DNS Statistics 2026: Benchmarks, Trends and 22 Countries

What's a normal NXDOMAIN rate or cache hit ratio? 2026 DNS statistics from 1.1.1.1 by month and country, plus who hosts DNS: Cloudflare 15.4%, GoDaddy 14.2%.

Published Data through September 202633 min read

DNS Statistics 2026: Benchmarks, Trends and 22 Countries
Share:

DNS statistics for 2026 show that 82.2% of queries to Cloudflare's 1.1.1.1 resolver are answered from cache, 12.9% arrive encrypted and 14.5% end in NXDOMAIN, a rate lifted by an August spike. TechnologyChecker's DNS probe of 2,423 live domains finds Cloudflare hosting DNS for 15.4% of them and GoDaddy for 14.2%.

Key DNS statistics at a glance (resolver window 27 Aug to 23 Sep 2026, compared with the same dates in 2025):

Metric 2026 value vs 2025 Source
A record share of resolver queries 65.0% +1.9 pt Cloudflare Radar (1.1.1.1)
AAAA (IPv6 address) share 20.9% +2.5 pt Cloudflare Radar (1.1.1.1)
NXDOMAIN share of responses 14.5% +3.5 pt Cloudflare Radar (1.1.1.1)
SERVFAIL share of responses 2.1% −0.7 pt Cloudflare Radar (1.1.1.1)
Answered from cache 82.2% −0.1 pt Cloudflare Radar (1.1.1.1)
Answers with TTL of 1 minute or less 75.0% −3.3 pt Cloudflare Radar (1.1.1.1)
Encrypted queries (DoH + DoT) 12.9% +0.8 pt Cloudflare Radar (1.1.1.1)
End-to-end DNSSEC validated 0.54% +0.16 pt Cloudflare Radar (1.1.1.1)
Median DNS response time (IQI p50) 56.5 ms +3.3 ms Cloudflare Internet Quality Index
Live domains on Cloudflare nameservers 15.4% n/a (first probe) TechnologyChecker sample, n = 2,423
Live domains with no MX record 21.4% n/a (first probe) TechnologyChecker sample, n = 2,423
Live domains enforcing DMARC 13.9% n/a (first probe) TechnologyChecker sample, n = 2,423
🧮
How We Measured: Two datasets sit behind this page. Resolver behaviour comes from Cloudflare Radar's view of its 1.1.1.1 public resolver, which is one large resolver and not all DNS on the internet. Hosting and email-record figures come from TechnologyChecker's own probe of a random sample of live business domains, resolved on 23 September 2026.

I'm David Thomson, CTO at TechnologyChecker. I spent five years on crawling and indexing systems in Google Search, and I now run the crawler that sweeps our index of about 30 million live business domains. Every one of those fetches starts with a DNS lookup, so these numbers are the first thing that goes wrong for us when the internet misbehaves.

What are DNS statistics?

DNS statistics are counts and ratios describing how the Domain Name System is used: which record types get asked for, how often lookups fail, how much is served from cache, how queries travel and who runs the servers that answer them. The term covers four different populations, and mixing them up is the most common way these numbers get misread.

  • Recursive resolver statistics describe the lookups a resolver performs for its users. Your ISP's resolver, a corporate resolver and a public one such as 1.1.1.1 all produce them.
  • Authoritative statistics describe the queries a zone's own nameservers receive. Route 53, Cloudflare DNS or a BIND box in your data centre sees these.
  • Public-resolver telemetry is resolver data published at internet scale. Cloudflare Radar's DNS dashboard is the main open source of it, and it's the backbone of the traffic sections below.
  • Zone and domain data describes how domains are configured: nameservers, MX records, SPF, DMARC, DNSSEC signing. This is where TechnologyChecker's probe comes in.
Yes: 82.2% No Yes No Timeout or broken zone Device asks for a name Recursive resolver Answer in cache? Cached answer Authoritative nameserver Does the name exist? NOERROR NXDOMAIN SERVFAIL
Where each resolver statistic in this post is measured

Search for "DNS statistics" today and you mostly get vendor manuals: the PowerShell cmdlet that dumps counters from a Windows DNS server, a statistics screen in a load balancer. Useful if you already know what you're looking at. None of them tells you whether 14% NXDOMAIN is normal, and that's the question I kept wanting answered, so this page puts the internet-wide numbers next to each counter.

Which DNS record types do resolvers answer most?

A records still dominate. 65.0% of queries to 1.1.1.1 ask for an IPv4 address and another 20.9% are AAAA lookups for IPv6, so address lookups make up 86% of resolver traffic. Every other record type, HTTPS and MX included, fights over the last 14%.

Query type Share, 2026 window Same window 2025 Change
A 65.01% 63.06% +1.95 pt
AAAA 20.89% 18.43% +2.46 pt
HTTPS (type 65) 7.11% 8.53% −1.42 pt
PTR (reverse) 3.88% 4.76% −0.88 pt
NS 0.76% 1.53% −0.76 pt
TXT 0.73% 0.63% +0.10 pt
CNAME 0.23% 0.38% −0.15 pt
MX below 0.23% 0.36% fell out of the top 10

DNS Query Types 2026: A Records 65%, AAAA 21% of 1.1.1.1 Lookups

Distribution of DNS queries to Cloudflare's 1.1.1.1 resolver by record type. A (IPv4 address) lookups made up 65.0% and AAAA (IPv6 address) lookups 20.9% in the 2026 window, both up on 2025, while HTTPS record queries fell from 8.5% to 7.1%.

Source: Cloudflare Radar · Aug-Sep 2026 (with 2025 comparison in notes)

DNS Query Types 2026: A Records 65%, AAAA 21% of 1.1.1.1 Lookups
DNS record typeShare of queries (%)
A65.01%
AAAA20.89%
HTTPS7.11%
PTR3.88%
NS0.76%
TXT0.73%
CNAME0.23%
  • Address lookups (A plus AAAA) are 86% of resolver traffic
  • AAAA gained 2.5 points, the biggest rise of any record type
  • HTTPS record queries fell 1.4 points year on year

AAAA gained more share than any other type. It's tempting to read that as IPv6 winning, and it isn't: only 9.0% of queries reached the resolver over IPv6, down from 9.3%. Dual-stack clients ask for both A and AAAA over whatever link they have, so AAAA share tracks IPv6-capable software, not IPv6-connected users.

The HTTPS record (defined in RFC 9460) lets a site advertise HTTP/3 support and connection hints before the first request. Its query share fell 1.4 points in a year. That points in the same direction as the HTTP/3 figures in our HTTP protocol adoption tracker, though I wouldn't claim one causes the other from query shares alone.

