Skip to content

DNS monitoring that catches a hijacked record.

A wrong DNS record doesn't take your site down — it quietly sends your visitors and email somewhere else. Uptimia watches every answer your nameservers give and alerts you within minutes of a change you didn't make.

30-day free trial · 50 DNS zones No credit card GDPR-ready
Watched names
20
Sweep cadence
5min
Checkpoints
171+
Countries covered
70+

A mail record changes — and it wasn't you

Nothing goes down. Every nameserver keeps answering — the answer is just wrong, and your email starts going to the wrong server. Here's how that plays out with Uptimia watching.

09:14:02 The @ MX answer stops matching baselineCaught within one 5-minute sweep — every nameserver still up mail: misrouted
09:14 One incident for the zone — not a floodMail records default to critical → your alert channels page the team mail: misrouted
09:21 You reverse it at the registrarAcknowledged, MTTA 7 min — nothing to click in Uptimia, it keeps watching mail: misrouted
09:31 Back at baseline — it closes itselfThree consecutive sweeps verify the restore; no re-checking by hand mail: where it belongs
17 minchanged → verified
Verified, not assumed.09:31
A wrong MX doesn't take anything down — mail just quietly goes somewhere else. This one lived 17 minutes, because the baseline noticed what uptime checks never would.
caught in one sweep — ≤ 5 minone incident, not per-record spamverified ×3 before closingA · MX · NS · TXT — per-record baselines
And without the baseline? Nothing was "down" — every server answered promptly, with the wrong answer. You learn about it when someone asks why invoices have bounced for a week. bounced mail

What's watched in your zone

The records your zone serves and the health of the nameservers serving them — read straight from your authoritative servers, no resolver cache in between.

A·AAAA Address records & aliasesA, AAAA and CNAME, baselined
MX·TXT Mail & policy recordsMX, SPF & DMARC, CAA
NS Nameserver reachabilityEvery server answers — or you know
SOA Serial agreementAll servers on the same version
5 min · every sweep authoritative-direct, no resolver cache
LAME Delegation & lame serversRegistrar delegation, re-checked every 22 h
DS·DIFF DNSSEC & record changesDS state recorded · diffs alerted
* Any name you addYour baseline, your record list
Alerts name the exact failure: a changed record, a hijacked answer, a dead nameserver, SOA serial drift, a lame delegation, or a record that appeared or vanished. vs your baseline

Changes, nameservers and delegation

Change detection

Detect DNS hijacking and silent edits

Uptimia keeps a per-record baseline of what your zone should answer and diffs the live authoritative answer against it every sweep. A repointed A record or swapped SPF surfaces even while every server stays green.

  • A saved baseline per record — any real, non-TTL difference opens a change episode
  • Round-robin safe — answer sets are sorted, so shuffled order never false-alarms
  • Within 5 minutes — a change is caught on the next sweep, at most five minutes away
Watch the certificates your CAA record guards
MX@ · mailwas 10 mail.caldmont.com→ mx.mailhijack.ru
A@ · addresswas 203.0.113.10→ 198.51.100.7
TXT@ · spfv=spf1 include:_spf… ~allunchanged
2 / 26records off
baseline
Change alert09:14:18
@ MX and @ A no longer match the saved baseline — every server still answers green, the answers are simply wrong.
SlackEmailSMS+ PagerDuty…
CDN reshuffled the answer order? Answer sets are sorted before comparing — round-robin rotation never false-alarms. no alert
Nameserver health

Down only when two probes agree

A flaky link between one probe and one server should never wake you at 3 a.m. When the primary probe sees a nameserver unreachable, a second probe in a different location re-checks it before the incident opens.

  • Primary + confirm probe — a down server is re-checked from a second location first
  • UDP and TCP reachability, answer time and the AA bit checked on every server
  • SOA serials compared across servers — drift beyond your window opens a trouble episode
The 171+ checkpoints your zone is checked from
1
Primary probe — Frankfurt
ns3 · UDP timeout · 09:14:02
unconfirmed
2
Confirm probe — New York
ns3 · UDP ✗ · TCP ✗ · 09:14:31
2 / 2 agree
Nameserver down09:14:31
ns3.caldmont.com alerted only after both vantage points agreed — the zone's other nameservers keep answering.
SlackEmailSMS+ PagerDuty…
Only one probe can't reach a server? A flaky path between one probe and one nameserver is logged and re-swept — nobody is paged at 3 a.m. no page
Delegation

Catch a lame delegation

Every 22 hours, Uptimia compares the registry's delegation against what your zone actually answers, and probes each delegated server for a real authoritative reply. A nameserver the registrar still lists but that no longer answers is exactly the problem you never see coming.

