Skip to the content
BEST FOReriks.best

For when you need to: check a domain’s DNS — and whether its email can be forged

Resolver: best for DNS and mail checks in plain words

Resolver is a dig desk for people. Type a domain and it looks up eight record types, asks two independent resolvers the same question and lays their answers side by side, draws the delegation from the root, and — in its Mailworthy check — says in one sentence what happens to a forged email claiming that domain.

The Resolver page on labs.llc: the headline “dig, made humane.”, paragraphs on the delegation chain, the two-resolver comparison and the Mailworthy verdict, and buttons to ask a name, check a domain’s mail or read the method.
Resolver as served by labs.llc build 537, captured from our local copy of that build.

Who it is for

Site owners, people setting up email for a domain, support staff and the curious: anyone who needs DNS answers without learning to read dig’s output. TTLs are written in seconds, minutes, hours or days, and response codes as words — “NXDOMAIN — no such name” rather than a bare status number.

How it works

The browser talks directly to two public DNS-over-HTTPS JSON endpoints, Google’s dns.google and Cloudflare’s cloudflare-dns.com. The script’s header explains why there are only two: Quad9’s JSON port was unreachable and AdGuard sends no CORS header, so these are the independent operators a browser can honestly use.

The quorum normalises both answer sets and compares them, printing that the operators agree or naming the difference. The chain walk asks for NS and DS records at each suffix from the root down, and the page is candid that this is the chain as a recursive resolver reports it, not a packet trace. Mailworthy reads MX, the SPF record, DMARC and six common DKIM selectors, then picks a verdict by fixed rules that treat SPF’s ending (-all or ~all) and DMARC’s policy separately.

What we tested

All times are UTC on 27 September 2026, measured against a copy of labs.llc build 537 served from our own machine, or against the public source the page itself calls.

  1. The page, locally200, 43,673 bytes; resolver.js is 399 lines.
  2. Both operators asked for wikipedia.org MXGoogle (0.035 s) and Cloudflare (0.044 s) returned the same two Wikimedia hosts in reverse order, with TTLs of 179 s and 300 s.
  3. Mail inputs for wikipedia.orgSPF ends ~all; DMARC is p=reject; all six DKIM selector probes came back NXDOMAIN.
  4. Delegation“org” has a DS record with the AD flag set; wikipedia.org has none.

By the page’s rules that SPF and DMARC pair reads: “Forgeries are rejected by DMARC, though SPF alone would let them limp through.” The six empty DKIM probes would be reported as not found, not as “no DKIM”, because selectors cannot be listed from outside. And since the quorum compares sorted sets, it reports the MX answers as agreeing while each side still shows its own cache age.

How it compares

We checked each alternative’s own pages on 27 September 2026 and describe only what we saw there. Each gets the pick below when it does the job better.

MXToolbox SuperTool

checked 27 Sep 2026

An integrated DNS and email diagnostics tool: MX, SPF, DKIM, DMARC, BIMI, MTA-STS and TLSRPT lookups, blacklist checks, SMTP tests on port 25, HTTP, ping, traceroute and WHOIS, with a history of results.

Better at

  • Much broader mail diagnostics: blacklists, live SMTP tests, BIMI, MTA-STS and TLSRPT.
  • A DKIM lookup for the selector you name, not six guesses.
  • PTR, ASN and WHOIS in the same place.

Where Resolver goes further

  • The same question put to two operators, both answers shown, any disagreement named.
  • One plain sentence about forged mail, with -all and ~all explained in words.
  • Runs in your browser against public DoH endpoints, with no account and no history kept.

DNSViz

checked 27 Sep 2026

An open-source tool that visualises the status of a DNS zone — above all its DNSSEC authentication chain and resolution path — and flags configuration problems.

Better at

  • A real DNSSEC diagnosis; the labs walk shows only the nameservers and whether a DS exists at each cut.
  • Open source.

Where Resolver goes further

  • Everyday answers on the same page: eight record types with readable TTLs, the two-resolver quorum and a mail verdict.

Where it falls short

  1. Two resolvers only, so it cannot show global propagation the way multi-location checkers do.
  2. Eight record types have chips. PTR, SRV, DS/DNSKEY and HTTPS are in its type table but have no chip of their own.
  3. DKIM is probed with six fixed selectors; a domain that uses any other selector shows no DKIM even when it has one.
  4. No blacklist, SMTP or TLS checks, and no WHOIS or reverse-IP lookup.
  5. The chain walk cannot diagnose a broken DNSSEC signature.

Which one to pick

Match the need to the tool. Rows marked “ours” point to labs.llc.
If you need…Pick
A domain’s records, in readable unitsResolverours
Whether two big public resolvers agreeResolverours
A one-line answer on whether forged mail gets throughResolverours
Blacklists, SMTP tests or a DKIM selector you knowMXToolbox SuperTool
Why DNSSEC validation is failingDNSViz

The fit

Best for

  • Setting up a domain’s email and checking SPF and DMARC say what you meant
  • Support staff explaining DNS to a customer
  • A quick cross-check between Google and Cloudflare

Not for

  • Deliverability trouble involving blacklists or SMTP
  • DNSSEC troubleshooting
  • Checking propagation around the world

Pick Resolver if you want a domain’s DNS and mail posture explained in sentences, checked by two operators.

Try Resolver on labs.llc

Sources for this review

  • resolver/assets/js/resolver.js in build 537 — header lines 1–24, endpoints at 38–48, RCODE and ttlWord() at 52–62, quorum at 146–180, walk() at 184–200, DKIM selectors at 259, mail rules at 272–273 and 336–352; resolver/index.html lines 449–456
  • MXToolbox SuperTool and DNSViz, fetched on 27 September 2026 at about 20:04 UTC