📈
Trend Watch: ANY queries made up 1.14% of 1.1.1.1 traffic in late summer 2025. The weekly series was still near 3% in spring 2026, then collapsed to 0.08% by September 2026. NOTIMP responses fell from 1.14% to 0.10% over the same year, in step with the ANY collapse, which suggests many of those ANY queries were being answered NOTIMP.

ANY queries return every record at a name, which makes them useful for amplification attacks and little else. RFC 8482 lets servers answer them with a minimal response instead. If ANY still shows up in your own resolver logs at more than a fraction of a percent, check where it comes from.

How often do DNS lookups fail?

Mail sorting hub where most envelopes reach houses and a pile returns from empty plots, illustrating NXDOMAIN answers
About one lookup in six asks for a name that doesn't exist. Illustration; data: Cloudflare Radar, September 2026.

About one DNS lookup in six comes back without a usable address. Across the 27-day window, 83.2% of 1.1.1.1 responses were NOERROR, 14.5% were NXDOMAIN and 2.1% were SERVFAIL. REFUSED and NOTIMP together were 0.2%.

Response code 2026 window Same window 2025 Trailing 52 weeks
NOERROR 83.16% 84.52% 84.13%
NXDOMAIN 14.52% 10.97% 11.46%
SERVFAIL 2.11% 2.77% 2.86%
REFUSED 0.11% 0.60% 0.61%
NOTIMP 0.10% 1.14% 0.94%

DNS Failure Rates 2026: NXDOMAIN Spiked to 18% of 1.1.1.1 Responses

Weekly share of DNS responses from Cloudflare's 1.1.1.1 resolver that returned NXDOMAIN (name does not exist) or SERVFAIL (resolver could not get an answer), June to mid-September 2026. NXDOMAIN sat near 10 to 11% until late July, jumped to 18.0% in the week of 10 August, stayed around 16% through August and eased to 11.8% by the week of 14 September. SERVFAIL stayed near 2 to 3% throughout.

Source: Cloudflare Radar · Jun-Sep 2026

DNS Failure Rates 2026: NXDOMAIN Spiked to 18% of 1.1.1.1 Responses
Week startingNXDOMAIN share of responses (%)
Jun 110.33%
Jun 811.51%
Jun 1510.61%
Jun 229.75%
Jun 2910.47%
Jul 610.84%
Jul 1310.67%
Jul 2010.96%
Jul 2711.09%
Aug 313.46%
Aug 1018.04%
Aug 1716.73%
Aug 2416.04%
Aug 3116.29%
Sep 714.22%
Sep 1411.83%
  • NXDOMAIN jumped from 11.1% to 18.0% of responses in two weeks in early August 2026
  • The surge faded through September, back to 11.8% by the week of 14 September
  • SERVFAIL, the closer proxy for broken lookups, stayed between 1.8% and 2.4% every week

The NXDOMAIN jump is an August event, not a trend. The weekly series sat around 10 to 11% from April to the end of July, then went to 13.5% in the week of 3 August and 18.0% the week after. It held near 16% for the rest of August and was back to 11.8% by the week of 14 September. The 27-day figure above catches the tail of that surge. A rate that moves seven points in two weeks and drifts back is almost always a handful of noisy sources, not a change in how people browse. The usual NXDOMAIN drivers are:

  • software appending search-domain suffixes (api.example.com.corp.local)
  • malware and ad-fraud tooling generating random names
  • misconfigured devices retrying a retired hostname
  • scanners and typos, which are a steady background rather than a spike

My first guess was cloud servers, because a lot of 1.1.1.1's traffic comes from data centres. The network split says no. Home broadband sits right on the global average, and two of the big cloud networks sit below it:

Source network Share of 1.1.1.1 queries NXDOMAIN share
SpaceX Starlink 8.97% 23.3%
Hetzner 1.33% 17.0%
Comcast 1.23% 15.0%
Deutsche Telekom 0.64% 14.9%
AT&T 0.98% 11.9%
DigitalOcean 2.07% 10.1%
Tencent 3.73% 8.8%

Starlink is the outlier, with close to one answer in four an NXDOMAIN, and 10.5% of its queries are reverse (PTR) lookups against 3.9% overall. Tencent's traffic looks nothing like people at all: 50.8% A, 49.1% AAAA and almost no HTTPS-record queries, which is what a fleet of servers resolving the same backends produces.

Negative answers are cacheable too. Under RFC 2308, the NXDOMAIN cache time comes from the lower of the zone's SOA TTL and its SOA MINIMUM field, so a zone with a tiny SOA minimum pushes repeated misses back to its authoritative servers.

⚠️
Common Mistake: Treating a 14.5% NXDOMAIN rate as a failure rate for users. Most NXDOMAIN answers go to software asking for names that were never meant to exist. SERVFAIL, at 2.1%, is the number closer to "a real lookup broke".

Domains fail at the zone level as well. When we probed our random sample of 2,567 live business domains on 23 September, 66 (2.6%) returned NXDOMAIN and 19 (0.7%) returned SERVFAIL. Those were all domains our crawler had seen serving a website. Registrations lapse and zones break between one scan and the next, so any domain list starts decaying the day it's built.

How much DNS is served from cache?

Most of it. 82.2% of queries to 1.1.1.1 were answered straight from cache in the 2026 window, level with 82.4% a year earlier. The trailing 52-week average is lower, at 79.8%, because the ratio dipped in spring, to 75.2% for April as a whole, before recovering.

A cache hit ratio in the low 80s at this scale is a useful ceiling for anyone running their own resolver. A public resolver serving millions of clients shares cache entries across all of them. A company resolver with a few thousand users will see fewer repeat names and should expect a lower ratio.

Why isn't it higher? Short TTLs. 75.0% of answers carried a TTL of one minute or less, down from 78.3% a year ago.

Answer TTL 2026 window Same window 2025
1 minute or less 74.97% 78.30%
Over 1 min, up to 5 min 14.69% 12.33%
Over 5 min, up to 15 min 2.34% 2.18%
Over 15 min, up to 1 hour 3.66% 3.38%
Over 1 hour, up to 1 day 3.13% 2.30%
Over 1 day, up to 1 week 0.06% 0.06%
Over 1 week 1.15% 1.44%

The TTL a resolver returns is the time remaining in its cache, not the TTL set in the zone file, so a cached one-hour record shows up as anything between zero and 60 minutes. Even allowing for that, most of what users resolve is set to expire quickly. CDNs and load balancers use short TTLs to steer traffic, and they account for a large share of popular names.

My view: if you don't do DNS-based failover on a record, a 60-second TTL buys you nothing except resolver load and slower first lookups. The small shift this year from sub-minute answers towards the 1-to-5-minute bucket may mean some operators have made the same call, though remaining-TTL data can't prove it.

How much DNS traffic is encrypted?

