DNS monitoring10 record types

DNS monitoring
for every record.

DNS monitoring for A, MX, TXT and seven more record types, checked every 30 seconds against the answer you expect.

DNS monitors are included from the Essentials plan.

Trusted by teams that put uptime first.

Read customer stories

Six ways DNS breaks. Each one fails a check.

DNS monitoring queries your records on a schedule and treats a missing record, a wrong answer or a silent nameserver as downtime. It catches what an HTTP check misses: the servers are fine, but nobody can find them.

  • A example.com · NXDOMAINENOTFOUND · alert

    The record someone deleted

    A zone cleanup, a move to a new DNS provider, an infrastructure change that dropped one line. The servers stay up and the name stops resolving. The next check fails.

    DNS monitoring docs
  • A example.com → 203.0.113.9expected 192.0.2.1 · no match

    Resolving, but to the wrong place

    A hijacked registrar account or a well-meant edit points the name somewhere else. Set the answer you expect, and any other value counts as downtime.

    Expected answers
  • MX example.com · mail.example.com missingMX monitor · alert

    Mail broke, the website didn’t

    MX records and SPF or DKIM entries live in DNS, so a website check never sees them. Watch MX and TXT records on their own, with the entry that must be there.

    Record types
  • ns2.example.net · old zonenameserver check · no match

    A change that only half propagated

    After a migration, one nameserver can keep serving the old zone. Query each one directly with the same expected answer and the one that lags fails on its own.

    Custom nameservers
  • A example.com · no answer in 10 stiming out on DNS resolution

    The DNS provider is the outage

    When your DNS host has an incident, every service behind it goes dark at once. Checks from up to 18 regions show whether it’s one region or everywhere.

    Monitoring regions
  • example.io · registration expiredrecords stop resolving

    The domain nobody renewed

    An expired registration takes its DNS down with it, and the DNS monitor fails the moment it happens. Domain expiry alerts warn you up to 90 days before.

    Domain expiry alerts

Ten record types. From the website to the mail server.

Each DNS monitor checks one record type on one hostname. The value on the right is what an expected answer is matched against.

  • A record

    192.0.2.1

    The IPv4 address a hostname points to. The default, and the one that takes a site offline.

  • AAAA record

    2001:db8::1

    The IPv6 address. Worth its own monitor when IPv6 visitors take a different path.

  • CNAME record

    example.cdn.net

    An alias to another hostname, such as a CDN, a load balancer or a hosted service.

  • MX record

    mail.example.com

    The mail servers. Matched on the mail host, whatever its priority.

  • NS record

    ns1.example.net

    The authoritative nameservers. Catches a delegation moved somewhere you didn’t move it.

  • TXT record

    include:_spf.example.net

    SPF, DKIM, DMARC and domain verification entries. One entry can be checked among many.

  • SOA record

    ns1.example.net

    The zone’s start of authority. Matched on its primary nameserver.

  • SRV record

    sip.example.com

    Service locations for SIP, XMPP and others. Matched on the target host.

  • CAA record

    letsencrypt.org

    Which certificate authorities may issue certificates for the domain.

  • PTR record

    mail.example.com

    Reverse DNS, the name behind an IP address. Mail servers are judged on it.

To watch several record types on the same domain, create one monitor per type: A for the website, MX for mail, TXT for SPF. Each has its own expected answer, regions and alerts.

Check the answer, not just a reply. On the nameserver you choose.

A record that resolves to the wrong address still answers. The expected answer is what turns a DNS lookup into a check of your own configuration.

  1. 1

    Set the answer you expect

    The check passes while one record contains it, ignoring case. Leave it empty and any answer counts. MX and SRV records are matched on their host, CAA on its value.

  2. 2

    Ask the nameserver that matters

    By default each region queries through its own resolver, like a visitor would. Name a nameserver, by IP or hostname, to check your authoritative servers directly or a public resolver after a change.

  3. 3

    See what every region got

    Each check keeps the records returned, the resolution time and the error, such as NXDOMAIN or SERVFAIL, so you can tell a deleted record from a slow nameserver.

DNS check · example.comResolved
Record Type
A
Nameserver
Default resolver
Location
Frankfurt, Germany (FRA)
Response Time
11 ms
Expected Answer
Match
DNS Records
  • 192.0.2.1

The expected answer is 192.0.2.1. The record still holds it, so the check passes. Delete the record or point it elsewhere and the next check fails.

