Check if DNS is working

How to know that Control D is working, and what to do to fix it if it's not.

Quick Check

On a device that is supposed to be using Control D, visit the Status Page. It checks the DNS path used by that browser, not every app or device on your network.

  • Using Control D means the check completed and detected a Control D resolver for that path.
  • Not using Control D means the check completed without detecting a Control D resolver. If you configured it, continue below to compare the setup outside the browser.
  • Unable to verify means the browser's verification check failed, not that DNS is necessarily broken or that you are definitely not using Control D. Follow the Unable to verify troubleshooting steps, which distinguish working DNS from a broader DNS failure.

Command Line Check

If you've configured Control D on your network router, or directly on the network interface Control D should be setup OS wide. Open Terminal / command line and run this command:

nslookup verify.controld.com

Server:         127.0.0.1
Address:        127.0.0.1#53

Non-authoritative answer:
verify.controld.com     canonical name = api.controld.com.
Name:   api.controld.com
Address: 147.185.34.1
Name:   api.controld.com
Address: 2606:1a40:3::1
  • If this command returns the expected verification address, it is evidence that this command's DNS path reaches Control D. It does not prove that the browser uses the same path, or that its verification request can complete. Inspect the browser's Secure DNS / DNS-over-HTTPS setting for a possible override, but do not assume that a disagreement with the Status page proves one. For Unable to verify, use the Status page troubleshooting steps.

  • If the command fails or does not return the expected address, that result alone does not distinguish a different resolver from a DNS, network, or verification-service failure. Check an ordinary domain as well and review the setup appropriate to your OS, router, or app. A browser-only Control D setup is not expected to change this command's result.

📘

Windows DNS Intercept Mode

nslookup.exe bypasses the Windows DNS Client and its NRPT rules, so it is not a reliable test of DNS Intercept Mode. Follow the DNS Intercept Mode testing guidance instead.

External Check

If your device does not have a browser, nor a command line, the only way you can check if Control D is working is to start the Activity Log on a Device that you've setup on your physical gadget. If you see any records in the Activity Log as you perform actions on the device, it's all working. If the log is always blank, then your DNS queries are not making it to Control D. The most likely reason for this is the fact that the IP is not authorized.


Did this page help you?