Compare the fleet

Every domain is checked for the same 13 records, then compared with the reference. If the reference is blank, the most common value for each record is the baseline.

How it works

fleet · 12 domains · baseline acme.co
SPF11 same · getacme.com ~all → +all1 DIFFERS
DKIMgoogle selector on 111 MISSING
DMARCp=reject on 10 · p=none on 22 DIFFER
NScloudflare.com on allSAME
MXgoogle on allSAME
Twelve domains set up by hand over three months. Three of them are not what you think they are.
01

Collect

Thirteen records are fetched for every domain over DNS-over-HTTPS: NS, A, AAAA, MX, SPF, DMARC, DKIM on the selectors you name, MTA-STS, TLS-RPT, BIMI, CAA, DNSSEC and www.

02

Normalise

Nameservers are reduced to their provider, SPF mechanisms are sorted, DMARC is reduced to its policy tags, so cosmetic differences do not show as drift.

03

Baseline

The reference domain's values are the baseline. With no reference, the most common value per record across the list is.

04

Diff

Every cell is same, differs, missing or duplicate. The differences table lists each one with both values, and the CSV has every raw record.

Fleets drift

Twelve sending domains, set up over three months by two people following the same checklist, are never actually the same. One was created before the DMARC policy moved to reject and still says none. One has the SPF include for a tool that was dropped in April. One was registered at a different registrar and never had DNSSEC turned on. None of these shows up in a per-domain check, because each domain looks fine on its own. They show up when you put them side by side, and this is the side-by-side.

Why the reference matters

Pick the domain you know is right — usually the oldest, or the one you set up most carefully — and everything else is measured against it. Without one, the tool uses the majority value for each record, which works well for a fleet that is mostly correct and badly for one where the majority is wrong. If eight of ten domains have SPF ending in +all because a template was copied, the majority baseline will mark the two good ones as different. The notes below the grid catch that specific fault regardless, but a reference is better.

What is compared, and what is not

Nameservers are compared by provider, not hostname, because Cloudflare and Route 53 assign different servers to every zone and that is not drift. SPF mechanisms are sorted before comparison so include:a include:b and include:b include:a match. DMARC is compared on policy — p, sp, adkim, aspf, pct — and the rua address is exported but not diffed, since it is often per-domain. DKIM is compared on which of your named selectors exist, not the key itself, because keys are meant to differ. A and www are compared exactly, which is right for a fleet that should all land on the same site.

The faults this usually finds

A domain with MX but no DKIM on any known selector, meaning it has been sending unsigned. SPF that still lists a departed tool, or that ends in +all. DMARC at none on the newest domains because the template predates the policy change. A www that does not resolve, which loses every prospect who types it. And nameservers split across two providers because a domain was bought at a different registrar — not wrong, but it explains why the next DNS change gets missed on that one.

Frequently asked questions

What counts as a difference?

Any cell whose normalised value is not identical to the baseline's. Nameservers compare by provider, SPF by sorted mechanisms, DMARC by policy tags, DKIM by which selectors exist, everything else exactly.

Why is my DKIM selector shown as missing?

The tool only probes the selectors you list in the box. Google Workspace uses 'google', Microsoft 365 'selector1' and 'selector2', most tools something like 'k1' or 'mail'. Add yours if it is different.

Can I compare domains on different providers?

Yes. Nameserver and MX differences are reported as differences, which is what you want to see. Whether they matter is your call — the notes flag the ones that affect delivery.

How many domains can I compare?

Twenty-five per run, thirteen records each. The checks run three domains at a time so the resolver does not rate-limit you.

Does this monitor for drift over time?

No — it is a snapshot. The domain monitor watches the same records daily and emails you when one changes.

Last reviewed

Related tools

What to run next

The checks that most often follow this one.

DNS records

More in this category

Read more

Guides that go deeper

Services

When the tools tell you something is wrong

The diagnostics here are free and always will be. When the fix is bigger than a DNS record, this is the work I do.

Get in touch

Start with a call

Bring a domain and the symptom. I will tell you what is actually wrong and whether you need me at all — plenty of people leave that call able to fix it themselves.

Thirty minutes, no pitch

We will run the checks together on your actual domains, and you will leave knowing what is broken, what it takes to fix, and what it should cost. If that is a job you can do in-house, I will say so.

Based inRangpur, Bangladesh — all time zones
RepliesWithin one business day
PartnerGoogle Workspace Silver
Back to top