Skip to content
Inspect My DNS

Delegation

Registry servers

delegation.registry-responded

Everything in this section compares what the registry has on file against what the domain's own nameservers say.

What this check measures

Every finding in this section is a comparison: what the registry has on file against what the domain's own nameservers say. That comparison only exists because the two were asked separately. A recursive resolver would answer both halves out of one merged cache entry and agree with itself, which is precisely the disagreement worth finding.

So the scan first has to locate the registry's nameservers for the TLD and get one of them to answer. This check records which one did. It is bookkeeping rather than a finding about your domain — but it is the bookkeeping every parent-side check depends on, and a report that quietly skipped it would be claiming a comparison it never made.

When it cannot be done, the result is unknown rather than a failure. A registry that rate-limited us, an anycast node that dropped the query and an outbound restriction on our own network are indistinguishable from here, and none of them is evidence about the domain. unknown is excluded from the score for exactly that reason.

How to fix it

Nothing, when it passes. When it does not, re-run the scan — registry rate limits are per-source and short-lived, and the parent-side checks fill in once one answers.

If it fails repeatedly for one TLD in particular, that registry is either unusually aggressive about rate limiting or is not reachable from this network. The child-side checks — everything measured against your own nameservers — are unaffected and still valid.

References

Run this check on a domain

Registry servers is one of 56 checks in every report, alongside delegation, mail authentication, TLS and registration.