Documentation
What we monitor
Six measurement families. Every one is an active check against live infrastructure — never a cached third-party feed.
| Check | Measures | Cadence |
|---|---|---|
| DNS | A, AAAA, NS and MX record sets, resolved through a probe-local recursive resolver | Critical |
| Delegation | An iterative walk from the root: parent NS vs child NS, plus lame-server detection | Critical |
| DNSSEC | Parent DS against child DNSKEY, and the RRSIGs over the DNSKEY RRset and apex SOA | Critical |
| TLS | The leaf certificate actually served, its chain, SANs, expiry and hostname validity | Standard |
| HTTP | Status, redirect target and security-relevant response headers | Standard |
| Reachability | TCP reachability of the served endpoint | Standard |
Critical checks run every 60 seconds on paid plans (30 seconds on Enterprise) and hourly on Free. Standard checks run every 5 minutes on paid plans.
Enrichment
Alongside the probe checks, ZoneInsight enriches what it observes:
- Registration (RDAP) — registrar, registry, registration and expiry dates, status codes and the nameservers the registry has on file. Refreshed on a 12-hour cycle, and immediately when a domain is added.
- Routing — origin ASN, announced prefix and RPKI validity for each observed address.
- Certificate Transparency — certificates issued for your domains, including ones never served, so unexpected issuance is visible.
What is deliberately not a change
A check that times out, returns SERVFAIL, or otherwise cannot reach a verdict is recorded as inconclusive and never diffed as though records disappeared. Likewise, an address still witnessed by any other recent observation is not treated as removed — this is what keeps a rotating CDN address pool from generating a continuous stream of meaningless events.