NetTrace

News and updates

Everything that changed since the first version, newest first.

Benchmark

Measured: faster than Cloudflare and Google for repeat checks

  • In the public benchmark of 5 October NetTrace is the fastest for a repeated DNS check: median 1.1 ms, versus 5.4 ms for Cloudflare 1.1.1.1 and 6.8 ms for Google Public DNS.
  • Also the fastest with a warm cache: p95 2.4 ms, versus 9.9 ms for Cloudflare and 13.0 ms for Google.
  • API v1.7 versus v1.0 with a cold cache: first answer in 44.5 ms instead of 1,204 ms, more than 27 times faster.
  • To be fair: for a completely new name Cloudflare (10.1 ms) and Google (19.5 ms) are still faster, because they query one resolver and NetTrace more than 200. All figures and the method are on the benchmark page.
  • Mail and blacklist checks now take about 80 and 140 ms for a cold query.
v1.7

Faster first answer, two new tools and dark mode

  • DNS checker: the first answer now arrives once 60% of resolvers have answered (after at least 0.03 s), or 45% after 0.1 s, and always within 0.6 s; if 85% is already ready, immediately. In our test with not-yet-cached names the median dropped from 168 to 67 ms compared to v1.6.
  • New: Subdomain finder. Finds subdomains without brute force, from certificate logs (crt.sh, Cert Spotter), NSEC walking, zone transfer, the domain's own DNS records and the website itself. Every name is verified live; dead names are not shown.
  • The subdomain finder identifies the CDN or host of every subdomain (Cloudflare, Bunny, Gcore, Fastly, Akamai, AWS, Google Cloud, Hetzner and more) from the CNAME chain and the ASN. Click an IP address for full details in IP info.
  • New: Mail server test. Tests the MX servers on port 25: SMTP banner, STARTTLS, TLS version, certificate, reverse DNS, DANE, MTA-STS and TLS-RPT, with a score. No mail is ever sent.
  • Mail check, blacklist check and security scan are much faster for cold queries: mail check from ~500 to ~80 ms, blacklist check from ~520 to ~140 ms. Slow or broken nameservers no longer hold up a check for up to 5 seconds.
  • Dark mode: follows your system setting automatically, with a button to choose yourself.
  • The homepage illustration now moves: pings and packets between the nodes.
  • Tele2 is now called Odido in the resolver list.
  • New: the NetTrace Discord bot with every tool as a slash command (/dns, /mail, /security, /blacklist, /ip, /website, /whois, /ssl, /headers, /mailserver, /subdomains, /spf, /dmarc), in Dutch and English.
  • New: a check page for every major DNS provider, such as Cloudflare, Google, Quad9, OpenDNS, AdGuard, NextDNS, Control D and DNS4EU.
  • New: the Logo and banners page with the logo, wordmarks and banners to download.
v1.6

2 to 3 times faster first answer

  • Fast-first answer: the response arrives once 65% of resolvers have answered (after at least 0.06 s), or 50% after 0.15 s, and always within 0.8 s.
  • Cold DNS check: median from 418 ms (v1.5) to 78 ms.
  • Per-resolver timeout from 2 to 1.2 seconds: a complete check is now ready in ~1.2 s instead of ~2 s.
  • Slow and unreliable resolvers moved to the standby list and replaced by faster ones.
v1.5

Fast-first answer, 200+ resolvers and new tools

  • Fast-first answer: NetTrace no longer waits for the slowest resolver. Resolvers still running are marked "pending" and completed in the background; you can watch live with streaming.
  • Popular checks are kept warm, so they almost always come straight from the cache.
  • From 50 to more than 200 DNS resolvers worldwide, with automatic replacement of resolvers that keep failing.
  • New tools: Website check (speed, SEO and best practices), Whois, SSL check, HTTP headers and an SPF/DMARC generator, under a new Tools menu.
  • Comparison page with other DNS tools, with sources.
Rebuild

The API rebuilt: from PHP to Go

  • The entire API was rewritten from PHP to Go. Every resolver is now really queried, all at once, with its own strict timeout per server.
  • Answers are cached according to their own TTL; identical concurrent questions share one lookup. A repeated query returns in ~1 ms.
  • Our own validating DNS resolver (Unbound) for mail, security and blacklist checks, HTTP/2 and HTTP/3, compression and a fair per-IP rate limit.
  • Tested against local mock resolvers: a 10-minute soak test with 770,883 requests without a single error.
  • Mail checker: automatic DKIM detection and no more false failures for DMARC and Google verification. Blacklist check: SORBS and Invaluement (no longer available) replaced by Spamhaus ZEN and Mailspike.
  • New IP info tool with multiple sources (DB-IP, MaxMind via RIPEstat, RIR, RDAP and BGP).
  • New website: fast, white design, Dutch and English, with its own API documentation, a public benchmark, a status page and an About page.
  • Privacy: access logs are anonymised (IPv4 /24, IPv6 /48) and deleted after 14 days.
  • Existing integrations keep working: /v1.0 behaves like the old API (waits for all resolvers), so the browser extensions and the npm CLI don't break.
v1.0

The original NetTrace

  • The first version of NetTrace, built in PHP: DNS check, email check, security check and blacklist check through a simple API, with browser extensions for Chrome and Firefox and an npm CLI.

Technical details per API version are in the API documentation