
Who it is for
Site owners, people setting up email for a domain, support staff and the curious: anyone who needs DNS answers without learning to read dig’s output. TTLs are written in seconds, minutes, hours or days, and response codes as words — “NXDOMAIN — no such name” rather than a bare status number.
How it works
The browser talks directly to two public DNS-over-HTTPS JSON endpoints, Google’s dns.google and Cloudflare’s cloudflare-dns.com. The script’s header explains why there are only two: Quad9’s JSON port was unreachable and AdGuard sends no CORS header, so these are the independent operators a browser can honestly use.
The quorum normalises both answer sets and compares them, printing that the operators agree or naming the difference. The chain walk asks for NS and DS records at each suffix from the root down, and the page is candid that this is the chain as a recursive resolver reports it, not a packet trace. Mailworthy reads MX, the SPF record, DMARC and six common DKIM selectors, then picks a verdict by fixed rules that treat SPF’s ending (-all or ~all) and DMARC’s policy separately.
What we tested
All times are UTC on 27 September 2026, measured against a copy of labs.llc build 537 served from our own machine, or against the public source the page itself calls.
- The page, locally200, 43,673 bytes; resolver.js is 399 lines.
- Both operators asked for wikipedia.org MXGoogle (0.035 s) and Cloudflare (0.044 s) returned the same two Wikimedia hosts in reverse order, with TTLs of 179 s and 300 s.
- Mail inputs for wikipedia.orgSPF ends ~all; DMARC is p=reject; all six DKIM selector probes came back NXDOMAIN.
- Delegation“org” has a DS record with the AD flag set; wikipedia.org has none.
By the page’s rules that SPF and DMARC pair reads: “Forgeries are rejected by DMARC, though SPF alone would let them limp through.” The six empty DKIM probes would be reported as not found, not as “no DKIM”, because selectors cannot be listed from outside. And since the quorum compares sorted sets, it reports the MX answers as agreeing while each side still shows its own cache age.
How it compares
We checked each alternative’s own pages on 27 September 2026 and describe only what we saw there. Each gets the pick below when it does the job better.
MXToolbox SuperTool
checked 27 Sep 2026An integrated DNS and email diagnostics tool: MX, SPF, DKIM, DMARC, BIMI, MTA-STS and TLSRPT lookups, blacklist checks, SMTP tests on port 25, HTTP, ping, traceroute and WHOIS, with a history of results.
Better at
- Much broader mail diagnostics: blacklists, live SMTP tests, BIMI, MTA-STS and TLSRPT.
- A DKIM lookup for the selector you name, not six guesses.
- PTR, ASN and WHOIS in the same place.
Where Resolver goes further
- The same question put to two operators, both answers shown, any disagreement named.
- One plain sentence about forged mail, with -all and ~all explained in words.
- Runs in your browser against public DoH endpoints, with no account and no history kept.
DNSViz
checked 27 Sep 2026An open-source tool that visualises the status of a DNS zone — above all its DNSSEC authentication chain and resolution path — and flags configuration problems.
Better at
- A real DNSSEC diagnosis; the labs walk shows only the nameservers and whether a DS exists at each cut.
- Open source.
Where Resolver goes further
- Everyday answers on the same page: eight record types with readable TTLs, the two-resolver quorum and a mail verdict.
Where it falls short
- Two resolvers only, so it cannot show global propagation the way multi-location checkers do.
- Eight record types have chips. PTR, SRV, DS/DNSKEY and HTTPS are in its type table but have no chip of their own.
- DKIM is probed with six fixed selectors; a domain that uses any other selector shows no DKIM even when it has one.
- No blacklist, SMTP or TLS checks, and no WHOIS or reverse-IP lookup.
- The chain walk cannot diagnose a broken DNSSEC signature.
Which one to pick
| If you need… | Pick |
|---|---|
| A domain’s records, in readable units | Resolverours |
| Whether two big public resolvers agree | Resolverours |
| A one-line answer on whether forged mail gets through | Resolverours |
| Blacklists, SMTP tests or a DKIM selector you know | MXToolbox SuperTool |
| Why DNSSEC validation is failing | DNSViz |
The fit
Best for
- Setting up a domain’s email and checking SPF and DMARC say what you meant
- Support staff explaining DNS to a customer
- A quick cross-check between Google and Cloudflare
Not for
- Deliverability trouble involving blacklists or SMTP
- DNSSEC troubleshooting
- Checking propagation around the world
Pick Resolver if you want a domain’s DNS and mail posture explained in sentences, checked by two operators.
Sources for this review
- resolver/assets/js/resolver.js in build 537 — header lines 1–24, endpoints at 38–48, RCODE and ttlWord() at 52–62, quorum at 146–180, walk() at 184–200, DKIM selectors at 259, mail rules at 272–273 and 336–352; resolver/index.html lines 449–456
- MXToolbox SuperTool and DNSViz, fetched on 27 September 2026 at about 20:04 UTC