Skip to main content

Measurements

buffer.lol returns diagnostic signals rather than a single score. Each tool answers a narrow question about a domain, URL, certificate, network, IP address, or browser-local value.

DNS records

DNS lookups show the records published for a domain. A and AAAA records identify IPv4 and IPv6 addresses, MX records identify mail exchangers, TXT records often carry verification and policy data, and NS or SOA records describe delegation and authority.

DNS resolver comparison

DNS Resolver Comparison queries Cloudflare, Google, Quad9, and OpenDNS concurrently for one selected record type: A, AAAA, CNAME, MX, NS, TXT, or CAA. It normalizes and sorts the returned values before comparing answer sets, so record order and TTL differences do not count as disagreements. Agreement means the public resolvers that returned answers produced the same normalized values at that moment. It is not a geographic propagation map, and a resolver with no answer or a query error is reported separately from a different answer.

Email DNS health

Email DNS Health checks published MX, SPF, DMARC, optional DKIM, MTA-STS, and SMTP TLS reporting records. A DKIM check requires the selector used by the sender, such as google, selector1, or default; DKIM cannot be discovered reliably from the domain alone. The report evaluates recognizable DNS configuration. It does not send mail or measure inbox placement, sender reputation, policy alignment for a particular message, or complete deliverability.

HTTP status and headers

HTTP checks show the response status, response time from the diagnostics service, and headers. Headers can reveal cache behavior, redirects, content type, server metadata, security policy, and whether a target rejects HEAD requests.

HTTP security headers

HTTP Security Headers follows up to five safely validated redirects and inspects the final response. It checks HTTPS transport, HSTS, Content Security Policy, clickjacking protection, MIME sniffing protection, Referrer Policy, Permissions Policy, and cross-origin isolation/resource policies. It uses HEAD when supported and otherwise makes a headers-only ranged request without retaining the page body. The result reports individual pass, warning, fail, or informational checks with observed values and recommendations. It intentionally does not assign a letter grade: the right policy depends on the site’s application behavior, embedded content, and threat model.

TLS validity

TLS checks connect to the target host, read the peer certificate, and report authorization state, protocol, cipher, issuer, names, fingerprint, and validity dates. An unauthorized result can point to an expired certificate, hostname mismatch, incomplete chain, or other trust problem.

Port reachability

Port checks open a TCP connection from the diagnostics service to a public host:port. A reachable result means the port accepted a connection from buffer.lol; an unreachable result can mean the service is down, filtered, restricted by firewall rules, or only reachable from another network.

RDAP data

RDAP lookups summarize domain and IP registration data from public RDAP providers. They can include network ranges, country fields, registrar or entity names, nameservers, events, and source links.

ASN data

ASN checks use Team Cymru DNS data to connect a public IP address or autonomous system number to origin network records. Results can include ASN, prefix, country, registry, allocation date, and network name.

Browser latency

The Browser Latency Test sends repeated same-origin HTTPS requests from your browser to buffer.lol. It reports minimum, average, and maximum round-trip time plus approximate jitter. This is application-layer latency, not ICMP ping, and it does not measure latency to an arbitrary host.

Connection stability

The Connection Stability Test sends a larger series of HTTPS samples to buffer.lol and counts requests that fail or time out. A failed-request percentage can indicate an unstable browser-to-site path, but it is not a raw network packet-loss measurement.

Traceroute

Traceroute runs from buffer.lol’s restricted diagnostics worker to a public destination. It reports public hops and round-trip timings visible from that server. Private infrastructure hop addresses and raw command output are hidden by default.

Duration

Server-side API responses include durationMs. This is the time buffer.lol spent handling that diagnostic request, not a promise about the end user’s network quality.

Worker-backed checks

Traceroute requires privileges that are not available in ordinary serverless runtimes, so it runs through a separate authenticated container or VM worker. Browser latency and connection stability do not use that worker.