dnsproof.net

Ground truth about DNS.

Open-source tools that check what DNS actually does — not what the records and resolvers claim. Each one measures, then shows you the evidence.

$ svcbscan -probe example.com
  record says:  alpn="h2,h3"  ech=…
  server does:  h2 ok   h3 rejected   ech accepted

svcbscan

HTTPS/SVCB & ECH record scanner.

Checks a domain's HTTPS DNS record against the spec and the rest of its DNS, then connects to verify that HTTP/3, Encrypted Client Hello and address hints really work as advertised. 31 checks per domain.

dnsledger

Passive DNS sensor.

Collects dnstap from a resolver and keeps a deduplicated ledger of what resolved to what, with first-seen and last-seen times. Output follows the Passive DNS Common Output Format, with a bailiwick check to keep poisoned answers out.

canarydns

DNS defense self-test.

Run it from inside a network to check whether its DNS controls actually stop resolver bypass, encrypted-DNS bypass, rebinding and tunneling. It emits labeled, one-way test patterns to a zone you control and reports which ones escaped.

All three are single Go binaries, Apache-2.0, and built to be run yourself. They share one idea: a DNS record or a resolver makes a promise, and the only way to know if it holds is to measure it and keep the receipt.