Analysis Statistics
Platform telemetry — DNS intelligence operations, query distribution, and global reach
RFC-aligned confidence scoring across 9 protocol domains. NIST SP 800-53 SI-7 & ICD 203 source evaluation framework with SHA-3-512 provenance.
Global Reach
Most Analyzed Domains
- 1. nlnetlabs.nl 1261
- 2. ietf.org 664
- 3. google.com 490
- 4. it-help.tech 434
- 5. freebsd.org 360
- 6. apple.com 330
- 7. cia.gov 242
- 8. dnstool.it-help.tech 222
- 9. red.com 222
- 10. github.com 198
Top Domains — Plugin
Scans run through the DEVONagent Pro plugin (or any client passing ?src=agent). Counted on its own so plugin usage never inflates the human, verified-bot, or investigate totals.
- 1. replit.com 38
- 2. apple.com 36
- 3. red.com 30
- 4. agentquery 12
- 5. it-help.tech 9
- 6. cia.gov 8
- 7. google.com 8
- 8. devontechnologies.com 8
- 9. blue.com 6
- 10. zoho.com 3
Top Domains — Human
Browser-driven sessions only. Excludes plugin scans, verified bots, investigate traffic, and security-tool scans.
- 1. it-help.tech 26
- 2. johnsoncustombuilders.com 25
- 3. apple.com 16
- 4. inmanindustrial.com 15
- 5. google.com 13
- 6. owccgb.org 12
- 7. nsa.gov 12
- 8. cia.gov 11
- 9. deeptiesfishing.com 11
- 10. nlnetlabs.nl 11
Top Domains — Verified Bots
UA + reverse-DNS verified operators (Googlebot, GPTBot, ClaudeBot, etc.).
- 1. caolt.ro 1
- 2. devontechnologies.com 1
- 3. dpsg-bodensee.de 1
- 4. g-my.com 1
- 5. innbn-bucuresti.ro 1
- 6. spitalpoianamare.ro 1
- 7. zmacnashville.net 1
Top Domains — Investigate
Claimed-bot UAs that failed verification, plus generic non-browser clients (curl, python-requests, headless).
- 1. proton.me 6
- 2. nlnetlabs.nl 5
- 3. example.com 5
- 4. johnsoncustombuilders.com 4
- 5. ietf.org 4
- 6. dns-evil-flicker.com 4
- 7. it-help.tech 4
- 8. mailbox.org 4
- 9. google.com 4
- 10. apple.com 3
Recent Daily Activity
| Date | Total | Success | Failed | Unique | Avg Time |
|---|---|---|---|---|---|
| 08/23 | 7 | 7 | 0 | 0 | 59.52s |
| 08/22 | 18 | 18 | 0 | 0 | 55.09s |
| 08/21 | 12 | 12 | 0 | 0 | 21.24s |
| 08/19 | 1 | 1 | 0 | 0 | 62.51s |
| 08/18 | 45 | 45 | 0 | 0 | 14.25s |
| 08/17 | 25 | 25 | 0 | 0 | 51.46s |
| 08/16 | 17 | 17 | 0 | 0 | 49.76s |
Operational Insights
Epistemic Disclosure Events
Epistemic Disclosure Events (EDEs) document instances where the Confidence Engine’s scoring model, evidence weighting, or detection logic required structural correction. This is not an error log — it is a formalized record of model self-correction, inspired by scientific corrigenda culture and high-reliability engineering practice (NASA anomaly reporting, medical adverse event systems). Each EDE informs a confidence recalibration review across affected protocols.
EDEs are maintained as a permanent, append-only record — entries are never deleted or silently revised. All analysis outputs are SHA-3-512 hashed at export, providing tamper-evident snapshots of the scoring state at each point in time. Protocols affected by an EDE undergo recalibration through the ICIE/ICAE pipeline before updated scores are published.
We use two cookies, both essential:
_csrf— Prevents cross-site request forgery. Required for form submissions. Security-only._dns_session— Only exists if you choose to sign in. No account required to use DNS Tool.
We log your IP address for two reasons: rate limiting (so nobody abuses the service) and security (identifying malicious actors and complying with legal obligations). We check source geography for analysis accuracy — DNS responses vary by region, and knowing which resolver answered from where makes the science better.
No tracking cookies. No analytics cookies. No ad networks. No data brokers. Our code is open-core — the application framework is publicly available under BUSL-1.1 with timed Apache-2.0 conversion. Verify it yourself.
Public analyses are archived by a third party. When a scan is not marked private or run as /dev/null, its report URL is submitted to the Internet Archive, which creates a permanent public record outside our control. That is deliberate — it gives every published analysis tamper-evident provenance independent of us — but it is not reversible, so it is stated here before you scan rather than after.
If you create an account and want out, account deletion removes your login and scan history. Public domain analyses remain available because they contain only public DNS records, already hashed. Full details: Privacy Policy.