Pipeline of open postcards with one sealed padlocked envelope, illustrating the small share of encrypted DNS queries
Most DNS still travels as a postcard: 12.9% of 1.1.1.1 queries are encrypted. Illustration; data: Cloudflare Radar, September 2026.

Roughly one query in eight. 12.9% of queries to 1.1.1.1 arrived encrypted in the 2026 window, 6.5% over DNS over HTTPS (DoH) and 6.3% over DNS over TLS (DoT), up from 12.0% a year earlier. Plain UDP still carries 85.1% of queries, and plain TCP 2.0%.

The two protocols swapped places during the year. DoH, standardised in RFC 8484, rose from 5.2% to 6.5%, while DoT, from RFC 7858, slipped from 6.8% to 6.3%. DoH runs inside browsers and apps. DoT is mostly an operating-system setting, which is why it's so uneven by country.

DNS over HTTPS vs DNS over TLS 2026: DoH Passes 50% of Encrypted DNS

DNS over HTTPS (DoH) as a share of all encrypted DNS queries (DoH plus DNS over TLS) reaching Cloudflare's 1.1.1.1 resolver, sampled every two weeks from September 2025 to mid-September 2026. DoT carried the majority of encrypted queries for most of the year, apart from a brief spike in early November 2025; DoH moved above 50% again in September 2026 and stayed there for two straight weeks.

Source: Cloudflare Radar · Sep 2025-Sep 2026

DNS over HTTPS vs DNS over TLS 2026: DoH Passes 50% of Encrypted DNS
Week startingDoH share of encrypted DNS queries (%)
Sep 29 '2543.2%
Oct 13 '2543%
Oct 27 '2543%
Nov 10 '2550.2%
Nov 24 '2547.1%
Dec 8 '2545.3%
Dec 22 '2543.8%
Jan 5 '2645.2%
Jan 19 '2647.2%
Feb 2 '2645.8%
Feb 16 '2643.6%
Mar 2 '2645.2%
Mar 16 '2647.8%
Mar 30 '2649%
Apr 13 '2647.5%
Apr 27 '2648.5%
May 11 '2648%
May 25 '2646.7%
Jun 8 '2646.9%
Jun 22 '2646.4%
Jul 6 '2646.4%
Jul 20 '2646.2%
Aug 3 '2647.8%
Aug 17 '2648.4%
Aug 31 '2649.9%
Sep 14 '2651.9%
  • DoH has carried more encrypted DNS than DoT at 1.1.1.1 for two straight weeks in September 2026; the only earlier crossing was a brief spike in November 2025
  • Over the 27 days to 23 September, DoH carried 6.5% of all queries and DoT 6.3%
  • Encrypted DNS as a whole reached 12.9% of 1.1.1.1 queries, up from 12.0% a year earlier
Country DoH DoT Encrypted 2026 Encrypted 2025 Change
India 5.9% 22.6% 28.5% 28.8% −0.3 pt
Germany 11.4% 12.8% 24.1% 19.3% +4.9 pt
United Kingdom 9.6% 12.9% 22.5% 16.0% +6.5 pt
South Korea 9.6% 8.1% 17.6% 28.7% −11.0 pt
Russia 11.2% 6.4% 17.6% 11.5% +6.1 pt
Turkey 11.2% 5.3% 16.5% 19.3% −2.8 pt
France 8.4% 7.8% 16.2% 15.4% +0.8 pt
Indonesia 3.1% 11.6% 14.7% 13.5% +1.2 pt
Brazil 4.7% 8.3% 13.1% 10.7% +2.4 pt
Japan 9.0% 3.1% 12.1% 18.0% −5.9 pt
United States 4.9% 3.3% 8.2% 7.9% +0.3 pt
China 0.01% 3.8% 3.8% 5.9% −2.1 pt

Encrypted DNS by Country 2026: India Leads at 28.5%, US at 8.2%

Share of DNS queries to Cloudflare's 1.1.1.1 resolver that used DNS over HTTPS or DNS over TLS, by country, for 27 August to 23 September 2026 compared with the same dates in 2025. India had the highest encrypted share at 28.5%, mostly DoT; the UK, Russia and Germany gained 5 to 6.5 points, while South Korea fell 11 points.

Source: Cloudflare Radar · Aug-Sep 2026 (with 2025 comparison in notes)

Encrypted DNS by Country 2026: India Leads at 28.5%, US at 8.2%
CountryEncrypted share of queries (%)
India28.5%
Germany24.1%
United Kingdom22.5%
South Korea17.6%
Russia17.6%
Turkey16.5%
France16.2%
Indonesia14.7%
Brazil13.1%
Japan12.1%
United States8.2%
China3.8%
  • India leads at 28.5%, with 22.6% of queries over DoT
  • The UK gained 6.5 points and Russia 6.1 points in a year
  • South Korea dropped 11 points, from 28.7% to 17.6%

India is DoT-heavy: 22.6% of its 1.1.1.1 queries use DoT against 5.9% DoH. That pattern fits mobile-first traffic, since Android's Private DNS setting uses DoT. South Korea lost 11 points in a year and Japan almost 6, while the UK, Russia and Germany gained 5 to 6.5 points each. The United States sits at 8.2%, below the global figure. A likely reason is the volume of US traffic that reaches 1.1.1.1 from routers and servers, which rarely encrypt DNS.

📊
By the Numbers: DoH carried 6.5% of 1.1.1.1 queries in September 2026 against 5.2% a year earlier, overtaking DoT (6.3%) as the more common encrypted DNS transport. I'll cover what's driving the DoH shift, country by country, in a separate post.

How many domains use DNSSEC?

11.0% of 1.1.1.1 answers were DNSSEC-validated as secure in the 2026 window, up from 8.1%. Only 0.54% of queries were protected end to end, meaning a DNSSEC-aware client asked and a validated answer came back. Bogus (INVALID) answers stayed at 0.06%.

The rise wasn't gradual. By calendar month, the validated-secure share sat between 8.0% and 8.3% from January to July 2026, then jumped to 11.8% in August, the same month NXDOMAIN spiked. One explanation fits both: denials for random names under a signed TLD such as .com validate as secure, so a burst of junk lookups can lift both numbers at once. Summary data can't confirm that, so treat it as a hypothesis.

The client side went the other way. Queries from DNSSEC-aware clients fell from 13.2% to 10.0%, so more signed answers are going to clients that don't check them. Our DNSSEC adoption tracker follows these numbers month by month. Its August 2026 figure (11.8% signed) is the same calendar-month number as above; this page's headline 11.0% uses the 27 August to 23 September window instead.

From the zone side, TechnologyChecker's probe finds 8.3% of live business domains signed, with a DS record in the parent zone (±1.1 points at 95% confidence). Only 3.7% publish a CAA record, which restricts which certificate authorities may issue for the domain. Among CAA records, letsencrypt.org is the CA named most often, followed by Google's pki.goog.

