Compare the fleet
Every domain is checked for the same 13 records, then compared with the reference. If the reference is blank, the most common value for each record is the baseline.
How it works
Collect
Thirteen records are fetched for every domain over DNS-over-HTTPS: NS, A, AAAA, MX, SPF, DMARC, DKIM on the selectors you name, MTA-STS, TLS-RPT, BIMI, CAA, DNSSEC and www.
Normalise
Nameservers are reduced to their provider, SPF mechanisms are sorted, DMARC is reduced to its policy tags, so cosmetic differences do not show as drift.
Baseline
The reference domain's values are the baseline. With no reference, the most common value per record across the list is.
Diff
Every cell is same, differs, missing or duplicate. The differences table lists each one with both values, and the CSV has every raw record.
Fleets drift
Twelve sending domains, set up over three months by two people following the same checklist, are never actually the same. One was created before the DMARC policy moved to reject and still says none. One has the SPF include for a tool that was dropped in April. One was registered at a different registrar and never had DNSSEC turned on. None of these shows up in a per-domain check, because each domain looks fine on its own. They show up when you put them side by side, and this is the side-by-side.
Why the reference matters
Pick the domain you know is right — usually the oldest, or the one you set up most carefully — and everything else is measured against it. Without one, the tool uses the majority value for each record, which works well for a fleet that is mostly correct and badly for one where the majority is wrong. If eight of ten domains have SPF ending in +all because a template was copied, the majority baseline will mark the two good ones as different. The notes below the grid catch that specific fault regardless, but a reference is better.
What is compared, and what is not
Nameservers are compared by provider, not hostname, because Cloudflare and Route 53 assign different servers to every zone and that is not drift. SPF mechanisms are sorted before comparison so include:a include:b and include:b include:a match. DMARC is compared on policy — p, sp, adkim, aspf, pct — and the rua address is exported but not diffed, since it is often per-domain. DKIM is compared on which of your named selectors exist, not the key itself, because keys are meant to differ. A and www are compared exactly, which is right for a fleet that should all land on the same site.
The faults this usually finds
A domain with MX but no DKIM on any known selector, meaning it has been sending unsigned. SPF that still lists a departed tool, or that ends in +all. DMARC at none on the newest domains because the template predates the policy change. A www that does not resolve, which loses every prospect who types it. And nameservers split across two providers because a domain was bought at a different registrar — not wrong, but it explains why the next DNS change gets missed on that one.
Frequently asked questions
What counts as a difference?
Any cell whose normalised value is not identical to the baseline's. Nameservers compare by provider, SPF by sorted mechanisms, DMARC by policy tags, DKIM by which selectors exist, everything else exactly.
Why is my DKIM selector shown as missing?
The tool only probes the selectors you list in the box. Google Workspace uses 'google', Microsoft 365 'selector1' and 'selector2', most tools something like 'k1' or 'mail'. Add yours if it is different.
Can I compare domains on different providers?
Yes. Nameserver and MX differences are reported as differences, which is what you want to see. Whether they matter is your call — the notes flag the ones that affect delivery.
How many domains can I compare?
Twenty-five per run, thirteen records each. The checks run three domains at a time so the resolver does not rate-limit you.
Does this monitor for drift over time?
No — it is a snapshot. The domain monitor watches the same records daily and emails you when one changes.
Last reviewed
What to run next
The checks that most often follow this one.
More in this category
Guides that go deeper
When the tools tell you something is wrong
The diagnostics here are free and always will be. When the fix is bigger than a DNS record, this is the work I do.
Deliverability rescue
Mail landing in spam, replies gone quiet, or a domain suddenly blocked. I find the actual cause rather than guessing, and fix it.
- Authentication and alignment failures
- Blocklist delistings and reputation repair
- Gateway and filter-level blocks
- A written report on what broke and why
Email & sending infrastructure
Sending domains, inboxes, authentication and warmup, built to survive volume instead of burning down in a month.
- Domain and inbox fleets at any scale
- SPF, DKIM, DMARC and tracking domains
- Google Workspace — Silver Partner
- Handover documentation you actually own
Domain, DNS & migration
Changing registrar, mail provider or host without a day of downtime or a week of mail silently failing.
- Registrar and nameserver moves
- Workspace and Microsoft 365 migrations
- MX, SSL and subdomain cutover
- Staged rollout with rollback at every step
Monitoring & retainer
Infrastructure drifts. Records get edited, certificates expire, domains get listed. Ongoing eyes on the fleet.
- Scheduled checks across every domain
- Alerts before your clients notice
- Monthly reporting
- Priority response when something breaks
Start with a call
Bring a domain and the symptom. I will tell you what is actually wrong and whether you need me at all — plenty of people leave that call able to fix it themselves.
Thirty minutes, no pitch
We will run the checks together on your actual domains, and you will leave knowing what is broken, what it takes to fix, and what it should cost. If that is a job you can do in-house, I will say so.