SOA Consistency Checker: compare zone serials across nameservers

Nameservers can disagree after a DNS change. Enter a domain to compare their SOA records, including the zone serial and timing settings. This helps find a server that may be behind, without treating matching serials as proof that every DNS record is identical.

How the comparison works

Type a domain or hostname and run the check. We find the authoritative zone it belongs to, look up every nameserver's address, and ask each address directly for its SOA record. When a server answers the same way over IPv4 and IPv6, we keep those together in one row. When a server hands back a different serial or a different timing value, it gets its own row so the odd one out stands out.

Each nameserver is queried independently. A failed address remains a failed check, not an extra version of the zone.

What the serial tells you

The serial is the zone's version counter. Different serials can indicate a transfer still in progress or a server that hasn't received a change. Matching serials are useful evidence of agreement, but this checker doesn't compare every record in the zone. To verify the record you edited, use the DNS change checker.

One catch: a smaller number is not always the older one. Serials are counters that roll back to zero after they reach 4,294,967,295, so a server that just wrapped can show a low number while actually being newest. To handle that, this page compares serials with DNS serial arithmetic rather than treating them as plain numbers.

What each SOA value means

FieldMeaning
PrimaryThe primary named in the SOA record. It does not reveal the provider's complete replication topology.
MailboxThe contact for the zone, written as a DNS name. The first unescaped dot separates the mailbox name from its domain. For example, admin.example.com represents [email protected]; escaped dots need care.
RefreshHow often a secondary checks with the primary to see if anything changed.
RetryHow long a secondary waits before trying again after a failed check.
ExpireHow long a secondary keeps serving its copy while it cannot reach the primary at all, before it gives up.
Negative cacheThe starting cache lifetime for a negative answer, such as a nonexistent name or missing record type. It is the lower of the SOA TTL and the MINIMUM value.

When a mismatch is worth worrying about

A brief difference is normal. It usually just means a change is still spreading from the primary to the secondaries and has not landed everywhere yet. A persistent difference deserves investigation, especially when it lasts beyond the expected transfer schedule. The timing fields alone cannot prove when a provider's replication will finish. If one is stuck, check whether it can reach the primary, whether zone transfers are allowed to it, and whether it is still meant to serve the zone at all. There is no single correct timing value, so this tool just shows you what differs instead of handing out a made-up grade.

DNS serial arithmetic defines wraparound comparisons, including cases where ordering is undefined. Negative caching explains how the SOA contributes to cached empty answers. The check runs from stack127's server and cannot inspect private transfer logs or your provider's internal state.