What does TechnologyChecker's crawl see in DNS?

Every domain we crawl starts with a DNS lookup, and the answers are detection signals in their own right. TechnologyChecker's crawler reads the nameserver, mail-exchanger and TXT records at the root of each of the 30,287,857 live domains in our index and matches them against 18 nameserver patterns, 39 mail patterns and 134 TXT patterns. That's how we know which mail provider or DNS host a company uses without loading a single web page.

Here's what that looks like on our own domain, resolved on 23 September 2026:

$ dig +short technologychecker.io NS
kirk.ns.cloudflare.com.
tina.ns.cloudflare.com.

$ dig +short technologychecker.io MX
1 smtp.google.com.

$ dig +short technologychecker.io TXT
"v=spf1 include:amazonses.com ~all"
"google-site-verification=..."   (two tokens)

$ dig +short _dmarc.technologychecker.io TXT
"v=DMARC1;p=quarantine;rua=mailto:..."
Record What it says How we read it
NS *.ns.cloudflare.com Cloudflare answers for the zone DNS host: Cloudflare
MX smtp.google.com Mail is delivered to Google Mail provider: Google Workspace
TXT include:amazonses.com Amazon SES may send mail as this domain An authorised sender, not proof of current sending
TXT google-site-verification The domain was verified with a Google service once A past verification, not an active install
_dmarc p=quarantine Failing mail goes to spam Counted among the 13.9% that enforce DMARC (probe only)

The MX line is the one I trust most. It has to be right for mail to arrive, so a stale MX record breaks something and gets fixed. TXT verification tokens are the opposite: nothing breaks when they outlive the service, which is why we treat them as history rather than a live install.

💡
Quick Insight: Our own domain shows the gap in the Google Workspace count below. Google's newer single-record setup, smtp.google.com, isn't matched by the older Google mail pattern, so technologychecker.io itself wouldn't be counted. In the probe, 49 of 374 Google-mail domains (13.1%) used that setup, which puts the real figure nearer 4.45 million.

Across the whole index, these are the DNS-derived counts on 23 September 2026:

DNS signal Record Live domains Share of index
GoDaddy DNS or email NS, SOA, MX 4,616,211 15.2%
Microsoft 365 mail MX 4,051,686 13.4%
Google Workspace mail MX 3,868,210 (a floor) 12.8%
IONOS DNS or email MX, SOA 674,085 2.2%
Zoho Mail MX, TXT 484,911 1.6%
Apple iCloud Mail MX, TXT 384,257 1.3%
SendGrid (SPF include) TXT 347,638 1.1%
Mailgun (SPF include) TXT 310,438 1.0%
Namecheap email MX 259,385 0.9%
Amazon SES (SPF include) TXT 228,601 0.8%
Titan Email MX 151,217 0.5%
Mimecast MX 73,711 0.2%
Proofpoint MX 56,641 0.2%
Sophos MX, TXT 48,038 0.2%

GoDaddy and Microsoft 365 are the two counts we re-checked record by record: the detection agreed with the live lookup on 352 of 356 and 307 of 311 sampled domains. Read the three SPF-include rows as accounts rather than current sending, since an include line usually stays in place after a team stops using the service.

Who hosts the web's DNS?

Grid of houses with many lines converging on two large hubs, illustrating DNS hosting concentrated in two providers
Two operators answer for close to 30% of live business domains. Illustration; data: TechnologyChecker DNS probe, September 2026.

Two companies. Cloudflare and GoDaddy run the authoritative DNS for 29.6% of live business domains between them, and no other nameserver operator passes 4%. These shares come from TechnologyChecker's NS lookups on a random sample of 2,423 live, resolving domains on 23 September 2026.

Nameserver operator Share of live domains 95% margin
Cloudflare 15.4% ±1.4 pt
GoDaddy 14.2% ±1.4 pt
Google Cloud DNS 3.7% ±0.8 pt
Wix 3.6% ±0.7 pt
Hostinger 3.3% ±0.7 pt
Parking and aftermarket nameservers 3.3% ±0.7 pt
IONOS 2.4% ±0.6 pt
Namecheap 2.2% ±0.6 pt
AWS Route 53 (AWS) 1.9% ±0.5 pt
NS1 1.7% ±0.5 pt
OVHcloud 1.5% ±0.5 pt
Strato 1.2% ±0.4 pt
HostGator 1.1% ±0.4 pt
SiteGround, Bluehost, Network Solutions, WordPress.com, One.com, Aruba 0.8 to 0.9% each ±0.4 pt
Azure DNS 0.3% ±0.2 pt
Everything else (200+ operators) 33.2% ±1.9 pt

DNS Hosting Market Share 2026: Cloudflare 15.4%, GoDaddy 14.2%

Authoritative DNS hosting share among live business domains, measured by TechnologyChecker from NS record lookups on a random sample of 2,423 resolving domains on 23 September 2026. Cloudflare answered for 15.4% and GoDaddy for 14.2%; no other operator passed 4%, and the four big cloud DNS products (Google Cloud DNS, Route 53, NS1, Azure DNS) totalled 7.6%.

Source: TechnologyChecker · September 2026

DNS Hosting Market Share 2026: Cloudflare 15.4%, GoDaddy 14.2%
Nameserver operatorShare of live domains (%)
Cloudflare15.4%
GoDaddy14.2%
Google Cloud DNS3.7%
Wix3.6%
Hostinger3.3%
Parking/aftermarket3.3%
IONOS2.4%
Namecheap2.2%
AWS Route 531.9%
NS11.7%
OVHcloud1.5%
Azure DNS0.3%
  • Cloudflare and GoDaddy host DNS for 29.6% of live business domains between them
  • Route 53, NS1, Google Cloud DNS and Azure DNS add up to just 7.6%
  • Only 45% of domains that use Cloudflare somewhere also use Cloudflare nameservers

A third of live domains use nameservers outside the top 30, mostly local registrars and hosting companies. The part that surprised me is how small the big cloud DNS products are: Route 53, NS1, Google Cloud DNS and Azure DNS add up to 7.6%.

Parking and aftermarket nameservers get their own row because they're a real category, and an annoying one. 3.3% of domains that serve something also delegate DNS to a parking or domain-sale service. For anyone building a prospect list from domains, that bucket is noise worth filtering.

🚩
Red Flag: "Uses Cloudflare" and "uses Cloudflare DNS" are different claims. In our sample, 817 domains showed Cloudflare somewhere in their stack, but only 370 of them (45%) delegate nameservers to Cloudflare. The rest sit behind Cloudflare's network with DNS elsewhere. Amazon shows the same split: 46 of 84 AWS-using domains run Route 53.

