Check IPv6 reachability

Enter a domain. The IPv6 check reads the AAAA records of the domain and of www (for a subdomain only those of that host) and fetches the website over every IPv6 address separately, provided the checking location has an IPv6 route itself (otherwise the result says so explicitly). You see whether visitors who arrive over IPv6 actually reach your site.

AAAA records and IPv6

An AAAA record maps a host name to an IPv6 address, just as an A record maps it to an IPv4 address. If a name has both, the client decides which path to take, and operating systems prefer IPv6 as soon as it is available. Many mobile networks now give devices only an IPv6 address and reach IPv4 destinations through translation at the provider (DNS64 and NAT64).

DNS
example.com.      IN A     203.0.113.10
example.com.      IN AAAA  2001:db8:10::10
www.example.com.  IN AAAA  2001:db8:10::10

Why a dead AAAA record hurts

The typical case: when moving to a new server, the A record is updated but the AAAA record keeps pointing to the old one. Or the host assigns an IPv6 address but the web server only listens on IPv4, or the firewall only lets port 443 through for IPv4.

If you have both IPv4 and IPv6, you hardly notice: Happy Eyeballs (RFC 8305) tries both paths almost simultaneously and takes whichever answers first. The site loads, everything is green at the office. In IPv6-only mobile networks, however, the device uses the AAAA record directly; translation via NAT64 only kicks in when there is none. For these visitors the site is simply unreachable. The same goes for apps, scripts and services that work without falling back to IPv4.

What the check tests

  • AAAA records of the domain and of www. If you enter a subdomain such as shop.example.com, only those of that host.
  • Every IPv6 address separately: clients land on any of them, one dead address among several is enough for failures.
  • No answer or a server error (5xx) over IPv6: warning.
  • Redirect to a target without an AAAA record: hint. The server answers over IPv6 but sends visitors to an address that is only reachable over IPv4.
  • No AAAA records: hint. The website is then only reachable over IPv4, which thanks to NAT64 also works from IPv6-only networks. It costs no points in the domain check.

What "not checked" means

To fetch a website over IPv6, the checking location itself needs an IPv6 route. Without one, the check only lists the AAAA records and says clearly that reachability over IPv6 could not be verified. That is not a finding and costs no points in the domain check; it means neither that IPv6 works nor that it is broken. You can test it yourself from a machine with IPv6 using curl -6 -I https://example.com/.

Setting up IPv6 properly

Most faults do not appear at the initial setup but with later changes to the server:

  • Make the web server listen on both protocols: in nginx one listen line each for IPv4 and [::], in Apache Listen 443 without a fixed IPv4 address.
  • Firewall: IPv4 and IPv6 often have separate rules (iptables and ip6tables, separate entries in the host's firewall). Ports 80 and 443 must be open in both.
  • Virtual hosts: a vhost bound to an IPv4 address serves the server's default site over IPv6, often with the wrong certificate.
  • Moving servers: change the A and AAAA records together. If the new server has no IPv6, remove the AAAA record instead of leaving it in place.
nginx
server {
    listen 443 ssl;
    listen [::]:443 ssl;
    server_name example.com www.example.com;
}

Monitor IPv6 continuously

A dead AAAA record almost never shows up in your own checks because Happy Eyeballs masks it. When IPv6 is enabled, DomainWarn fetches the websites of all customer domains from a checking location with IPv6 over every IPv6 address, every 6 hours on the Free plan, hourly otherwise. Before every finding it verifies its own IPv6 path so that a disruption at the checking location does not trigger a false alarm.

Frequently asked questions

Does my website have to be reachable over IPv6?
No. Without an AAAA record, users in IPv6-only networks usually still reach the site through NAT64 at their provider. Only an AAAA record with nothing answering behind it is a problem: it is worse than none at all.
The site loads for me, yet the check reports IPv6 as unreachable?
Your connection probably uses IPv4, or the browser silently falls back to IPv4 via Happy Eyeballs. With curl -6 https://example.com/ you test specifically over IPv6; without IPv6 on your own connection, try it from a server.
Why does the check test www as well?
Visitors use both names, and both often have separate records. If www is a CNAME to a hosting provider or CDN, its AAAA record may belong to a completely different server than the one at the apex.
Monitor continuously
Monitor the websites of all client domains continuously

Website monitoring for agencies: DomainWarn checks availability, status code, response time, redirects, IPv6, headers and content of all client websites.

