See all checks →
Domain & DNS

DNS monitoring that catches the change you didn't make.

Relvato records your domain's nameservers and key DNS records, you approve them, and every day after that it flags what changed — a new nameserver or mail server as a problem, anything else as a change to review. It also checks DNSSEC and that the domain resolves the same everywhere.

First run: approve the records once — every change after that is flagged.
Supported sitesNo plugin needed
WordPresssupportedAI-built appssupportedAny websitesupported
Add your URL and this check runs from the outside, the way a visitor sees your site.
What it checks
  • ✓Nameservers and mail servers match what you approved
  • ✓Addresses, CAA and SPF/DMARC records haven't drifted
  • ✓DNSSEC validates (when the domain is signed)
  • ✓Public resolvers and regions agree the domain resolves
Why it matters

A domain hijack starts with the nameservers: whoever controls them decides where your visitors and your email go, and the site can look normal from your office for days. The same records break by accident too — a DNS migration that forgets the mail servers, a DNSSEC key that wasn't re-signed. Both are cheap to catch the day they happen and expensive a week later.

How it works
  • The first check captures your nameservers, addresses, mail servers, CAA and SPF/DMARC records; you approve them as the baseline in one click.
  • Each day it compares the live records with the baseline: a nameserver or mail-server change is a problem, other changes are flagged for review, and one click accepts a change you made.
  • It asks Cloudflare, Google and NextDNS the same questions, and Google's resolver what visitors in five regions get — so a broken DNSSEC chain or a region that can't resolve the site shows up, while normal CDN differences don't.
Questions, answered
Is this DNS propagation monitoring?

It checks whether the answer is the same everywhere — the public resolvers and five regions — which is what tells you a change has landed or a region is broken. It doesn't time how long a change takes to spread.

My site is behind Cloudflare. Will address changes flood me?

No. Behind a CDN the check follows the CNAME rather than the rotating addresses, and it doesn't compare addresses between resolvers or regions, since those legitimately differ.

What do I do when it flags a change I made?

Open the run and click “Accept current DNS” — the records become the new baseline and only later changes are flagged.

Related checks
DNS health

Put this check on autopilot.

Free forever on one site — every check, 100 runs a month. No card, no sales call.