For GoDaddy, where the nameserver and mail-exchanger patterns are unambiguous, we can go beyond the sample. GoDaddy DNS or GoDaddy email appears on 4,616,211 live domains, 15.2% of the 30.29 million in TechnologyChecker's index, and that detection matched the NS probe on 352 of 356 sampled domains. For scale, the Verisign Domain Name Industry Brief counts 401.6 million registered domains at the end of Q2 2026. Only about one in 13 of those runs a live business site we can detect. You can browse operators by footprint in our DNS and domain services category.

How are domains' email DNS records configured?

Google Workspace receives mail for 19.8% of live domains that publish an MX record, and Microsoft 365 for 16.4%. 21.4% of live business domains publish no MX record at all. Those shares come from the same 2,423-domain probe; 1,892 of the domains had an MX record.

Mail provider (by MX record) Share of domains with MX Share of all live domains
Google Workspace 19.8% 15.4%
Microsoft 365 16.4% 12.8%
Hostinger 2.7% 2.1%
IONOS 2.7% 2.1%
GoDaddy (Secureserver) 2.5% 1.9%
Zoho 1.6% 1.3%
Namecheap 1.4% 1.1%
OVHcloud 1.4% 1.1%
Proofpoint (gateway) 1.0% 0.7%
Mimecast (gateway) 0.5% 0.4%
Other and self-hosted 43.2% 33.8%

Across the full index, Microsoft 365 handles mail for 4,051,686 live domains (13.4%), a count that agreed with the sample probe on 307 of 311 domains. Google's full-index count runs low because Google's newer single-MX setup (smtp.google.com) isn't in every detection pattern yet, so the sample share above is the better guide to Google's lead.

Then the authentication records thin out fast:

  • SPF: 68.5% of live domains publish one (83.8% of those with MX). 24 domains in the sample publish two SPF records, which makes SPF evaluation fail outright.
  • DMARC: 39.3% publish a record. Of those, 64.4% are set to p=none, 19.9% to quarantine and 15.3% to reject.
  • Enforcement: only 13.9% of all live domains enforce DMARC with quarantine or reject, and 6.0% reject.

DNS Security Records 2026: 68.5% Publish SPF, 13.9% Enforce DMARC

Adoption of DNS-published security records among live business domains, measured by TechnologyChecker on a random sample of 2,423 resolving domains on 23 September 2026. 68.5% publish SPF and 39.3% publish DMARC, but only 13.9% enforce DMARC with quarantine or reject. 8.3% are DNSSEC-signed and 3.7% publish a CAA record.

Source: TechnologyChecker · September 2026

DNS Security Records 2026: 68.5% Publish SPF, 13.9% Enforce DMARC
DNS recordShare of live domains (%)
SPF record68.5%
DMARC record39.3%
DMARC enforced13.9%
DNSSEC signed8.3%
DMARC reject6%
CAA record3.7%
  • Two in three live domains publish SPF
  • Fewer than one in seven enforce DMARC; 64.4% of DMARC records are p=none
  • Only 8.3% of domains are DNSSEC-signed
🔑
Key Takeaway: Two in three live domains publish SPF, but fewer than one in seven enforce DMARC. Most DMARC records are in monitor-only mode, which reports spoofing without stopping it.

The message-level side of this, meaning how much delivered mail passes DMARC, is tracked in our DMARC adoption statistics.

Where does resolver traffic come from?

Mostly the US, then Brazil, Germany and Singapore, at 23.2%, 8.1%, 7.1% and 5.6% of queries to 1.1.1.1. Singapore more than doubled from 2.2% a year earlier. Brazil dropped 2.8 points.

Country shares hide a lot, though, and the network list shows what. The single largest source network is SpaceX Starlink at 8.97% of all queries, up from 7.67%. That's about seven times Comcast's 1.23%. Tencent's cloud (3.73%) is second, followed by DigitalOcean (2.07%), Hetzner (1.33%), Zenlayer (1.12%), OVH (1.04%), Vultr (1.03%) and Amazon (1.02%). A good share of public-resolver traffic comes from servers, not people, and a cloud region in Singapore shows up as Singaporean traffic.

By top-level domain, .com names account for 62.4% of queries and .net for 11.6%. Reverse lookups under .arpa are 4.3%. The fastest movers:

TLD 2026 window Same window 2025
.org 2.81% 2.44%
.ru 1.67% 1.08%
.io 1.61% 1.28%
.cn 1.38% 0.84%
.xyz 0.99% 0.33%

Radar also publishes a DNS Magnitude score, a 0 to 10 index of how many distinct networks query a TLD rather than how many queries it gets. .com scores 9.98, .net 9.89, .org 9.75 and .io 9.73. A TLD can have high reach and modest volume, so don't read magnitude as traffic share.

💡
Quick Insight: AS112 servers handled an average of 7.27 billion queries a day in the window, and 90.3% of them got NXDOMAIN. 81.8% were PTR lookups for private addresses that should never leave a local network. That's pure leakage, and it isn't shrinking: the latest full week was 4.7% above the same week a year earlier.

AS112 is a separate population entirely. Under RFC 7534, AS112 nodes act as a sink for reverse lookups of private address space and similar queries that shouldn't reach the public DNS. Cloudflare's AS112 data shows 44.1% of this traffic coming from the US, all of it over IPv4 and 99.96% over plain UDP. If your network leaks in-addr.arpa lookups for 10.x or 192.168.x addresses, some of this is yours.

How did DNS change month by month in 2026?

Most of 2026 was flat, and then August happened. Encrypted DNS, cache hits and AAAA lookups drifted up slowly, while NXDOMAIN and DNSSEC-validated answers jumped in a single month. Here's the calendar-month view from Cloudflare Radar, with 2025 alongside where Radar has it:

Month Encrypted (DoH + DoT) Encrypted, 2025 NXDOMAIN NXDOMAIN, 2025 SERVFAIL AAAA Cache hit DNSSEC secure IPv6 transport
Jan 11.8% 11.6% 11.1% 10.6% 2.7% 21.0% 79.1% 8.3% 9.6%
Feb 12.0% 11.4% 10.9% 10.4% 4.9% 20.1% 79.2% 8.0% 9.3%
Mar 11.6% 11.6% 10.2% 10.7% 3.4% 20.3% 78.4% 8.0% 9.7%
Apr 11.7% 11.4% 10.4% 10.9% 2.4% 20.4% 75.2% 8.1% 9.4%
May 11.7% 10.7% 9.9% 11.1% 2.1% 21.2% 76.3% 8.1% 9.5%
Jun 12.6% 10.7% 10.5% 11.3% 1.9% 21.8% 76.9% 8.1% 9.0%
Jul 13.3% 11.6% 10.8% 11.4% 2.3% 22.1% 80.9% 8.2% 9.3%
Aug 12.5% 11.9% 15.2% 11.4% 2.2% 20.6% 81.8% 11.8% 9.1%
Sep (1 to 22) 13.0% 12.0% 14.2% 10.9% 2.1% 21.0% 82.3% 10.7% 9.0%

Encrypted DNS by Month 2026: DoH and DoT Reach 13% of 1.1.1.1 Queries

Monthly share of queries to Cloudflare's 1.1.1.1 resolver that arrived encrypted (DNS over HTTPS plus DNS over TLS) in 2026. The share held near 11.6 to 12.0% from January to May, rose to 13.3% in July and was 13.0% for 1 to 22 September, against 10.7 to 12.0% in the same months of 2025.