More about monitoring

More tools

Free tool

Domain Check

Check website, email, DNS and domain in one run: 19 checks, a score from 0 to 100 per area and overall, with recommendations. Free, no sign-up required.

Open tool →
Free tool

Email header analyzer

Paste email headers and read them in plain words: did SPF, DKIM and DMARC pass, does the sender domain align, which servers relayed it, how long it took?

Open tool →
Free tool

Privacy check

Check for free which third parties your home page loads before any consent: Google Fonts, Analytics, pixels, maps – with a note on what is legally risky.

Open tool →
Free tool

security.txt Checker

Check your security.txt for free: Contact, Expires, expiry date, HTTPS and content type per RFC 9116. See whether security researchers can reach you.

Open tool →
Free tool

Email Check

Check SPF, DKIM, DMARC and MX of a domain in one run, free and without sign-up. Shows whether your mail meets the Google and Yahoo sender requirements.

Open tool →
Free tool

SPF Checker

Free SPF record check and lookup: syntax, includes, the 10 DNS lookup limit and the closing qualifier. Shows whether your domain blocks forged senders.

Open tool →
Free tool

DMARC Checker

Free DMARC record check: policy (none, quarantine, reject), pct, reporting addresses and syntax errors. With recommendations for moving to p=reject.

Open tool →
Free tool

DNS Checker

Free DNS lookup straight from the authoritative name server: A, AAAA, CNAME, MX, TXT, NS and CAA records at a glance. No sign-up, every record explained.

Open tool →
Free tool

MX Checker

Free MX lookup: which mail servers receive for a domain, do they resolve, is the priority right? Detects missing and unreachable mail servers.

Open tool →
Free tool

SSL Checker

Free SSL certificate check: expiry date, issuer, chain, host name and TLS version, mail servers too. Detects expired, self-signed and mismatched certificates.

Open tool →
Free tool

HTTP Header Checker

Free HTTP header check: HSTS, Content-Security-Policy, X-Content-Type-Options, X-Frame-Options, Referrer-Policy and Permissions-Policy, with fixes.

Open tool →
Free tool

Is the website down?

Website not loading? Check for free whether a site is down for everyone or just for you: response, status code, load time, redirects and IP addresses.

Open tool →
Free tool

DNS Propagation Checker

Check DNS propagation for free: which resolvers worldwide (Google, Cloudflare, Quad9 …) already return the new A, MX or TXT record, which still the old one?

Open tool →
Free tool

Redirect Checker

Free 301 redirect check: every hop with status code and response time, from http to https, from www to non-www. Detects redirect chains, loops and 302s.

Open tool →
Free tool

DKIM Checker

Free DKIM record check and lookup: selector, key type, key length, syntax and revoked keys. Leave the selector empty to try common selectors automatically.

Open tool →
Free tool

DNSSEC Checker

Free DNSSEC test: DS record, resolver validation and broken signature chains. Shows whether validating resolvers like Google and Cloudflare still reach you.

Open tool →
Free tool

Name Server Check

Free name server check: does every NS answer authoritatively, do all serve the same zone data, are they in different networks? Finds lame delegation.

Open tool →
Free tool

CAA Record Checker

Free CAA record check: issue, issuewild and iodef, matched against the CA of your current certificate. Shows whether the next renewal is going to fail.

Open tool →
Free tool

MTA-STS Checker

Free MTA-STS check: DNS record, policy file, mode, max_age and whether your MX servers are covered. Shows whether inbound mail enforces TLS.

Open tool →
Free tool

TLS-RPT Checker

Free TLS-RPT record check: syntax, reporting addresses (rua) and common errors such as a missing record. Shows whether you get reports on TLS failures.

Open tool →
Free tool

BIMI Checker

Free BIMI record check: syntax, logo URL, SVG Tiny PS, VMC certificate and the DMARC prerequisite. Shows why your logo does not appear in Gmail.

Open tool →
Free tool

Blacklist Check

Free IP and domain blacklist check: mail server IPs, website IP and domain against Spamhaus, Spamcop, Barracuda, PSBL and SURBL. With delisting links.

Open tool →
Free tool

Domain Checker

Free domain check: WHOIS data via RDAP straight from the registry, expiry date, registrar, EPP status, transfer lock and name servers. Warns before expiry.

Open tool →