Per monitor
Ignore noisy record types
Leave record types that change by design out of the comparison entirely.
DNS changes outside the deploy
See the DNS change before your client reports a broken site or missing mail. Oh Dear records the DNS state of the hostname you monitor, rechecks it against every authoritative nameserver it discovers, and alerts you when a record changes or a lookup starts failing.
10-day free trial · No credit card required · Every feature included
Previous
Current
Illustrative records, values and timestamps
A lookup is only a snapshot
dig, nslookup and a browser-based DNS checker answer one question: what does
this hostname resolve to right now? None of them shows which record a client, registrar, host or
previous provider changed while you were elsewhere.
A DNS checker run by hand
DNS monitoring with Oh Dear
Need the current answer once, without a monitor? Run a one-off DNS lookup.
Two different searches
Both are called DNS monitoring, and they are bought by different people for different reasons. Oh Dear does one of them.
What Oh Dear does
A different job
One answer out of three
A migration updates the record, most nameservers pick it up, one keeps the old answer. Visitors get either, and a manual lookup returns whichever replied first.
Authoritative comparison
Oh Dear queries every authoritative nameserver it discovers for the monitored hostname. When the answers disagree, it names the nameserver, shows the previous and current value, and summarises the difference.
+all. Findings like this are shown for review only: they do not fail the check and they do not send a notification.
The repair loop stays the same each time: confirm whether the change was planned, check the provider that owns the zone, use the previous state to guide the repair, then watch the next checks until the authoritative nameservers agree again. Oh Dear observes the DNS state from outside; it does not manage your provider and cannot prevent a registrar compromise.
Oh Dear detected an issue that our other uptime monitor did not!
Casey Sprague, CTO at thera-LINK
A record change is not an outage yet. That is the point of watching it.
Noise control
Some records are supposed to move. Alerting on every rewrite is how a team learns to ignore the channel.
Per monitor
Leave record types that change by design out of the comparison entirely.
Per notification
Keep the blocking failures on while muting DNS records changed.
Temporary
Mute the check for the length of a migration, then let it come back on its own.
When Cloudflare nameservers are detected on a hostname, Oh Dear automatically ignores A and AAAA changes when deciding whether records changed or nameservers agree.
Operational ownership
A record change can belong to the domain owner, the mail admin, or one client's account manager. Give each monitored hostname its own responsible people and its DNS alerts arrive on the channels they already use.
One client's zone should not alert the whole team. Route per site, not per account.
No feature tiers
DNS monitoring is included with Oh Dear's website-health checks on every plan. Choose by the number of sites you monitor, not by which checks you need.
Try DNS monitoring alongside uptime, certificate, domain and the rest of the website-health toolkit.
10-day free trial. No credit card.
Before the first check
What Oh Dear checks, how often, and where DNS monitoring ends.
DNS monitoring repeatedly checks the DNS records published for a hostname and reports when they change or stop resolving. Oh Dear queries every authoritative nameserver it discovers, compares the answers, and keeps the history.
Every two hours by default, for each monitored hostname, and you can slow that down per site. A change made just after a check surfaces at the next scheduled one, so this is a change record rather than an instant alarm.
Yes. The DNS change history shows the previous and current values with timestamps, the nameservers that answered, and a summary of what differed. Newest results appear first.
DNS record monitoring asks whether the authoritative records changed, disappeared, disagree, or are malformed. DNS server monitoring asks how a DNS service performs: query latency, cache behaviour, daemon health. Oh Dear does the first.
Yes. Oh Dear discovers the authoritative nameservers for the monitored hostname, queries each one, and reports which is unreachable or out of sync with the others.
Results can include A, AAAA, CNAME, MX, NS, TXT, SOA, CAA and other records discovered on the exact hostname you monitor. Subdomains are added as separate monitors, and a hidden CNAME can be added by hand in the check settings.
Yes. Oh Dear flags common mistakes such as an SPF record ending in +all, two SPF records on one name, a DMARC record on the wrong name, an MX or NS record pointing at an IP address, a CNAME on the apex, or a malformed CAA record. These findings are advisory: they sit next to the record for review and do not fail the check.
Yes. Leave selected record types out of the comparison, silence only the DNS records changed notification, or snooze the check while planned work is happening. Some records are supposed to move, and alerting on every rewrite trains a team to ignore the channel.
It shows you the warning sign. An unexpected A, NS or MX change is one of the earliest indications of hijacking or a subdomain takeover, but Oh Dear reports the observable change. It cannot prove intent, and it cannot prevent a registrar compromise.
No. Oh Dear reads the authoritative DNS state from outside, the same way a resolver does, so there is no provider integration to set up and no API credentials to hand over. It also means Oh Dear never writes to your zone.
You can monitor DNS free during Oh Dear's 10-day trial. Free lookup tools show your records when you remember to look; catching an unplanned change needs a schedule and an alert.
Scheduled checks against every authoritative nameserver, a readable change history, and blocking failures kept apart from advisory warnings. It should route each alert to the owner and sit beside neighbouring checks such as the served certificate and blocklist reputation.
Yes. Monitor every client domain from one account, organise sites with tags, and route DNS-change alerts per domain so one client's zone does not alert the whole team.
Get started
Stop relying on memory and single-moment lookups. Keep DNS changes and nameserver evidence where your team can see them.