Nameserver checks
How DomainCare watches your domain's registrar delegation and alerts the moment your nameservers change.
Nameserver checks
DomainCare reads your domain's nameserver delegation from the registry — the same authoritative record your registrar publishes — and alerts the moment it changes. A nameserver change you didn't make is one of the strongest hijack signals a domain can produce; a change you did make is worth a confirmation either way.
What it monitors
- Registrar delegation — the exact nameserver set the registry reports for your domain (normalized, so case and trailing-dot differences never count as changes)
- Delegation changes — any difference from the previously observed set alerts immediately; registry data is stable, so there's no need to wait for a confirming re-check
- Registry reachability — if the registry data source stops answering across consecutive checks, you get a low-priority note (that's registrar-side maintenance or rate-limiting, not a problem with your domain)
How often it runs
The nameserver check runs every 12 hours (43,200 seconds), aligned with the registry check — the two share a single registry query per cycle, halving DomainCare's footprint against registrar rate limits.
A registry timeout is not a state. If the registry can't be queried, that run is marked unavailable and nothing alerts. A change that happens during such a gap is still caught: the next successful read compares against the last known delegation, so a real move alerts and an unchanged set stays silent.
Alerts this check produces
| Event | Tone | When it fires |
|---|---|---|
nameservers_changed | Warning | The registry reports a different nameserver set than the last known one. Fires immediately on first detection; the check returns to valid on the next run if the new set holds |
registrar_timeout | Info | The registry data source failed to answer on two consecutive checks. Fires once per outage, digest-only |
What to do when alerts fire
-
nameservers_changed— and you made the change. Nothing to do; this is your confirmation the delegation landed at the registry. The check shows "needs attention" for one cycle and returns to valid on its own. -
nameservers_changed— and you didn't. Treat it as urgent. An unauthorized delegation change points every service on your domain (web, email, everything) at infrastructure you don't control. Log in to your registrar immediately, check the account's recent activity, re-secure it (password + 2FA), and revert the delegation. -
registrar_timeout. Usually nothing — registry endpoints rate-limit and have maintenance windows. Change detection resumes automatically once it answers. If it persists for days, check whether your TLD's registry is having a wider incident. -
After making changes, delegation updates at the registry are typically visible within minutes to hours. DNS resolvers may serve the old nameservers until their cached delegation expires (up to 48 hours), which is normal.
Related
Know the moment your nameservers change
DomainCare watches your registrar delegation and alerts immediately on any change — the strongest early signal of a domain hijack.
Start free trial