read-only · beginner
Diagnose an NXDOMAIN response
Separate a truly absent name from NODATA, negative caching, delegation trouble, and wrong-scope queries before changing DNS.
ClueDNS knowledge path
Scope the failure, gather read-only evidence, identify the responsible owner, then change only what the evidence supports.
read-only · beginner
Separate a truly absent name from NODATA, negative caching, delegation trouble, and wrong-scope queries before changing DNS.
read-only · intermediate
Separate DNSSEC validation, unreachable authority, malformed data, resolver policy, and cached failure without guessing from SERVFAIL alone.
read-only · intermediate
Compare authority, cache lifetime, DNS view, stale service, validation, and resolver policy before declaring an answer globally wrong.
availability-impacting · intermediate
Trace parent delegation, child-zone data, DNSSEC, cached authority, and web layers with explicit stop and rollback conditions.
availability-impacting · intermediate
Separate parent delegation, child-apex NS, nameserver addresses, and required glue before changing either DNS control plane.
availability-impacting · advanced
Trace parent DS, child DNSKEY, signatures, denial proofs, time, and validator evidence before attempting DNSSEC recovery.
read-only · intermediate
Separate web DNS from MX routing, exchanger addresses, SMTP, sender authentication, mailboxes, filtering, and delivery evidence.
read-only · intermediate
Hand off from a verified DNS answer to hostname, TLS, redirect, HTTP, CDN, origin, browser, and search-migration evidence.