DNS monitoring that catches a hijacked record.
A wrong DNS record doesn't take your site down — it quietly sends your visitors and email somewhere else. Uptimia watches every answer your nameservers give and alerts you within minutes of a change you didn't make.
Watched Records
the zone as both nameservers serve it right nowNameserver Health
queried directly · AA bit checkedWhat the sweep asks
dig · 52 queries every 5 minA mail record changes — and it wasn't you
Nothing goes down. Every nameserver keeps answering — the answer is just wrong, and your email starts going to the wrong server. Here's how that plays out with Uptimia watching.
What's watched in your zone
The records your zone serves and the health of the nameservers serving them — read straight from your authoritative servers, no resolver cache in between.
Changes, nameservers and delegation
Detect DNS hijacking and silent edits
Uptimia keeps a per-record baseline of what your zone should answer and diffs the live authoritative answer against it every sweep. A repointed A record or swapped SPF surfaces even while every server stays green.
- A saved baseline per record — any real, non-TTL difference opens a change episode
- Round-robin safe — answer sets are sorted, so shuffled order never false-alarms
- Within 5 minutes — a change is caught on the next sweep, at most five minutes away
baseline
Down only when two probes agree
A flaky link between one probe and one server should never wake you at 3 a.m. When the primary probe sees a nameserver unreachable, a second probe in a different location re-checks it before the incident opens.
- Primary + confirm probe — a down server is re-checked from a second location first
- UDP and TCP reachability, answer time and the AA bit checked on every server
- SOA serials compared across servers — drift beyond your window opens a trouble episode
Catch a lame delegation
Every 22 hours, Uptimia compares the registry's delegation against what your zone actually answers, and probes each delegated server for a real authoritative reply. A nameserver the registrar still lists but that no longer answers is exactly the problem you never see coming.
- Parent vs child NS — the registry's delegation compared to your zone's own answer
- Lame-server probe — each delegated server is checked for an authoritative answer
- DNSSEC state, recorded — signed or unsigned is shown alongside, never judged for you
.io delegates 4 servers chad · lia · ns3 · ns4
zone answers the same 4 sets match — no drift
chad ✓ lia ✓ ns3 ✓
ns4 → REFUSED · lame
One incident per zone, self-closing
When several records or servers misbehave at once, you get one zone incident, escalating only for the worst thing actually happening. Once the zone is back at baseline for enough consecutive sweeps, the incident verifies and closes on its own.
- One incident, not a flood — alertable changes and health episodes roll into a single incident
- Verified restore — a change is "back" only after every reachable server agrees across consecutive sweeps
- A dead nameserver that returns clears immediately — it was already double-confirmed
incident
You decide what pages you
Address, mail and nameserver records page as critical by default, policy records as trouble — every group is yours to toggle and re-rank.
Addresses, mail and NS records default to critical; policy records (SPF, DMARC, CAA) to trouble. TTL-only changes stay info — never paging.
Acknowledge a planned change and the new answer becomes the baseline. Mark rotating records "dynamic" and Uptimia watches that they exist, not what they say — so CDN and GeoDNS pools stop crying wolf.
Silence change alerts for 4 hours, 24 hours or 7 days. Changes keep recording — they just stop paging.
How DNS monitoring works
One monitor watches one zone — nothing to install, checks run straight against your authoritative nameservers.
Enter your domain
Uptimia discovers your nameservers, watches @ and www by default, and snapshots today's answers as the baseline.
Tune what pages you
Keep the defaults or adjust severities, add names, mark rotating CDN pools dynamic. Alerts use your existing channels.
Get alerted when the answer is wrong
Each sweep reads your authoritative answers, diffs them against the baseline, and checks nameserver health. Anything alertable opens one zone incident.
Baseline the zone once.Hear about every answer that changes.
Every zone, every sweep, every alert channel — free for 30 days, and none of it is a paid add-on.
What is DNS monitoring?
DNS monitoring is an automated service that continuously queries your domain's own authoritative nameservers and compares the answers against a known-good baseline. It alerts you when a record changes unexpectedly, a nameserver stops answering, or your delegation drifts — before the problem reaches your customers.
How does DNS monitoring work?
Each sweep diffs every watched record against its saved baseline and checks each nameserver's reachability and SOA serial. A real difference opens a change episode; a confirmed-unreachable server opens a health episode.
Authoritative answers, not propagation
Our free DNS Checker asks resolvers in 14 countries "has my change propagated?" This monitor does the opposite — it reads your own servers to answer "is my zone serving the right answers?"
What a bad change breaks
Uptimia groups records so alerts match the blast radius: address, mail and NS default to critical, policy to trouble, TTL-only changes to info.
Free tool: check your DNS propagation →| Record group | Records watched | Default alert | A bad change means |
|---|---|---|---|
| Addresses | A · AAAA · CNAME | Critical | Traffic sent to the wrong server |
| MX | Critical | Email silently rerouted or dropped | |
| Nameservers | NS | Critical | Your whole zone can be taken over |
| Policy | TXT · SPF · DMARC · CAA | Trouble | Spoofed mail or rogue certificates |
| TTL only | any record's TTL | Info · never pages | Caching timing only — nothing served changed |
DNS monitoring FAQ
01What is DNS monitoring?+
02How often does Uptimia check my DNS?+
03Does this check DNS propagation from around the world?+
04Which records can I monitor?+
05Will constant checking overload my nameservers?+
06How do you avoid false alarms?+
07Does it monitor DNSSEC?+
08What happens after I fix a DNS problem?+
09Can I monitor DNS for an IP address?+
10Can I pause alerts during a DNS migration?+
11How do I get alerted when something changes?+
12Is DNS monitoring included in my plan, or a paid add-on?+
Start monitoring your DNS today.
Enter a domain, keep the defaults — and be the first to know when your zone answers with anything you didn't set.