  • Parent vs child NS — the registry's delegation compared to your zone's own answer
  • Lame-server probe — each delegated server is checked for an authoritative answer
  • DNSSEC state, recorded — signed or unsigned is shown alongside, never judged for you
Watch the registration behind the delegation
LAMEns4.caldmont.com
delegation check · every 22 h
chad.ns.cloudflare.comAA ✓ · 24 ms
lia.ns.cloudflare.comAA ✓ · 31 ms
ns3.caldmont.comAA ✓ · 39 ms
ns4.caldmont.comREFUSED
The registry still lists ns4 — but it no longer answers for the zone. Every resolver that picks it gets silence.
Registry — parent NS
.io delegates 4 servers
chad · lia · ns3 · ns4
Your zone — child NS
zone answers the same 4
sets match — no drift
Authoritative probe — every server
chad ✓  lia ✓  ns3 ✓
ns4 → REFUSED · lame
DNSSEC state is recorded, not judged — signing the zone later shows up as a plain change, never a pass or fail. unsigned · noted
One incident, self-healing

One incident per zone, self-closing

When several records or servers misbehave at once, you get one zone incident, escalating only for the worst thing actually happening. Once the zone is back at baseline for enough consecutive sweeps, the incident verifies and closes on its own.

  • One incident, not a flood — alertable changes and health episodes roll into a single incident
  • Verified restore — a change is "back" only after every reachable server agrees across consecutive sweeps
  • A dead nameserver that returns clears immediately — it was already double-confirmed
Page the next person until someone acknowledges
MX@ · mailchanged · 09:14:02critical
A@ · addresschanged · 09:14:02critical
NSns3 · unreachableconfirmed ×2 · 09:15:31trouble
1zone
incident
Zone incident #81209:14 → 09:31
Three things broke at once — one incident, escalating as the worst of them. Not five alert threads.
opened — critical09:14
acknowledged via signed link09:21
baseline again — verify 1/309:26
verified ×3 — closed09:31
Never closed on a lucky sweep — the zone has to hold at baseline across consecutive sweeps before the incident closes. A returning nameserver clears at once — it was already double-confirmed. auto-close

You decide what pages you

Address, mail and nameserver records page as critical by default, policy records as trouble — every group is yours to toggle and re-rank.

Sensible defaults

Addresses, mail and NS records default to critical; policy records (SPF, DMARC, CAA) to trouble. TTL-only changes stay info — never paging.

A change you meant, one click away

Acknowledge a planned change and the new answer becomes the baseline. Mark rotating records "dynamic" and Uptimia watches that they exist, not what they say — so CDN and GeoDNS pools stop crying wolf.

Migrating? Snooze, don't go blind

Silence change alerts for 4 hours, 24 hours or 7 days. Changes keep recording — they just stop paging.

Watched records & change alerts
Addresses
A · AAAA · CNAME
Critical
Mail
MX
Critical
Nameservers
NS
Critical
Policy
TXT · _dmarc · CAA
Trouble
Watched names — up to 20
@wwwapishopmail+ add a name
Snooze change alerts
Off4 h24 h7 d
TTL-only changes stay info · restore verified over 3 sweeps

How DNS monitoring works

One monitor watches one zone — nothing to install, checks run straight against your authoritative nameservers.

Step 120 seconds

Enter your domain

Uptimia discovers your nameservers, watches @ and www by default, and snapshots today's answers as the baseline.

Zone
caldmont.com
4 nameservers found · 14 records baselined
Sweep cadence
Every 5 minutes · fixed
Vantage
Authoritative-direct · AA verified
Step 220 seconds

Tune what pages you

Keep the defaults or adjust severities, add names, mark rotating CDN pools dynamic. Alerts use your existing channels.

Change alerts
Addresses · criticalMail · criticalNS · criticalPolicy · trouble
Alert via
Email · Slack · SMS · your escalation policy
CancelStart watching →
Step 3every 5 min

Get alerted when the answer is wrong

Each sweep reads your authoritative answers, diffs them against the baseline, and checks nameserver health. Anything alertable opens one zone incident.

#ops-alerts
Uptimia 09:14
⚠ DNS change — caldmont.com
@ MX & A differ from baselinecritical09:14:02 UTC
Also sent to EmailSMSPagerDuty

Baseline the zone once.Hear about every answer that changes.

Every zone, every sweep, every alert channel — free for 30 days, and none of it is a paid add-on.

Start your free 30-day trial
30 days free no credit card cancel anytime

What is DNS monitoring?

DNS monitoring is an automated service that continuously queries your domain's own authoritative nameservers and compares the answers against a known-good baseline. It alerts you when a record changes unexpectedly, a nameserver stops answering, or your delegation drifts — before the problem reaches your customers.

Every 5 minutes

How does DNS monitoring work?

