> ## Documentation Index
> Fetch the complete documentation index at: https://docs.uptimeio.com/llms.txt
> Use this file to discover all available pages before exploring further.

# DNS Monitoring

> Check that your domain resolves to the records you expect

A DNS monitor resolves a domain and compares the answer with the values you expect. It catches DNS misconfiguration, failed propagation and unexpected record changes (including hijacking). It does not check whether the resolved addresses are reachable; pair it with an [HTTP](/monitors/http) or [Port](/monitors/port) monitor for that.

## When to use it

* Confirm a domain resolves to the right IP addresses
* Verify a DNS change has propagated
* Watch MX, TXT or NS records for unexpected changes
* Detect DNS server outages

## Create a DNS monitor

<Steps>
  <Step title="Enter the domain">
    Enter the **Domain Name**, a public domain such as `example.com`. Private and internal names, IP addresses in private ranges, and UptimeIO's own domains are not accepted.
  </Step>

  <Step title="Add record checks">
    In **DNS Configuration**, click **Add Record**. Each row has a **Record Type**, **Expected Values** and a **Match Mode**. UptimeIO looks up the current values and fills them in; click the refresh button on a row to fetch them again, or edit them yourself.
  </Step>

  <Step title="Optionally choose a DNS server">
    Under **Advanced Options**, leave **DNS Server** empty to use the default resolver, or enter a resolver IP address such as `8.8.8.8`.
  </Step>

  <Step title="Set interval and locations">
    In **How often we check**, choose the **Check Interval**. The shortest interval depends on your plan: 5 minutes on Free, 1 minute on Pro and Scale. DNS answers change slowly, so every 5 minutes is usually enough. Pro and Scale can choose probe locations; Free uses automatic selection.
  </Step>
</Steps>

### Settings

| Setting | What it does | Default / options |
| - | - | - |
| **Monitor Name** | Name shown in your dashboard | Generated from the domain, up to 80 characters |
| **Domain Name** | Domain to resolve | Required |
| **Record Type** | The DNS record to check. Each type can be added once per monitor | A, AAAA, CNAME, MX, TXT, NS |
| **Expected Values** | The values the record should have. Values are checked for the right format (for example an IPv4 address for A) | At least one per record |
| **Match Mode** | How resolved values are compared with the expected values | Match Any (default) or Match All |
| **DNS Server** | Resolver to query | Default resolver. Enter an IP address |
| **Check Interval** | Time between checks | 1 minute to 24 hours. Plan minimum applies |
| **Domain Expiry Monitoring** | Domain expiry warnings. See [Domain expiry monitoring](/monitors/http#domain-expiry-monitoring) | Off |

### Match modes

| Mode | The record passes when |
| - | - |
| Match All | **Every** expected value appears in the resolved values. |
| Match Any | **At least one** expected value appears in the resolved values. |

The monitor succeeds only when **all** record rows pass. A row also fails when no records of that type exist.

<Note>
  For MX records the comparison uses the mail server hostname only (for example `mail.example.com`), not the priority.
</Note>

### Example

* **Domain Name**: `example.com`
* **A Record**, **Expected Values** `93.184.216.34`, **Match All**
* **MX Record**, **Expected Values** `mail.example.com`, **Match Any**
* **DNS Server**: `8.8.8.8`

## Record types

| Type | Purpose | Example expected value |
| - | - | - |
| A | IPv4 address | `93.184.216.34` |
| AAAA | IPv6 address | `2606:2800:220:1:248:1893:25c8:1946` |
| CNAME | Alias | `target.example.net` |
| MX | Mail server | `mail.example.com` |
| TXT | Text records (SPF, verification) | `v=spf1 include:_spf.google.com ~all` |
| NS | Nameservers | `ns1.example.com` |

## DNS server choice

| DNS Server | When to use |
| - | - |
| Empty | Normal resolution as your users would see it |
| A public resolver (`8.8.8.8`, `1.1.1.1`) | Consistent results independent of the probe's resolver |
| Your authoritative nameserver IP | See changes as soon as you make them |

## Incidents

When a record check fails, UptimeIO records a DNS failure (for example no records found, or a value mismatch). An incident opens only after several probe locations confirm the failure (see [Understanding incidents](/essentials/understanding-incidents)). Connect an email, Slack or webhook channel so unexpected record changes reach you quickly.

## Best practices

* Monitor the records that matter: the apex A/AAAA, `www`, MX and any critical subdomains.
* If you use GeoDNS, answers differ by location; use **Match Any** rather than one fixed address.
* Before a planned change, lower the record's TTL a day ahead so the change propagates faster.

## Troubleshooting

<AccordionGroup>
  <Accordion title="No records / NXDOMAIN">
    The domain or record type does not exist. Check registration and nameserver configuration with `dig example.com`.
  </Accordion>

  <Accordion title="Unexpected values">
    The records changed, a CDN or load balancer returns different addresses, or (if unauthorized) the domain may have been tampered with. Query your authoritative nameserver directly: `dig @ns1.example.com example.com`.
  </Accordion>

  <Accordion title="Invalid DNS server">
    **DNS Server** must be an IP address, not a hostname.
  </Accordion>

  <Accordion title="Timeouts">
    Try a different resolver in **DNS Server**.
  </Accordion>

  <Accordion title="Results differ between locations">
    Propagation may be in progress, or the domain uses GeoDNS.
  </Accordion>
</AccordionGroup>

## Next steps

<CardGroup cols={2}>
  <Card title="HTTP Monitoring" icon="globe" href="/monitors/http">
    Monitor web services and APIs
  </Card>

  <Card title="Notifications" icon="bell" href="/notifications/overview">
    Configure alerts for DNS monitors
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.