DNS propagation check
You changed a record and some people still get the old answer. This check asks your own name server what’s true now, then asks 24 public resolvers what they currently believe.
Nothing gets pushed anywhere
“Propagation” makes it sound as if your change travels outward from your DNS host until it has covered the whole internet. DNS doesn’t work that way. Your name servers hold the record and wait to be asked. They don’t send anything to anyone.
The machines that look names up for people are called resolvers. Your internet provider runs one, and so do Google (8.8.8.8) and Cloudflare (1.1.1.1). The first time a resolver is asked for www.example.com, it fetches the answer from your name server and keeps a copy. Every record carries a number, the TTL (time to live), that says how many seconds the copy may be reused. The resolver won’t ask again until that counter hits zero.
So after an edit, each resolver switches to the new value on its own schedule, when its copy of the old one runs out. A resolver that had no copy sees the new value right away.
What this check compares
- It finds the name servers that are authoritative for the name and asks one of them directly, with no cache in between. That answer is the reference, shown with its full TTL.
- It sends the same question, at the same moment, to 24 public resolvers: 17 run by providers in a known place (the United States, Brazil, Spain, Germany, Russia, India, China, South Korea, Australia, Zimbabwe and others) and 7 worldwide networks such as Google, Cloudflare, Quad9 and OpenDNS.
- It compares each full answer with the reference. If a name has several values, the whole set has to match.
You pick the record type: A, AAAA, CNAME, MX, NS, TXT or CAA. A name entered with www. is checked as typed, since www is a separate record.
Reading the map and the table
- Up to date
- The resolver returns the same values as your name server.
- Different
- It returns something else, normally the previous value. The TTL column shows how many seconds its copy has left, and that’s how long you’ll wait for that resolver.
- No answer
- The resolver timed out or refused. That tells you nothing about your record.
If the resolvers return three or more distinct sets of values, the check stops reading the differences as delay. A domain served by a content delivery network, or one using geographic routing, hands out different addresses by region on purpose. Large sites such as wikipedia.org or netflix.com always look like that.
“Does not exist (NXDOMAIN)” for a record you just created is a cached answer too. Resolvers remember that a name was missing for as long as the zone’s SOA record says, often between 5 minutes and 1 hour.
Planning a change so the wait is short
You can’t empty other people’s caches. What you can do is decide ahead of time how long they last.
- At least one full TTL before the move, lower the record’s TTL to
300. If it was 86400, do this the day before. - Make the change. Every resolver now follows within five minutes.
- Keep the old server running during that window so nobody lands on a dead address.
- Once everything works, raise the TTL back to 3600 or more. Short TTLs mean more lookups and slightly slower first visits.
Changing the name servers themselves is slower. The list of name servers is held by the registry of your ending, with a TTL you don’t control: 48 hours for .com. Keep the zone alive at the old DNS host for two days after the switch.
The worldwide networks answer from whichever of their sites is nearest to our server, so the result for Google or Cloudflare describes one of their locations, not all of them. Your own computer, browser and router keep caches too, and this check can’t see those.
Questions people ask
How long does DNS propagation take?
At most the TTL the record had before you changed it. That’s 5 minutes for a TTL of 300 and a day for 86400. The “24 to 48 hours” you often read is a safe upper bound, and it only really applies to a change of name servers.
Can I speed up DNS propagation?
Not after the fact, except on two networks that have a public form for dropping one cached name: Google Public DNS (“Flush Cache”) and Cloudflare 1.1.1.1 (“Purge Cache”). For everyone else, lower the TTL before your next change.
Every resolver is up to date, so why do I still see the old site?
Your device has its own cache. Run ipconfig /flushdns on Windows or sudo dscacheutil -flushcache; sudo killall -HUP mDNSResponder on macOS, then restart the browser. A home router can hang on to the old answer as well, and restarting it clears that.
Why do resolvers show different IP addresses for the same domain?
Either some of them still hold the previous value, or the domain answers differently by region through a CDN or geographic routing. The check tells the two apart by counting the distinct answers.
What TTL should I use for DNS records?
3600 (one hour) suits most records. Go down to 300 in the days around a migration, and up to 86400 for records that never change, such as MX at a large mail provider.