How to check DNS propagation after you change a record

How to check DNS propagation after you change a record

You changed an A record or moved the name servers, and some people still reach the old server. Before you edit anything again, check which resolvers already return the new value.

Why a DNS change doesn't show up everywhere at once

Resolvers cache answers. When you change a record, a resolver that asked before the change keeps the old answer until the record's TTL runs out, and a few keep it longer than the published TTL. For a while, two visitors can get two different addresses for the same name, and one of them lands on the server you are retiring.

Without a check, the common mistake is to "fix" a change that was right all along. You edit the record again, the caches start over, and the wait gets longer. The other mistake is to switch off the old server while part of the internet still points at it. A name server move takes longer to settle, because the registrar publishes the delegation and the zone publishes its own NS set, and the two can disagree until both are updated.

Check the name servers first, then the record

If you moved the domain to a new DNS host, start with the NS Lookup. It lists the name servers for the domain with the TTL of each one. Ask a public resolver first, then switch to Authoritative, which asks the zone's own servers. When the two lists differ, the delegation change is still moving through caches.

Next, read the zone as its own servers publish it with the DNS Lookup. It queries A, AAAA, CNAME, MX, NS, TXT, SOA, and CAA in one pass and shows each record with its TTL. Pick Authoritative to confirm that the new value is really in the zone. The tool only reads DNS. It doesn't change records at your registrar.

Then run the DNS Propagation Checker. It sends the same query to about 20 public resolvers in parallel and gives the batch about three seconds. Type the value you published, such as the new IP address, and the summary counts the resolvers that return it, for example "18 of 20 resolvers return the new value." With that box empty, a resolver counts as a match when it agrees with the answer most of the others returned. A resolver that stays silent shows "No answer within 3 seconds" and counts as not matching. There is no world map, because the resolvers are anycast and each row names the company that runs it, not a city.

Check DNS propagation for a changed record

  1. If you changed name servers, open the NS Lookup and compare a public resolver with Authoritative.
  2. Open the DNS Lookup, pick Authoritative, and confirm the new value and its TTL.
  3. Open the DNS Propagation Checker, enter the domain, and choose the same record type.
  4. Type the new value in the expected box, tick the robot check, and press Check.
  5. Read how many resolvers match. If some still return the old value, check again after the old record's TTL has passed.

What these checks can't tell you

  • Your own ISP's resolver is not in the list. It can lag behind the public ones, or get there first.
  • A full match means these public resolvers return the new value. An ISP resolver can still hold the old answer until its cache expires.
  • Each check covers one record type. Run it again for a second type.
  • None of the tools edit records. Changes still happen at your DNS host or registrar.

Frequently asked questions

How long does DNS propagation take?

Up to the TTL of the record you replaced. A resolver that cached the old answer keeps it until that timer ends, and a few keep answers longer than the published TTL.

Why do I still see the old IP address after a DNS change?

The resolver you use cached the old answer and its TTL hasn't run out. Compare it with the Authoritative answer in the DNS Lookup to confirm the change itself is right.

Does a full match mean everyone sees the new record?

It means the public resolvers in the check do. A resolver at an ISP can still hold the previous answer until its cache expires.

Can I check MX or TXT records too?

Yes. Choose the record type before you press Check. Each check covers one type.

Tools used in this guide

  • NS LookupDNS Tools

    Name servers from the NS records, with TTL.

  • DNS LookupDNS Tools

    One table of A, AAAA, MX, NS, TXT, SOA, and CAA records for a domain.

  • DNS Propagation CheckerDNS Tools

    One DNS question sent to about 20 public resolvers, with a match against the value you expect.

More from the blog

All guides