check_authoritative_dns_infra
Measure authoritative DNS infrastructure for a hostname over DNS-over-TCP/53: TCP reachability, AA flag, recursion exposure, SOA serial consistency, DNSKEY/RRSIG presence, and IPv4/IPv6 parity.
Instructions
Measure authoritative DNS infrastructure posture for a hostname over direct DNS-over-TCP/53 from a single vantage: TCP/53 reachability, the authoritative AA flag, recursion exposure, SOA serial consistency across nameservers, DNSKEY/RRSIG presence (not validation), IPv4/IPv6 answer parity, and unsupported-query handling — plus, for authenticated callers, a zone-transfer refusal test (first response only, no zone data retrieved) and CHAOS version.bind/id.server disclosure. Reports UDP/53 reachability, amplification, EDNS large-response/truncation, DNS cookies/RRL, BGP origin, RPKI, route-leak signals, anycast diversity, vantage latency, and RIR/RDAP as inconclusive — none of those are measured. Uses BV_INFRA_PROBE when available.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| domain | Yes | Domain to check (e.g., example.com) | |
| format | No | Output verbosity. Auto-detected if omitted. | |
| force_refresh | No | Bypass cache and run a fresh check. Useful after DNS changes. |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| score | Yes | ||
| passed | Yes | ||
| partial | No | ||
| category | Yes | ||
| findings | Yes | ||
| checkStatus | No | ||
| verdictWithheld | No |