svcbscan
HTTPS/SVCB & ECH record scanner.
Checks a domain's HTTPS DNS record against the spec and the rest of its DNS, then connects to verify that HTTP/3, Encrypted Client Hello and address hints really work as advertised. 31 checks per domain.
Open-source tools that check what DNS actually does — not what the records and resolvers claim. Each one measures, then shows you the evidence.
$ svcbscan -probe example.com record says: alpn="h2,h3" ech=… server does: h2 ok h3 rejected ech accepted
HTTPS/SVCB & ECH record scanner.
Checks a domain's HTTPS DNS record against the spec and the rest of its DNS, then connects to verify that HTTP/3, Encrypted Client Hello and address hints really work as advertised. 31 checks per domain.
Passive DNS sensor.
Collects dnstap from a resolver and keeps a deduplicated ledger of what resolved to what, with first-seen and last-seen times. Output follows the Passive DNS Common Output Format, with a bailiwick check to keep poisoned answers out.
DNS defense self-test.
Run it from inside a network to check whether its DNS controls actually stop resolver bypass, encrypted-DNS bypass, rebinding and tunneling. It emits labeled, one-way test patterns to a zone you control and reports which ones escaped.
All three are single Go binaries, Apache-2.0, and built to be run yourself. They share one idea: a DNS record or a resolver makes a promise, and the only way to know if it holds is to measure it and keep the receipt.