What this tool checks
A short-lived random hostname is requested by the browser. NekoIP’s authoritative DNS records the recursive resolver that reached it and returns NXDOMAIN, so no web or TLS connection to the probe host is required.
See the recursive resolver addresses that actually reach NekoIP’s authoritative test zone.
Queries are sent from NekoIP infrastructure. The target website is not contacted.
A short-lived random hostname is requested by the browser. NekoIP’s authoritative DNS records the recursive resolver that reached it and returns NXDOMAIN, so no web or TLS connection to the probe host is required.
The result may show your ISP, router, VPN or encrypted-DNS provider rather than your public IP. Several addresses can be normal when a resolver pool or IPv4 and IPv6 paths are used.
Blocking port 53, missing NS delegation, an expired session or DNS filtering can produce no observation. Wildcard A/AAAA and TLS certificates are neither required nor used.