue the TLD hands out — cannot be read through a normal recursive lookup, so this checker queries the parent zone's authoritative servers directly, without recursion. On networks where that direct query is blocked or intercepted, the parent section says Not assessed instead of guessing. For the wider DNS picture, use the DNS Health Check; to see which certificate authorities these nameservers authorise, use the CAA Record Checker.

Frequently asked questions

What is lame delegation?

It is when a nameserver is listed in a domain's delegation but does not actually serve the zone. Resolvers pick nameservers at random, so some lookups go to the server that cannot answer and are slowed or fail, while others succeed. That intermittency is what makes it hard to notice.

How does this checker find it?

It reads the delegated NS records, then queries each of those nameservers directly instead of asking a recursive resolver. A resolver hides the problem by retrying another server until one answers; asking each server on its own is what exposes the one that cannot.

Why do you say a nameserver "answered for the zone" instead of "is authoritative"?

Because that is what was measured. Reading the authoritative-answer flag in the DNS header requires access this checker does not have, so it reports that the server responded with the zone's NS records — strong evidence it serves the zone, but not the flag itself.

Do you check the parent delegation or glue records?

Yes, when the parent zone's authoritative servers can be queried directly — they are asked, without recursion, for the delegation and its glue, and the answer is always attributed to the server that gave it. Those records cannot be read through a normal recursive lookup, and on networks where the direct query is blocked or intercepted the parent section says Not assessed instead of guessing.

What is glue, and when is it required?

Glue is the nameserver IP address the parent zone hands out alongside a delegation. It is only required when a nameserver's own name lives inside the zone it serves — without glue, resolving that name would need the very zone being delegated. Nameservers outside the zone do not need glue, and this checker does not flag them for lacking it.

Is one nameserver a problem?

It is a resilience gap rather than a fault. It works today, but there is nothing to fall back to: if that server becomes unreachable the domain stops resolving entirely, taking mail and the website with it. RFC 2182 asks for at least two.

All my nameservers are under one domain name. Is that bad?

Not necessarily, and it does not affect the score here. Every large DNS provider uses a single name with servers spread worldwide by anycast, so the name alone says nothing about whether they share a network. It is shown for you to judge.

What does it mean if the nameservers disagree?

Each nameserver reports its own view of the zone's NS records. If those views differ, the answer a user gets depends on which server their resolver happened to ask, so the domain behaves differently for different people.

What does "Not assessed" mean here?

It means the NS lookup returned no delegation at all, so there was nothing to check and no score is produced. A nameserver that simply did not reply is also left unassessed rather than being reported as broken — a timeout is not evidence of a misconfiguration.

Delegation breaks most often during registrar and DNS provider moves.

Add your domain to CloudSpex to monitor NS records and the rest of your DNS configuration continuously.

Start Monitoring Free