Daily DNS measurement

Adoption is not compliance

Tracking HTTPS records across a fixed web cohort, whether observed records are valid and usable, and which optional connection features they advertise. Generic SVCB is measured only for explicitly mapped services.

Latest observation: Loading…

HTTPS names observed
Loading
Valid RRsets
Loading
H3 ALPN advertised
Loading
Cohort domains
Loading
What this measures

Service discovery signals in DNS

RFC 9460 defines SVCB and HTTPS resource records. Sites can use them to advertise endpoints, ALPN identifiers such as h3, address hints, ports, and ECH configuration.

Publishing either record is optional. A site without one is not “non-compliant,” and a DNS advertisement does not prove that a client can complete the advertised TLS or HTTP behavior.

Three separate questions

  • Was a record observed?
  • Is its syntax and parameter combination valid?
  • Which optional features does it advertise?
Current snapshot

Record adoption and features

HTTPS records by queried name

The denominator is queried HTTPS names. Legacy SVCB rows never dilute this metric.

Apex names
www names
Generic SVCB
Not measured for this web cohort

Optional features in usable service records

Counts and percentages use the feature-specific denominator reported by the dataset.

Adoption over time

Legacy aggregate points are retained but marked separately from detailed schema-v2 scans.

RFC interpretation

Validity and client usability

Classification

Valid but incompatible means the RRset can be valid while requiring a mandatory parameter that this scanner/client does not implement. Absence and DNS query failures are reported separately from RFC validity.

Since the previous detailed scan

Recent changes

Loading comparison data…

ChangeNameTypeSummary
Loading…
Inspect the evidence

Domain observations

Each row comes from the current snapshot. Open a row to inspect the complete retained RRset, raw presentation text, resolver provenance, and validation findings.

Domain / queried nameRecordResolverObservationFeaturesDetails
Loading…
How to read these results

Measurement boundaries

  • Adoption: whether the configured resolver returned an HTTPS RRset for an apex or www cohort name; SVCB is queried only with an explicit service mapping.
  • Validity: structural and semantic checks over the complete observed RRset, including AliasMode, ServiceMode, mandatory parameters, ALPN rules, and alias loops.
  • Feature advertising: parameters in usable ServiceMode records. It is evidence of DNS configuration, not proof that the endpoint behavior succeeds.
  • Historical continuity: older reports provide aggregate trends only. Detailed per-name comparisons begin with schema v2.
Full methodology
Roadmap

TLS and HTTP signals through 2028

The next measurement layer will use separate, versioned active probes for ECH behavior, hybrid ML-KEM TLS key agreement, and evolving TLS and HTTP response signals.

Important: DNS alone cannot prove ECH use, TLS negotiation, post-quantum cryptography, or HTTP header behavior. Those observations will remain distinct from RFC 9460 DNS results.