The delegation could not be checked
What this check looks for
We could not reach your nameservers directly, so none of the delegation checks ran. This says nothing about your zone — only that we could not look.
Why it matters
A checker that shows nothing and a checker that shows nothing wrong look identical unless it says which one happened. This finding exists so they never can be confused.
What it costs your score
This check never deducts. It reports a fact — or reports that something could not be verified — and is shown on the report without moving the score.
- Severity
- info
- Default confidence
- confirmed
- Status when triggered
- info
- Deduction
- 0 points
- Family cap
- none
- Category
- DNS
- Module
- Dns health
- Fix owned by
- user
- In the ruleset since
- 2026.09
Technical detail
The delegation walk did not complete: ‹reason›. Checking a delegation needs queries sent to *chosen* nameservers with recursion disabled, which is only possible from the probe host (docs/22 §2.1). With that unavailable, every check in this module is skipped rather than assumed to pass. Re-run the scan; if it persists, this is a fault on our side and not on yours.
Standards and references
Test this on your domain
Run the check that produces this finding, on its own, against any domain.
Other dns health checks
- A name has a CNAME alongside other records
- A glue record's address does not match the nameserver's own
- A nameserver inside the domain has no glue record
- A nameserver you delegate to does not answer for the zone
- The domain has fewer than two nameservers
- A nameserver name is an alias rather than a host
- The registry and the zone disagree about the nameservers
- All nameservers resolve to one address
- All nameservers sit in one network block
- A nameserver name has no address
- A nameserver answers queries for domains that are not yours
- Your nameservers are serving different versions of the zone