{"_id":"@bobfromarcher/dnsward","name":"@bobfromarcher/dnsward","dist-tags":{"latest":"1.0.0"},"versions":{"1.0.0":{"name":"@bobfromarcher/dnsward","publishConfig":{"access":"public"},"version":"1.0.0","description":"Audit the DNS health of a domain: A/AAAA, NS count and diversity, SOA timer sanity (RFC 1912), CAA, apex CNAME, TTL, and DNSSEC. Scored, with fixes. Zero dependencies.","bin":{"dnsward":"bin/dnsward.js"},"main":"bin/dnsward.js","scripts":{"test":"node test/test.js","start":"node bin/dnsward.js"},"keywords":["dns","dnssec","soa","ns","caa","ttl","health","audit","domain","infrastructure","cli","zero-dependency","devtools"],"author":{"name":"bobfromarcher"},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/bobfromarcher/dnsward.git"},"bugs":{"url":"https://github.com/bobfromarcher/dnsward/issues"},"homepage":"https://github.com/bobfromarcher/dnsward#readme","engines":{"node":">=16"},"gitHead":"107ac1691c002537333d72aa4aa4dde4b4c1374e","_id":"@bobfromarcher/dnsward@1.0.0","_nodeVersion":"24.14.1","_npmVersion":"11.11.0","dist":{"integrity":"sha512-ALRUUeUKx47+gcl8r3PEGXH5k+QcbcfDkT7fFd5gFrR4KFaau/CjYwTApFENi7RaVzbmpx3mh7kPk8K9resgfg==","shasum":"e016847fe84b75ee2980d48e5a7d024387068dd2","tarball":"https://registry.npmjs.org/@bobfromarcher/dnsward/-/dnsward-1.0.0.tgz","fileCount":4,"unpackedSize":17103,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQCpmsWKnGUJ2cQ1u0dLxuSbh7f0smEuSj79wTakfvEHiQIgAcd30fgAWnyzbcU4e/vk77+uShE4B8+3ccKWuzoV3Z0="}]},"_npmUser":{"name":"bobfromarcher","email":"chrisbellth@gmail.com"},"directories":{},"maintainers":[{"name":"bobfromarcher","email":"chrisbellth@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/dnsward_1.0.0_1781951758763_0.2616254416171555"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-20T10:35:58.520Z","1.0.0":"2026-06-20T10:35:58.900Z","modified":"2026-06-20T10:35:59.248Z"},"maintainers":[{"name":"bobfromarcher","email":"chrisbellth@gmail.com"}],"description":"Audit the DNS health of a domain: A/AAAA, NS count and diversity, SOA timer sanity (RFC 1912), CAA, apex CNAME, TTL, and DNSSEC. Scored, with fixes. Zero dependencies.","homepage":"https://github.com/bobfromarcher/dnsward#readme","keywords":["dns","dnssec","soa","ns","caa","ttl","health","audit","domain","infrastructure","cli","zero-dependency","devtools"],"repository":{"type":"git","url":"git+https://github.com/bobfromarcher/dnsward.git"},"author":{"name":"bobfromarcher"},"bugs":{"url":"https://github.com/bobfromarcher/dnsward/issues"},"license":"MIT","readme":"# dnsward\n\n[![npm](https://img.shields.io/npm/v/@bobfromarcher/dnsward?color=cb3837&logo=npm)](https://www.npmjs.com/package/@bobfromarcher/dnsward)\n[![CI](https://github.com/bobfromarcher/dnsward/actions/workflows/ci.yml/badge.svg)](https://github.com/bobfromarcher/dnsward/actions/workflows/ci.yml)\n[![license](https://img.shields.io/npm/l/@bobfromarcher/dnsward?color=blue)](LICENSE)\n[![zero deps](https://img.shields.io/badge/dependencies-0-success)](package.json)\n\nAudits the DNS health of a domain. It queries live DNS and checks the address records, nameserver count and diversity, SOA timers against RFC 1912, CAA, apex CNAME misconfiguration, TTL sanity, and DNSSEC, then scores the domain from 0 to 100 with a letter grade and specific fixes. No dependencies, no AI. The result is the same every time because it reads real DNS.\n\ndnsward is the infrastructure companion to [mailward](https://github.com/bobfromarcher/mailward): mailward covers email authentication, dnsward covers the zone itself.\n\n<p align=\"center\"><img src=\"demo.svg\" alt=\"dnsward auditing a domain\" width=\"560\"></p>\n\n## Install\n\n```bash\nnpm install -g @bobfromarcher/dnsward\n# or once:\nnpx @bobfromarcher/dnsward example.com\n```\n\n## Usage\n\n```bash\ndnsward <domain> [options]\n```\n\n| Option | Description |\n| --- | --- |\n| `--timeout <ms>` | DNS query timeout (default 5000) |\n| `--json` | Output JSON |\n| `--quiet`, `-q` | No output, exit code only |\n| `-h, --help` | Show help |\n| `-v, --version` | Show version |\n\nThe exit code is 0 for grade A or B and 1 for C or worse, so it gates a deploy or a monitoring job.\n\n## What it checks\n\n- **Address**: the apex resolves over A or AAAA.\n- **Apex CNAME**: a CNAME at the zone apex is invalid and breaks NS, SOA and MX. dnsward flags it.\n- **www**: the www name resolves, by A record or CNAME.\n- **Nameservers**: at least two, and whether they sit on more than one zone. A single nameserver, or all of them at one provider, is a single point of failure.\n- **SOA**: present, with refresh, retry, expire and minimum timers checked against the RFC 1912 ranges, including the common mistake of retry being larger than refresh.\n- **CAA**: present, so only the certificate authorities you choose can issue for the domain.\n- **TTL**: the apex record TTL is neither so low it is fragile nor so high it is slow to change.\n- **DNSSEC**: whether the zone is signed. This uses a direct DNSKEY query and degrades to \"not checked\" if the resolver does not answer.\n\n## As a library\n\n```js\nconst { audit } = require('@bobfromarcher/dnsward');\n\nconst report = await audit('example.com');\nconsole.log(report.grade, report.score);\nfor (const check of report.checks) {\n  if (check.status === 'fail' || check.status === 'warn') console.log(check.title, check.fix);\n}\n```\n\n`audit(domain, opts)` accepts an injected `resolver` and a `dnssec` override, which makes it testable without touching the network.\n\n## Examples\n\n```bash\ndnsward cloudflare.com\ndnsward example.com --json | jq '.grade'\n```\n\n## Notes\n\ndnsward reports on the public DNS of a zone. It does not check internal or split-horizon DNS, and the nameserver-diversity signal is based on the registrable name, which is a heuristic rather than a network-path analysis.\n\n## Development\n\n```bash\ngit clone https://github.com/bobfromarcher/dnsward\ncd dnsward\nnode test/test.js\n```\n\nCI runs the suite on Node 18, 20 and 22 across Linux, macOS and Windows.\n\n## License\n\nMIT, bobfromarcher.\n","readmeFilename":"README.md","_rev":"1-aaa208abc7767e4e8cff81e1fc02b8e3"}