DNS lookup
Examples:
Transparency
A browser cannot query the DNS directly. Your browser therefore asks a public DNS resolver, the one you choose among four, over HTTPS (DNS over HTTPS). The server of r-no.fr is not involved: it never sees the name you look up.
- What the resolver sees
- Each lookup sends to the chosen resolver, and to it alone, the name and the record type, one request per type (eight for “Common records”). Like any website, the resolver receives your IP address with these requests, and learns that they come from r-no.fr (the
Originheader, which browsers send and pages cannot remove). No cookie is sent. - The four resolvers
-
- DNS4EU, European Union: a project co-funded by the EU, run by Whalebone (Czech Republic), unfiltered version
unfiltered.joindns4.eu. Its commitments. - Quad9, Switzerland: a Swiss foundation, version without block list
dns10.quad9.net. Its commitments. - Cloudflare, United States:
cloudflare-dns.com. Its commitments. - Google Public DNS, United States:
dns.google. Its commitments.
Access-Control-Allow-Originheader). On 28 September 2026, no French public resolver allowed it (FDN, Aquilenet, La Contre-Voie…): they will be added if that changes. - DNS4EU, European Union: a project co-funded by the EU, run by Whalebone (Czech Republic), unfiltered version
- Enforced by your browser
- This page's Content Security Policy allows the four resolvers:
https://unfiltered.joindns4.eu,https://dns10.quad9.net,https://cloudflare-dns.comandhttps://dns.google. No form submission (form-action 'none'). One more destination is allowed, as on every page of the site:https://stats.r-no.fr, the audience measurement (see below). You can read the policy at the top of the page source. - Audience measurement
- Like every page of the site, this one counts its visit with Umami, installed on R-no’s own server (
stats.r-no.fr). It receives the address of the page, without parameters or anchor, the site you came from (its domain only), your browser, system, language and screen size, and the country, region and city deduced from your IP address, which is not kept. It never receives what you type, nor the result of the tool. No cookie, nothing stored in your browser; if your browser asks not to be tracked (Do Not Track), nothing is measured. The data is erased after 25 months.- /commun/mesure.js: the filter applied before each sending, written for R-no Toolbox. 1.4 kB
SHA-256225eec74fd12623d82fc05ee7d222be629ce454d081c129e8d1e249ed37ee716 - https://stats.r-no.fr/m.js: Umami’s tracker, open source (MIT), served by the measurement server. Its fingerprint is not shown here: it changes with each version of Umami, and you cannot check from your browser that it is the published code. For that part, you have to trust R-no.
- /commun/mesure.js: the filter applied before each sending, written for R-no Toolbox. 1.4 kB
- What is never sent
- Names reserved for local networks (
.local,.lan,.home.arpa,.internal,.test…) and names without a dot (nas,printer) are recognised in your browser and never sent: public DNS does not know them, and they describe a private network. An IP address is not sent either: the page points to ip/reverse. - Guardrail
- This page makes at most 20 lookups per minute. The requests leave from your address, not from the server, but they carry the r-no.fr origin: the limit keeps r-no.fr welcome at the resolvers.
- What is stored
- No cookie, and nothing in the address of this page: a lookup cannot be found in the server's logs. What you type is not kept. Your language is given by the address itself (
/en/or/fr/): nothing is stored to remember it. Like any website, the server records the download of the page and its files in its access logs (IP address, date and time, address requested, browser name). - Code that runs here
-
- app.js: checks the name, asks the chosen resolver, and shows the answers as a list or as dig would. Written for R-no Toolbox, not minified, no third-party library. 18.4 kB
SHA-256fb18f2c7e222deea5c52dd31061fd19e4d93d2dabb6ba01254c90516000cfb2f - /commun/doh.js: the DNS over HTTPS format (RFC 8484), shared with ip/reverse: it writes the question as a DNS packet, reads the binary answer, and holds the list of the four resolvers. It makes no request itself. Written for R-no Toolbox, not minified, no third-party library. 16.5 kB
SHA-25688afaa695a1c2b3212d3cc449b81add7736a6756d96213ecd5771cddc09129a1 - textes.js: the French messages of the tool, shown by its script (the rest of the French page is written into its HTML when the site is built). It only defines texts, with no logic. 9.8 kB
SHA-256b7740bde0b585f8979eaaef3331f9029d4db21d85c7ecdac96eecda406df2927 - /commun/langue.js: the language helper, the same on every page of the site. It reads the language of the page and gives the tool its messages in that language. It stores nothing. 1.6 kB
SHA-25680f76f69773ef628d36d09bf8387cfedebda4529210d7120649b6f5603310631
- app.js: checks the name, asks the chosen resolver, and shows the answers as a list or as dig would. Written for R-no Toolbox, not minified, no third-party library. 18.4 kB
- Tested
- The reading of names (accents, reserved names, pasted links), the writing of questions, the reading of binary DNS answers (real answers recorded from the four resolvers) and the dig output are covered by automated tests, run on every deployment.
- Check it yourself
- Download the script and compare its fingerprint with the one above:
curl -s https://r-no.fr/domains/dns/app.js | shasum -a 256 - Limits
-
- You see what a public resolver sees, not what your own network sees: no internal DNS, no answer specific to your company or your internet provider.
- A choice among four public resolvers, not any server (dig's
@server): the page can only talk HTTPS to the destinations its policy names. So no direct question to a domain's own servers, no+trace, no zone transfer. - The TTL shown is the time left in the chosen resolver's cache, not the value set in the zone.
- Sites behind a CDN may give a different address to the resolver than to you: the answer is computed for the resolver's location. Comparing two resolvers shows it.
ANYis not offered: resolvers no longer answer it (RFC 8482). “Common records” asks each type instead.