---
title: "How does Lemwatch detect DNS record changes? — Lemwatch Help"
description: "Lemwatch resolves your A, AAAA, MX, NS, CNAME, and TXT records on every check and hashes them — any hash change triggers a DNS change incident."
canonical: "https://lemwatch.com/help/dns-change-monitoring"
source: "https://lemwatch.com"
---

# How does Lemwatch detect DNS record changes?

> Lemwatch resolves your A, AAAA, MX, NS, CNAME, and TXT records on every check and hashes them — any hash change triggers a DNS change incident.

## Quick answer

 Every scheduled check resolves A, AAAA, MX, NS, CNAME, and TXT records, sorts them, and stores a hash. When the hash changes we log the diff and open a DNS change incident.

## Why this matters

- Nameserver hijacks are silent and catastrophic

- MX record edits break email delivery for days

- Rogue TXT records signal domain-shadowing attacks

- CNAME flips point traffic at attacker infrastructure

## Where to find it in Lemwatch

 **Site → DNS** — history + latest snapshot.

## FAQ

### Do you check all resolvers?

 We query multiple resolvers (Google + Cloudflare) and flag disagreements.

## Related

- Change detection

- SSL expiry tracking


## Related

- [Help centre](https://lemwatch.com/help)
- [Change Detection & Volatility Alerts](https://lemwatch.com/help/change-detection)
- [How does Lemwatch track SSL certificate expiry?](https://lemwatch.com/help/ssl-expiry-tracking)
- [How does Lemwatch detect WordPress plugins and themes?](https://lemwatch.com/help/wordpress-fingerprinting)
- [Lemwatch pricing](https://lemwatch.com/pricing)
- [DNS CNAME change check](https://lemwatch.com/help/dns-cname-change-check)
- [DNS A record change check](https://lemwatch.com/help/dns-a-record-change-check)