Source: Cloudflare Radar · Jan-Sep 2026

Encrypted DNS by Month 2026: DoH and DoT Reach 13% of 1.1.1.1 Queries
MonthEncrypted share of queries (%)
Jan '2611.78%
Feb '2611.97%
Mar '2611.63%
Apr '2611.74%
May '2611.7%
Jun '2612.6%
Jul '2613.34%
Aug '2612.54%
Sep '26 (1-22)13%
  • Encrypted DNS rose from 11.8% in January to 13.0% in September 2026
  • Every 2026 month ran ahead of the same month in 2025
  • DNS over HTTPS passed DNS over TLS in September 2026 (6.7% vs 6.3%)

A few things stand out once you read down the columns:

  • NXDOMAIN stayed between 9.9% and 11.4% in every month of 2025 and the first seven months of 2026. August's 15.2% is the only break in 21 months, and Radar carries no annotation explaining it.
  • February's 4.9% SERVFAIL is an incident, not a trend. Radar flags an anomalous query flood over TCP on 11 to 13 February 2026, which is why I'd leave that month out of any SERVFAIL baseline.
  • Cache hits climbed from a 75.2% low in April to 82.3% in September. That's seven points in five months on a resolver this size, and it lines up in time with the shift in TTLs away from sub-minute answers described above.
  • AAAA share hovered around 20 to 22% all year, up from 16.8% in January 2025. IPv6 transport stayed near 9% throughout, so the software asking for IPv6 addresses is growing faster than the networks carrying IPv6.

The encryption story has a twist that a 12-month comparison hides. In January 2025, DoH was only 1.7% of queries and DoT 10.0%. The two swapped over in June and July 2025, when DoH jumped to 4.7% and DoT fell to 6.9%. The encrypted total barely moved, so this looks like the same clients switching protocol rather than new clients encrypting.

IPv6 DNS Lookups 2025-2026: AAAA Queries Grow From 16.8% to 21%

Monthly share of queries to Cloudflare's 1.1.1.1 resolver that asked for an IPv6 (AAAA) address. The share rose from 16.8% in January 2025 to 18.4% by September 2025 and ran between 20.1% and 22.1% through 2026, while IPv6 transport to the resolver stayed near 9%.

Source: Cloudflare Radar · Jan 2025-Sep 2026

IPv6 DNS Lookups 2025-2026: AAAA Queries Grow From 16.8% to 21%
MonthAAAA share of queries (%)
Jan '2516.82%
Feb '2517.04%
Mar '2517.14%
Apr '2517.35%
May '2517.63%
Jun '2518.08%
Jul '2518.55%
Aug '2518.41%
Sep '25 (1-22)18.39%
Oct '2520.11%
Nov '2521.06%
Dec '2521%
Jan '2621%
Feb '2620.11%
Mar '2620.32%
Apr '2620.41%
May '2621.19%
Jun '2621.82%
Jul '2622.14%
Aug '2620.64%
Sep '26 (1-22)20.97%
  • AAAA lookups went from 16.8% of queries in January 2025 to 22.1% in July 2026
  • IPv6 transport to 1.1.1.1 stayed near 9% over the same period
  • More software asks for IPv6 addresses than connects over IPv6

How do DNS statistics differ by country?

A lot more than the global averages suggest. NXDOMAIN ranges from 4.2% of Singapore's 1.1.1.1 responses to 49.9% of Ukraine's, and IPv6 transport from 0.3% in Singapore to 18.0% in Canada. The table covers the 20 countries sending the most queries to 1.1.1.1 over 27 August to 23 September 2026, plus South Korea and Turkey:

Country Share of queries NXDOMAIN SERVFAIL AAAA IPv6 transport DNSSEC-aware clients Cache hit Encrypted
United States 23.2% 16.9% 1.9% 21.9% 14.2% 7.3% 77.9% 8.2%
Brazil 8.1% 7.3% 3.4% 20.5% 12.6% 16.0% 89.1% 13.1%
Germany 7.1% 11.6% 2.1% 25.2% 5.0% 14.3% 79.5% 24.1%
Singapore 5.6% 4.2% 0.7% 37.3% 0.3% 2.0% 86.4% 2.6%
Netherlands 3.9% 10.3% 2.1% 27.6% 1.9% 11.2% 78.9% 23.7%
United Kingdom 2.8% 12.7% 1.5% 22.3% 9.0% 7.7% 82.7% 22.5%
Indonesia 2.4% 12.9% 3.7% 13.3% 3.6% 17.8% 87.9% 14.7%
France 2.2% 18.4% 2.1% 24.7% 7.5% 12.1% 71.8% 16.2%
Russia 1.9% 24.3% 5.5% 19.2% 0.5% 17.5% 83.3% 17.6%
China 1.9% 5.2% 1.1% 10.3% 2.3% 2.3% 87.4% 3.8%
Canada 1.9% 16.4% 1.4% 21.2% 18.0% 6.7% 79.2% 10.7%
Mexico 1.8% 13.6% 1.4% 15.3% 16.4% 6.0% 90.2% 10.1%
Argentina 1.7% 45.5% 2.0% 7.7% 2.9% 6.7% 92.3% 5.0%
Japan 1.6% 9.1% 2.3% 25.0% 5.7% 8.2% 84.0% 12.1%
Hong Kong 1.4% 11.0% 2.9% 33.0% 1.1% 5.9% 80.7% 7.7%
India 1.4% 11.8% 2.0% 20.4% 10.4% 26.3% 78.5% 28.5%
Australia 1.4% 12.9% 2.4% 14.5% 2.7% 12.1% 83.4% 10.2%
South Africa 1.4% 15.4% 1.9% 11.9% 7.6% 6.7% 87.3% 7.1%
Ukraine 1.3% 49.9% 1.3% 6.6% 4.3% 5.8% 91.5% 5.2%
Finland 1.2% 8.1% 1.1% 29.4% 3.1% 7.5% 79.3% 20.7%
Turkey 0.8% 21.7% 1.5% 13.3% 3.1% 9.8% 86.7% 16.5%
South Korea 0.5% 15.0% 4.1% 20.2% 8.8% 9.2% 82.5% 17.6%

NXDOMAIN Rate by Country 2026: Ukraine 49.9%, Singapore 4.2%

Share of DNS responses from Cloudflare's 1.1.1.1 resolver that returned NXDOMAIN (name does not exist), by client country, for 27 August to 23 September 2026. Ukraine (49.9%) and Argentina (45.5%) were far above the 14.5% global rate; Singapore (4.2%) and China (5.2%) were lowest.

