Documentation

What we monitor

Six measurement families. Every one is an active check against live infrastructure — never a cached third-party feed.

CheckMeasuresCadence
DNSA, AAAA, NS and MX record sets, resolved through a probe-local recursive resolverCritical
DelegationAn iterative walk from the root: parent NS vs child NS, plus lame-server detectionCritical
DNSSECParent DS against child DNSKEY, and the RRSIGs over the DNSKEY RRset and apex SOACritical
TLSThe leaf certificate actually served, its chain, SANs, expiry and hostname validityStandard
HTTPStatus, redirect target and security-relevant response headersStandard
ReachabilityTCP reachability of the served endpointStandard

Critical checks run every 60 seconds on paid plans (30 seconds on Enterprise) and hourly on Free. Standard checks run every 5 minutes on paid plans.

Enrichment

Alongside the probe checks, ZoneInsight enriches what it observes:

  • Registration (RDAP) — registrar, registry, registration and expiry dates, status codes and the nameservers the registry has on file. Refreshed on a 12-hour cycle, and immediately when a domain is added.
  • Routing — origin ASN, announced prefix and RPKI validity for each observed address.
  • Certificate Transparency — certificates issued for your domains, including ones never served, so unexpected issuance is visible.

What is deliberately not a change

A check that times out, returns SERVFAIL, or otherwise cannot reach a verdict is recorded as inconclusive and never diffed as though records disappeared. Likewise, an address still witnessed by any other recent observation is not treated as removed — this is what keeps a rotating CDN address pool from generating a continuous stream of meaningless events.