NetTrace

Benchmark

How fast is NetTrace really? These are the measured numbers, including where we are not the fastest.

Test date: 4 October 2026Location: NetTrace's own VPS (37.1.226.221, Netherlands)Requests: 401

Fastest cache hit (repeat within 1 s): median 0.9 ms versus 4.0 ms for the fastest other service (Cloudflare 1.1.1.1). Compared with Google Public DNS and Cloudflare 1.1.1.1, measured on 2026-10-04.

Fastest cache hit (repeat within 1 s): p95 1.1 ms versus 5.5 ms for the fastest other service (Cloudflare 1.1.1.1). Compared with Google Public DNS and Cloudflare 1.1.1.1, measured on 2026-10-04.

Fastest warm cache: median 1.0 ms versus 4.2 ms for the fastest other service (Cloudflare 1.1.1.1). Compared with Google Public DNS and Cloudflare 1.1.1.1, measured on 2026-10-04.

Findings

  • 74% lower p95 latency than NetTrace (old API) for A/MX-lookups with cache hit (repeat within 1 s) (1.1 vs 4.1 ms), measured on 2026-10-04.
  • 99% lower p95 latency than Google Public DNS for A/MX-lookups with cache hit (repeat within 1 s) (1.1 vs 88.7 ms), measured on 2026-10-04.
  • 80% lower p95 latency than Cloudflare 1.1.1.1 for A/MX-lookups with cache hit (repeat within 1 s) (1.1 vs 5.5 ms), measured on 2026-10-04.
  • 299.0× higher p95 latency than NetTrace (old API) for A/MX-lookups with warm cache (1289.1 vs 4.3 ms), measured on 2026-10-04. NetTrace is not faster here: the old API did not really query the 32 resolvers (at the time) but sent every query to one local resolver, so the answers were not per resolver.
  • 165.6× higher p95 latency than NetTrace (old API) for A/MX-lookups with cold cache (2003.4 vs 12.1 ms), measured on 2026-10-04. NetTrace is not faster here: the old API did not really query the 32 resolvers (at the time) but sent every query to one local resolver, so the answers were not per resolver.
  • 64.9× higher p95 latency than Google Public DNS for A/MX-lookups with warm cache (1289.1 vs 19.9 ms), measured on 2026-10-04. NetTrace is not faster here.
  • 32.6× higher p95 latency than Google Public DNS for A/MX-lookups with cold cache (2003.4 vs 61.4 ms), measured on 2026-10-04. NetTrace is not faster here.
  • 215.7× higher p95 latency than Cloudflare 1.1.1.1 for A/MX-lookups with warm cache (1289.1 vs 6.0 ms), measured on 2026-10-04. NetTrace is not faster here.
  • 114.4× higher p95 latency than Cloudflare 1.1.1.1 for A/MX-lookups with cold cache (2003.4 vs 17.5 ms), measured on 2026-10-04. NetTrace is not faster here.

Cache hit (repeat within 1 s)

Latency in milliseconds, logarithmic scale. Shorter bar = faster.

1 ms10 ms100 msNetTrace p50 0.9 ms · p95 1.1 ms · p99 1.1 msNetTrace (old API) p50 3.9 ms · p95 4.1 ms · p99 4.2 msGoogle Public DNS p50 6.6 ms · p95 89 ms · p99 128 msCloudflare 1.1.1.1 p50 4.0 ms · p95 5.5 ms · p99 7.2 ms
p50p95p99

Warm cache (repeat after ~10 s)

Latency in milliseconds, logarithmic scale. Shorter bar = faster.

1 ms10 ms100 ms1 sNetTrace p50 1.0 ms · p95 1289 ms · p99 2003 msNetTrace (old API) p50 3.9 ms · p95 4.3 ms · p99 5.5 msGoogle Public DNS p50 6.5 ms · p95 20 ms · p99 59 msCloudflare 1.1.1.1 p50 4.3 ms · p95 6.0 ms · p99 8.7 ms
p50p95p99

Cold cache (unique name per query)

Latency in milliseconds, logarithmic scale. Shorter bar = faster.