Source: Cloudflare Radar · Aug-Sep 2026

NXDOMAIN Rate by Country 2026: Ukraine 49.9%, Singapore 4.2%
CountryNXDOMAIN share of responses (%)
Ukraine49.9%
Argentina45.4%
Russia24.3%
Turkey21.7%
France18.3%
United States16.9%
Canada16.4%
South Africa15.4%
South Korea14.9%
Mexico13.6%
Indonesia12.9%
Australia12.9%
United Kingdom12.7%
India11.8%
Germany11.6%
Hong Kong11%
Netherlands10.3%
Japan9.1%
Finland8.1%
Brazil7.3%
China5.2%
Singapore4.2%
  • Half of Ukraine's 1.1.1.1 answers were NXDOMAIN, against 14.5% globally
  • The US ran at 16.9%, above the global rate
  • Singapore and China, dominated by server traffic, were lowest at 4.2% and 5.2%

Ukraine and Argentina are the numbers I'd want explained before quoting them anywhere. Half of Ukraine's answers are NXDOMAIN, and both countries also have very high cache-hit ratios (91.5% and 92.3%) and very low AAAA shares. That combination usually means a small set of clients asking for the same non-existent names over and over, which caches well and says little about ordinary users. Russia's 24.3% NXDOMAIN comes with the highest SERVFAIL in the table (5.5%), and I'd expect filtering to be part of that picture.

Singapore, China and Hong Kong look like server traffic. Singapore sends 5.6% of all 1.1.1.1 queries, yet only 0.7% of its queries are HTTPS records, 2.0% come from DNSSEC-aware clients and 0.3% arrive over IPv6. Browsers ask for HTTPS records all the time, so a country where almost nothing does is mostly machines. It's the same pattern as the Tencent network above, and it's the likelier reason Singapore's share more than doubled in a year.

IPv6 DNS Traffic by Country 2026: Canada 18%, Russia Under 1%

Share of queries to Cloudflare's 1.1.1.1 resolver that arrived over IPv6 transport, by client country, for 27 August to 23 September 2026. Canada (18.0%), Mexico (16.4%) and the United States (14.2%) led; Singapore (0.3%) and Russia (0.5%) were lowest, against 9.0% globally.

Source: Cloudflare Radar · Aug-Sep 2026

IPv6 DNS Traffic by Country 2026: Canada 18%, Russia Under 1%
CountryIPv6 share of queries (%)
Canada18%
Mexico16.4%
United States14.2%
Brazil12.6%
India10.4%
United Kingdom9%
South Korea8.8%
South Africa7.6%
France7.5%
Japan5.7%
Germany5%
Ukraine4.3%
Indonesia3.6%
Finland3.1%
Turkey3.1%
Argentina2.9%
Australia2.7%
China2.3%
Netherlands1.9%
Hong Kong1.1%
Russia0.5%
Singapore0.3%
  • North America leads: Canada 18.0%, Mexico 16.4%, United States 14.2%
  • Most of Europe sits in single digits (Germany 5.0%, Netherlands 1.9%)
  • Singapore, at 0.3%, is almost entirely IPv4 server traffic

India stands out for DNSSEC-aware clients (26.3%, against 10.0% globally) as well as for DoT. North America leads on IPv6 transport: Canada 18.0%, Mexico 16.4% and the US 14.2%, while most of Europe sits in single digits.

⚠️
Common Mistake: Reading a country row as that country's internet. These are only queries that reach 1.1.1.1, and a country with lots of data centres (Singapore, the Netherlands) or one big enterprise user can dominate its own row. Radar also changed its IP geolocation provider in June 2025, so country comparisons that straddle that month need care.

How to benchmark your own DNS against these numbers

Put your resolver or zone counters next to the references below and look hard at anything far outside them. These are reference points taken from one very large public resolver, not service-level targets. A corporate resolver won't look like an ISP resolver, and neither looks like an authoritative server. That's fine.

Metric Internet-wide reference (2026) What a large deviation usually means
NXDOMAIN share 11 to 15% of responses (52-week average 11.5%) Well above: search-suffix appending, a misbehaving client, malware generating random names, or a retired hostname still in config
SERVFAIL share 2.1 to 2.9% Above: upstream authoritative outages, broken DNSSEC on a zone you query, resolver timeouts or resource limits
REFUSED share 0.1 to 0.6% Above: ACLs rejecting clients that shouldn't be using the resolver, or a resolver reachable from outside
Cache hit ratio 80 to 82% on a very large shared cache Much lower on a small resolver is normal. A sudden drop points at a cache flush, an eviction problem or a flood of unique names
Answers with TTL ≤ 1 minute 75% If your own zones sit here, ask whether each record needs failover-speed TTLs
Encrypted transport (DoH + DoT) 12.9% overall, 3.8 to 28.5% by country Near zero on a network with managed devices can mean OS-level DoT is blocked. A sudden rise can mean browsers bypassing your resolver
DNSSEC INVALID answers 0.06% Any bogus answers for your own zone is an outage for validating users. Check key rollovers and DS records
DNS response time (IQI) p25 33.8 ms, p50 56.5 ms, p75 94.2 ms Consistently above p75 from well-connected clients suggests a distant or overloaded resolver
ANY queries under 0.1% Anything visible deserves a look at the source

The response-time figures come from Cloudflare's Internet Quality Index, which estimates DNS response time from speed-test measurements. They describe what end users experience, not how fast 1.1.1.1 itself answers. The median went up 3.3 ms on the year while the 75th percentile improved by 2.6 ms, so the slowest quarter of users got slightly faster.

You probably have the counters already. Each of these pulls response codes and cache hits from a common resolver:

unbound-control stats_noreset | grep -E "total.num.queries|total.num.cachehits|num.answer.rcode"
rndc stats   # appends counters to named.stats in named's working directory
grep -E "NXDOMAIN|SERVFAIL|queries resulted" named.stats
curl -s http://localhost:9153/metrics | grep -E "coredns_dns_responses_total|coredns_cache_(hits|misses)_total"
Get-DnsServerStatistics -ComputerName "dns01"

Managed DNS (Route 53, Cloudflare, Google Cloud DNS) exposes the same numbers through query logging or the provider's analytics view.

Then compare them in four steps:

Pull a week of counters

Take at least seven days so weekday and weekend traffic both count, and note any incident in the window.

