New AI Incident Response, Multi-Region Agents, and Custom-Domain Status Pages, May 2026
Services Pricing Dashboard
DNS monitoring

See the DNS answer customers receive, not the one you expected.

Validate important records, compare public resolvers, detect propagation disagreement, and optionally require a DNSSEC-validated answer before a bad change becomes a widespread outage.

The public scan proposes coverage first. You review every check before anything is created.

The monitoring gap

DNS failures are often partial before they are global.

One resolver may hold a stale answer while another has the new record. A zone can resolve while returning the wrong target, or DNSSEC can fail even though an unsigned query appears healthy. A useful DNS check compares the answer, not just query success.

What it covers

A monitoring workflow built for this signal.

01

Validate the record you depend on

Monitor common address, mail, nameserver, alias, text, and authority record types.

02

Compare public resolver answers

Surface disagreement between configured resolvers so propagation lag and split answers are visible.

03

Check expected values and DNSSEC

Require a known target and optionally treat the absence of a validated DNSSEC answer as degraded.

From setup to response

Three steps from intent to a usable alert.

  1. 1

    Scan the domain and keep the recommended DNS check.

  2. 2

    Choose the record type, expected value, resolver set, and DNSSEC option.

  3. 3

    Route a down result or resolver disagreement with the returned records attached to the monitor result.

Evidence model

What the check can actually answer.

SignalValidationOperational question
ExistenceRecord query resultDid the requested record type return an answer?
CorrectnessExpected-value matchDoes the answer contain the intended target?
PropagationResolver answer comparisonDo public resolvers agree?
IntegrityDNSSEC AD validationDid a validating resolver authenticate the answer?
Questions

DNS monitoring FAQ

Which DNS records can ServiceAlert monitor?

DNS monitors support A, AAAA, MX, NS, CNAME, TXT, and SOA records.

Can ServiceAlert detect DNS propagation differences?

Yes. Multi-resolver mode compares answer sets and marks the result degraded when configured resolvers disagree.

Does DNS monitoring validate DNSSEC?

It can. When DNSSEC validation is enabled, ServiceAlert requires an authenticated-data response from a validating resolver and surfaces failure as degraded.

Recommended start

Monitor the records that route real traffic.

Begin with a domain scan, then keep only the DNS checks and resolver rules your operating model needs.

Scan DNS coverageView monitoring overview