1 ms10 ms100 ms1 sNetTrace p50 2003 ms · p95 2003 ms · p99 2007 msNetTrace (old API) p50 8.3 ms · p95 12 ms · p99 13 msGoogle Public DNS p50 20 ms · p95 61 ms · p99 104 msCloudflare 1.1.1.1 p50 10 ms · p95 18 ms · p99 86 ms
p50p95p99

All numbers

ServiceScenarionp50p95p99Errors
NetTracecache-hit240.9 ms1.1 ms1.1 ms0
NetTracewarm481.0 ms1289 ms2003 ms0
NetTracecold242003 ms2003 ms2007 ms0
NetTrace (old API)cache-hit243.9 ms4.1 ms4.2 ms0
NetTrace (old API)warm483.9 ms4.3 ms5.5 ms0
NetTrace (old API)cold248.3 ms12 ms13 ms0
Google Public DNScache-hit246.6 ms89 ms128 ms0
Google Public DNSwarm486.5 ms20 ms59 ms0
Google Public DNScold2420 ms61 ms104 ms0
Cloudflare 1.1.1.1cache-hit244.0 ms5.5 ms7.2 ms0
Cloudflare 1.1.1.1warm484.3 ms6.0 ms8.7 ms0
Cloudflare 1.1.1.1cold2410 ms18 ms86 ms0
HackerTargetwarm9–––9
HackerTargetcold8–––8

Method

All services were measured from the same location (NetTrace's own VPS (37.1.226.221, Netherlands)), in the same time window, with the same domains (nettrace.eu, wikipedia.org, github.com) and record types (A, MX). Service order was randomised every round.

Volume: one request at a time with a 2 s pause, round-robin across services, so roughly one request per 10 s per service. No load or stress testing of other services. HackerTarget is capped at 30 requests because of their free daily quota.

Warm cache: the same query repeated eight times with ~10 s in between; the first query is not counted. Because NetTrace keeps a complete check for 30 s, roughly every third repeat is a fresh check; that determines NetTrace's p95 in this scenario. Cold cache: a unique, never-used name under nettrace.eu (which exists through a wildcard record), so no service can have it cached.

Cache hit: ask the same query, then repeat it 1 second later; only the repeat counts. This measures, for every service, how fast an answer is that is already cached. HackerTarget is not included here because of its daily quota.

We measure total time from request to fully received response over an existing HTTPS connection (keep-alive). p50, p95 and p99 are computed from all successful measurements; failed requests are listed as errors.

Important for the comparison: NetTrace queries 84 resolvers per request and returns all 84 answers. Google and Cloudflare return the answer of one resolver, HackerTarget all record types from one resolver. With a cold cache NetTrace therefore waits for the slowest of 84 resolvers worldwide.

NetTrace cache: a complete DNS check (all resolvers) stays cached for at least 30 seconds and at most the shortest TTL among the answers (up to 1 hour). A repeated query within that time is a cache hit. Per resolver the cache follows the TTL exactly. The old API is the same service before the rebuild: it sent all 32 "resolver" queries to one local resolver, so it did not really query the resolvers, and it did so one after another.

Fairness note: this measurement runs on the same server as the NetTrace API, so NetTrace has no network round trip. That gives NetTrace an advantage. A measurement from a second, independent location is not yet available.

Domains used

nettrace.eu, wikipedia.org, github.com

Services

  • NetTrace – POST https://api.nettrace.eu/v1.0/dns-check (84 resolvers per request) (terms)
  • NetTrace (old API) – POST https://api.nettrace.eu/legacy/v1.0/dns-check (old PHP code, internal only) (terms)
  • Google Public DNS – GET https://dns.google/resolve?name=…&type=… (1 resolver) (terms)
  • Cloudflare 1.1.1.1 – GET https://cloudflare-dns.com/dns-query?name=…&type=… (1 resolver) (terms)
  • HackerTarget – GET https://api.hackertarget.com/dnslookup/?q=… (all record types per request) (terms)

Excluded

  • NetworkCalc: No terms of service found that allow automated use (terms page returned 404), so not measured.
  • DNSChecker.org / WhatsMyDNS.net: No public API; automated use of the website is not permitted.
  • HackerTarget (deze meting): HackerTarget's daily quota was reached during this run: the service returned a quota error instead of DNS data, so these measurements are not counted.

This benchmark is re-run automatically every month with the same script. The raw measurements are in the CSV.