← Back to help centre

DNS monitoring

How DNS monitoring works

Understand the DNS records WebCheck inspects, how baselines detect changes and what DNS results mean.

WebCheck DNS checks resolve the monitored hostname, validate the returned addresses and record normalized A, AAAA, CNAME, MX and NS values. After the first successful result, later runs can identify a change from the stored baseline.

Records WebCheck records

The DNS inspector normalizes supported A, AAAA, CNAME, MX and NS records before calculating a record hash. Sorting and normalization help avoid treating harmless record-order differences as a change.

First run and later runs

The first successful DNS result establishes the baseline. A later record hash that differs from the baseline is recorded as a DNS-records-changed failure so you can confirm whether the change was intentional.

What to do after a change

Check the DNS provider change history, recent hosting or CDN work, the expected TTL and the records returned by the authoritative configuration. If the change is intentional, review the target baseline workflow before treating it as an incident.

Important limitation

One resolver and monitoring environment cannot represent every resolver view everywhere. DNS propagation and caching can make results differ temporarily from a local lookup. WebCheck DNS monitoring also does not replace a complete DNS security or email configuration audit.