A wrong answer is an outage. It pages like one.

DNS monitors share the alerting of every other monitor: the same channels, alert delays, escalation policies and on-call schedules, and the same status page your users read.

  1. ResolvedA · AAAA · MX · TXT · …

    The record answers, and holds the expected value if you set one. Every check records the answer and how long the resolution took.

  2. FailedNXDOMAIN · SERVFAIL · no match

    No record, an error from the nameserver, or no record holding the expected answer. The incident reads: example.com failing A DNS resolution.

  3. Timing outno answer · 10 s by default

    The nameserver doesn’t answer within the monitor’s timeout. The incident says example.com is timing out on DNS resolution.

  4. Recoveredincident resolved · recovery sent

    The right answer is back in every region. The incident resolves and a recovery goes out on the same channels.

Where your team works.Through your on-call when it matters.

A failed DNS check goes to the channels you pick, and climbs your escalation policy until someone acknowledges it.

  • Slack
  • Microsoft Teams
  • Google Chat
  • PagerDuty
  • Opsgenie
  • Jira Service Management
  • Discord
  • Telegram
  • Mobile app
  • Email
  • SMS
  • Phone call
  • Webhooks

DNS checks as code. From the API or your AI agent.

  1. 1

    Create them from the API

    Set protocol to dns, then dns_record_type, and optionally dns_expected_answer and dns_nameserver. The same fields update an existing monitor.

  2. 2

    Or ask your AI agent

    The MCP server takes the same fields, so Claude, Cursor or another agent can add a DNS monitor for every domain you launch.

  3. 3

    Pair it with an HTTP check

    When both fail together, the problem is the name. When only HTTP fails, it’s the server. Two monitors on the same domain tell you where to look first.

POST /v1/monitorsbash
curl -X POST https://api.hyperping.io/v1/monitors \
  -H "Authorization: Bearer $API_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "name": "Mail DNS",
    "url": "example.com",
    "protocol": "dns",
    "dns_record_type": "MX",
    "dns_expected_answer": "mail.example.com",
    "dns_nameserver": "ns1.example.net"
  }'

The domain and its certificate. Watched on the SSL monitoring page.

A DNS monitor fails once a registration has lapsed. Domain expiry alerts read the end date from the registry and remind you up to 90 days before, and SSL monitoring checks the certificate every HTTPS monitor serves.

What teams say about Hyperping.

Guillermo Rauch
CEO, Vercel
@hyperping is really amazing
Fabrice Gregoire
Site Reliability Engineer, Alma
Hyperping’s reputation in our company is that it’s more reactive than Datadog. We usually get notifications from Hyperping before Datadog.
Pierre Renaudin
CTO, Slite
We picked Hyperping to bring a high quality incidents and status reporting dashboard to our users.
Moritz Dausinger
CEO & Founder, Refiner
We have the real-time alerts from Hyperping telling us if the app is down. These are sometimes arriving even before AWS notices or notifies us.
Gary Gaspar
CEO & Founder, Marker.io
We couldn’t imagine running our SaaS business without Hyperping now.
Jakob Bo Storjohann
CEO, Ideanote
Hyperping nails all aspects: from smooth setup to peace of mind and attentive customer service.

You learn your site is down from a customer’s support ticket.

Uptime, status pages and on-call.One platform. Know before your customers do.

Uptime monitoring

Catch downtime the moment it happens, from multiple regions, before your customers notice.

Server monitoring

A lightweight agent tracks CPU, memory and disk, so you spot trouble before it turns into downtime.

Browser checks / E2E

Playwright tests that catch broken sign-ins and checkouts before your customers do.

Cron job monitoring

Get alerted when a backup or scheduled job silently fails to run, not days later.

api.acme.com is down. HTTP 503 from Paris, confirmed from Frankfurt and N. Virginia.9:42 AM
Incident published on status.acme.com. 1,240 subscribers notified by email.9:43 AM
api.acme.com is back up. Downtime 4 min 12 s, incident resolved automatically.9:46 AM
View incident

Notification channels

Alerts reach the right person on Slack, Teams, SMS or a phone call, whichever wakes them up.

SSL monitoring

Keep certificates in check. Get alerted before they expire, so your customers always connect securely.

On-call calendar

Plan rotations, share the load, and see who’s on call. Every incident reaches the right person, at the right time.

Three tools. One better bill.Monitoring, status pages, and on-call. Together.

USD · Monthly billing for every plan

The tool mix

Three subscriptions to keep it all running.

