DNS NS record check
Alerts when authoritative nameservers change — the fastest warning of a domain hijack or unauthorised registrar transfer.
Quick answer
Lemwatch tracks the authoritative NS set at the registry (via the parent zone) and alerts on any change — always severity: critical.
What it checks
- NS records from the TLD registry, not the child zone (harder to spoof)
- Sorted-set hash of nameserver hosts
- DNSSEC DS record presence
- Registrar of record (via RDAP)
Where to find it in Lemwatch
Site details → Health → DNS tab.
How to respond
- Log into your registrar and check the audit trail.
- If the change is unauthorised, lock the domain and contact your registrar.
- If planned, acknowledge the alert.
- Consider enabling registrar lock (clientTransferProhibited).
FAQ
Why is this severity always critical?
NS changes usually mean either a planned migration or an active hijack — both need eyes-on.
Does DNSSEC help?
Yes — Lemwatch also alerts if DS records disappear.
Related