Uptimia
authoritative-direct
query · AA verified
Your nameservers
the live answer

Each sweep diffs every watched record against its saved baseline and checks each nameserver's reachability and SOA serial. A real difference opens a change episode; a confirmed-unreachable server opens a health episode.

The distinction

Authoritative answers, not propagation

Public resolver
cache · TTL blur
bypassed on purpose
Your nameservers
the source of truth

Our free DNS Checker asks resolvers in 14 countries "has my change propagated?" This monitor does the opposite — it reads your own servers to answer "is my zone serving the right answers?"

Records & severities

What a bad change breaks

Uptimia groups records so alerts match the blast radius: address, mail and NS default to critical, policy to trouble, TTL-only changes to info.

Free tool: check your DNS propagation
Record groupRecords watchedDefault alertA bad change means
AddressesA · AAAA · CNAMECriticalTraffic sent to the wrong server
MailMXCriticalEmail silently rerouted or dropped
NameserversNSCriticalYour whole zone can be taken over
PolicyTXT · SPF · DMARC · CAATroubleSpoofed mail or rogue certificates
TTL onlyany record's TTLInfo · never pagesCaching timing only — nothing served changed

DNS monitoring FAQ

01What is DNS monitoring?+
An automated service that reads your domain's answers straight from its own authoritative nameservers and compares them to a saved baseline. It alerts you when a record changes unexpectedly, a nameserver stops answering, or your delegation drifts — so a hijacked answer is caught before it reaches customers.
02How often does Uptimia check my DNS?+
Every 5 minutes. Because Uptimia reads your authoritative servers directly rather than waiting on caches, a change surfaces on the next sweep — at most five minutes away, with no propagation lag.
03Does this check DNS propagation from around the world?+
No — it does the opposite, on purpose. This monitor queries your zone's own authoritative nameservers directly, bypassing resolver caches, to answer "is my zone still serving the right answers?" To check whether a change has propagated to public resolvers, use our free DNS Checker instead.
04Which records can I monitor?+
Address records (A, AAAA, CNAME), mail records (MX), nameserver records (NS) and policy records (TXT, SPF, DMARC, CAA). @ and www are watched by default, plus up to 20 more names you add. It watches the names you choose — no zone transfer or wildcard sweep.
05Will constant checking overload my nameservers?+
No. A sweep is one query per watched record, plus a reachability query per nameserver — a few thousand a day in total, against servers built to answer millions. Answer time and the AA bit are read from queries the sweep already sends, so they cost nothing extra.
06How do you avoid false alarms?+
Three ways. A nameserver is only reported down after a second probe in a different location confirms it. Answer sets are sorted, so shuffled round-robin order never looks "changed". And TTL-only changes are informational — never paging. A change you made on purpose can be acknowledged in one click.
07Does it monitor DNSSEC?+
It records your DNSSEC state — signed or unsigned — but does not validate the chain of trust or judge it pass or fail. Signing a previously unsigned zone appears as a plain change event. If you need DNSSEC validation graded, this monitor isn't that tool.
08What happens after I fix a DNS problem?+
Uptimia re-checks automatically. Once every reachable server is back at baseline for three consecutive sweeps, the incident closes itself. A nameserver that comes back online clears immediately. You never click "resolve" or re-run anything.
09Can I monitor DNS for an IP address?+
No — a DNS monitor watches a domain's zone, so it needs a domain name; bare IPs are rejected. To watch a host by IP, use an uptime monitor with a ping or TCP-port check instead.
10Can I pause alerts during a DNS migration?+
Yes. Snooze change alerts for a 4-hour, 24-hour or 7-day window while you cut over. Changes keep recording — they just don't page until the window ends. Nameserver-health alerts are unaffected, so you'll still hear if a server goes dark.
11How do I get alerted when something changes?+
Through 12 channels — email, SMS (from your plan's allowance or your own Twilio number), Slack, WhatsApp, Telegram, Discord, PagerDuty, Microsoft Teams, Mattermost, Statuspage and custom webhooks — on the same contact list and escalation policies as every other Uptimia monitor. You get one incident per zone, escalating only for the worst thing happening — never a flood of separate alerts.
12Is DNS monitoring included in my plan, or a paid add-on?+
DNS monitoring starts with the paid plans — every paid plan includes it alongside uptime, SSL, domain and transaction monitoring, never as a paid add-on, and plans differ only in how many zones you can watch (from 1 on Basic up to 100). The free 30-day trial includes it in full (50 zones, no credit card); after the trial, DNS monitors pause until you're on a plan that includes them, while free-plan uptime monitoring keeps running.

Start monitoring your DNS today.

Enter a domain, keep the defaults — and be the first to know when your zone answers with anything you didn't set.

30-day free trial 50 DNS zones included No credit card EU-hosted, GDPR-ready
DNS monitoring sits beside your uptime, SSL, speed and heartbeat monitors — same contacts, groups and escalation policies.