Example stack
  • Pingdom100 uptime + 20 advanced checks
    $149/mo
  • StatuspagePublic Startup + private Growth
    $348/mo
  • PagerDutyProfessional · 10 users × $25
    $250/mo
Combined cost

$747/month

$8,964 over 12 months

Everything connected, from the first check.

Business
  • 1,000 monitors
  • 10 status pages
  • 20 team members
  • On-call & escalations
  • 20-second checks
  • Priority support
One platform. One subscription.

$299/month

$3,588 over 12 months
60% less

Save $5,376 a year with this mix.

Explore pricing
Pricing sources & assumptions

Reviewed . All amounts are USD; local currency prices may differ.

  • Pingdom Synthetic Monitoring: $149/month for 100 uptime checks, 20 advanced checks and 350 SMS credits. USD rate from our August 17, 2026 review; the live calculator served EUR during this check, so the USD rate was not independently reverified today.
  • Statuspage: one public Startup page ($99/month, 1,000 subscribers, 10 team members) and one private Growth page ($249/month, 300 authenticated subscribers, 15 team members).
  • PagerDuty Professional: $25/user/month on monthly billing, for 10 users. Its $21 rate requires annual billing.
  • Hyperping Business: $299/month on monthly billing. The advertised $249/month is a rounded annual equivalent of $2,990/year and is not used in this comparison.

This is one example of a three-tool stack, not the cheapest possible setup or a feature-for-feature match. Pingdom and PagerDuty also include status-page features; a separate Statuspage subscription may not be needed by every team. Usage charges and paid connectors are not included. Annual totals are 12 monthly payments, not annual subscription quotes.

Questions about DNS monitoring.

What is DNS monitoring?

DNS monitoring queries your DNS records on a schedule and alerts you when a record stops resolving, resolves to the wrong value or stops answering in time. A one-off lookup tells you what a resolver returns now; a monitor repeats it from several regions and pages someone when the answer changes. See DNS monitoring in the docs.

Why is DNS monitoring important?

Because DNS fails while everything else looks healthy. Your servers stay up and HTTP checks can keep passing from a resolver that cached the old answer, yet visitors on another resolver can’t reach you, and mail can bounce while the website works. A DNS monitor checks the records themselves, so those failures page you like any outage.

How do I monitor DNS changes?

Create a DNS monitor for the record and set the answer you expect, such as the IP of an A record or the mail host of an MX record. Hyperping fails the check when no record contains that value, so a changed, deleted or hijacked record triggers an alert. It checks one record type per monitor and doesn’t keep a history of every change in the zone.

Which DNS record types can Hyperping monitor?

A, AAAA, CNAME, MX, NS, TXT, SOA, SRV, CAA and PTR. Each monitor checks one record type on one hostname, so you watch A, MX and TXT on the same domain with three monitors, each with its own expected answer and alerts.

Can I monitor a specific DNS server or nameserver?

Yes. Give the monitor a nameserver, by IP address or hostname, and every check queries it directly. Point it at your authoritative nameservers to see a change the moment it’s published, or at a public resolver to confirm it has propagated. Without one, checks use the resolver of each monitoring region.

How often does Hyperping check DNS records?

As often as every 30 seconds, from up to 18 regions you choose, like any other monitor. Each check records the resolution time and the records returned, so you can see what every region got.

Can DNS monitoring detect DNS hijacking?

It catches the symptom: an A, NS or MX record that no longer holds the value you set. With an expected answer on each critical record, a hijacked record fails the next check and pages your on-call. Hyperping doesn’t validate DNSSEC or watch for look-alike domains, and stopping a registrar compromise is a separate job.

Does Hyperping alert me before my domain expires?

Yes. Domain expiry alerts read the registration’s end date from the registry and remind you 7 to 90 days ahead, once per domain. They come with HTTP, ping, port and DNS monitors and are explained on the SSL and domain expiry monitoring page.

Is DNS monitoring included in the free plan?

No. DNS monitors are included on the Essentials, Pro and Business plans, and count toward the plan’s monitors. The Free plan covers HTTP, keyword, ping and port monitors. See pricing.

Can I create DNS monitors with the API?

Yes. In the monitors API, set protocol to dns, then dns_record_type, and optionally dns_expected_answer and dns_nameserver. The MCP server takes the same fields, so an AI agent can add a DNS monitor for you.

Your DNS records, watched in a minute.