Convert counts to shares

Divide NXDOMAIN, SERVFAIL and REFUSED by total responses, and cache hits by total queries. A traffic spike raises every count, but only a real fault moves the ratios.

Compare with the reference column

Use the table above. Expect a small office resolver to sit lower on cache hits and higher on NXDOMAIN than 1.1.1.1.

Chase the biggest outlier first

Group the outlying response code by client and by queried name. One device or one suffix is usually behind most of it.

Methodology

Resolver data (Cloudflare Radar). All traffic, response, caching, encryption, DNSSEC, country, network and TLD figures describe queries received by Cloudflare's 1.1.1.1 public resolver. We pulled them from the Radar API on 23 September 2026 for the window 27 August to 23 September 2026 (27 days), because Radar's standard 28-day preset returned errors on DNS endpoints that day. Year-on-year comparisons use the same calendar dates in 2025. Trailing figures cover the 52 weeks to 21 September 2026. That period contains seven Radar-flagged DNS events, including request floods and the 18 November 2025 Cloudflare service degradation. Radar's weekly query-volume index sits near its 52-week high, but floods fall inside that period, so this page makes no claim about overall DNS growth.

Monthly, country and network breakdowns. Monthly figures are calendar-month summaries from the same Radar endpoints (September covers 1 to 22 September in both years). Country and network figures use the 27 August to 23 September 2026 window, filtered by Radar's location and ASN parameters. Radar annotations in the period: an anomalous TCP query flood on 11 to 13 February 2026, and an IP geolocation provider change on 4 June 2025.

AS112 and IQI. AS112 figures cover the AS112 nodes Cloudflare observes, not the global AS112 system. IQI response times are Cloudflare's end-user quality estimates.

Domain data (TechnologyChecker). Our index held 30,287,857 live business domains on 23 September 2026. For the nameserver, MX, SPF, DMARC, DNSSEC and CAA figures, we drew a deterministic random sample of 2,567 of them and resolved NS, MX, apex TXT, _dmarc TXT, DS and CAA records the same day. We excluded 85 domains that returned NXDOMAIN or SERVFAIL and 38 platform subdomains (sites on shared hosting domains), leaving 2,423 resolving domains. Margins at 95% confidence are about ±1.4 points at 15%, ±1.1 at 8% and ±0.8 at 4%. Full-index counts appear only where a detection pattern agreed with the probe on nearly every sampled domain (GoDaddy and Microsoft 365).

How was the 2,423-domain sample drawn?

We took a deterministic hash sample of 2,567 domains from the 30,287,857 live domains in our index, so the same draw can be repeated. On 23 September 2026 we resolved NS, MX, apex TXT, _dmarc TXT, DS and CAA records for each one through 1.1.1.1. We dropped 85 domains that returned NXDOMAIN or SERVFAIL and 38 platform subdomains on shared hosting domains, which left 2,423. Our crawler reads apex NS, MX and TXT records on every sweep but does not query _dmarc, DS or CAA, so the DMARC, DNSSEC and CAA figures exist only from this probe.

Limits. One resolver is not the internet: as the network table shows, a large share of 1.1.1.1's traffic comes from satellite and cloud networks, so its mix differs from an ISP resolver's. Our sample covers domains running a detectable website, not all registered domains. Provider shares from the sample carry the margins shown and shouldn't be read to the decimal.

Frequently asked questions

What are some examples of DNS statistics?

Common examples include the query-type mix (65% A, 21% AAAA at 1.1.1.1), response codes (NXDOMAIN, SERVFAIL), cache hit ratio, answer TTLs, encrypted-transport share, DNSSEC validation rates and nameserver market share. Operators also track queries per second and response latency on their own servers.

What are the four most common types of DNS records?

By resolver query volume in 2026, the four most requested types are A (IPv4 address), AAAA (IPv6 address), HTTPS (service binding for HTTP/3 and connection hints) and PTR (reverse lookup). By what domains configure, NS, MX, TXT and CNAME are the everyday records alongside A and AAAA.

What is a good DNS response time?

Cloudflare's Internet Quality Index puts the median DNS response time for end users at 56.5 ms, with the fastest quarter under 34 ms and the slowest quarter above 94 ms. A cached answer from a nearby resolver usually arrives in single-digit milliseconds; uncached lookups that go to distant authoritative servers take longer.

What is a typical DNS cache hit ratio?

A very large shared resolver answers about 80 to 82% of queries from cache. Smaller resolvers serving one office or company typically see lower ratios because fewer clients repeat the same names. Low TTLs cap the ratio too, since three-quarters of answers expire within a minute.

How common are DNS lookup failures in 2026?

At 1.1.1.1, 2.1% of responses were SERVFAIL and 14.5% NXDOMAIN in the 27 days to 23 September 2026, a window inflated by an August NXDOMAIN surge (the 52-week average is 11.5%). SERVFAIL is closer to a true failure rate. Most NXDOMAIN answers are software asking for names that don't exist rather than users hitting broken sites.

What share of DNS queries use DoH or DoT encryption?

12.9% of queries to 1.1.1.1 were encrypted in September 2026: 6.5% DNS over HTTPS and 6.3% DNS over TLS. Encrypted share ranges from 3.8% in China to 28.5% in India among the large countries we checked.

What does a DNS test check?

A DNS test usually checks whether a name resolves, which nameservers answer, how long the answer takes, which records are published (A, MX, TXT) and whether DNSSEC validates. Speed tests compare resolver latency; configuration tests look for missing SPF or DMARC, lame delegations and mismatched nameservers.

How do I view my DNS records?

Run dig example.com NS, dig example.com MX or dig TXT _dmarc.example.com on macOS or Linux, or nslookup -type=MX example.com on Windows. Your DNS provider's dashboard shows the full zone. To see which DNS, email and hosting providers any domain uses, look it up on TechnologyChecker.

Which public DNS resolver is fastest in 2026?

It depends on where you are. Resolver speed is dominated by the distance to the nearest server and by whether the answer is cached, so rankings change between cities and networks. Test from your own location over several days rather than trusting a single global ranking.

How do DNS failure rates affect SaaS application uptime?

Every API call and page load starts with a lookup, so a SERVFAIL on your domain looks like an outage to the user even when your servers are fine. Monitor resolution of your own hostnames from several external resolvers, keep TTLs long enough to ride out a short authoritative outage, and use more than one DNS provider for critical zones.

Update history

First editionDataMethod

First publication. Cloudflare Radar resolver data for 27 August to 23 September 2026 against the same dates in 2025, calendar months from January 2025, 22 countries and 7 source networks, plus TechnologyChecker's DNS probe of 2,423 live domains. The NXDOMAIN rate in this window is lifted by an August 2026 spike; the next update will show whether it settles back near 11%.