What this tool checks
NekoIP asks its validating recursive resolver for the selected RR type. It reports rcode, TTL, DNSSEC AD, UDP truncation and TCP retry. The All mode checks the eight common types A, AAAA, CNAME, MX, TXT, NS, SOA and CAA with explicit cached queries; it never sends DNS ANY.
How to read the result
NOERROR with zero records means the name exists without that type; NXDOMAIN means the owner name does not exist. Record count covers the requested type, while CNAME answers and RRSIG signatures are displayed separately.
Common problems
An AD flag confirms validation by this resolver, not that every client validates DNSSEC. Cached and stale labels matter when comparing a recent DNS change, and TLSA normally belongs below a port and transport owner name.