How to use the four panels 01 Open the panel. Each panel has its own page in the Network group: /data/netlab (Connection), /data/netlab/dns, /data/netlab/webrtc, /data/netlab/speed. 02 Connection. The Cloudflare trace cards give the IP, location, edge colo, TLS, HTTP and WARP values; the ipwho.is block adds country, city, ISP and ASN; Local info works with the network off, the other two blocks need it. 03 DNS Lookup. Type a domain, choose one of eight record types (A, AAAA, CNAME, MX, TXT, NS, SOA, CAA) and a provider, or Compare to run both, then press Query. Answers show Name, Type, TTL and Data; NOERROR means the name resolved, NXDOMAIN that it does not exist. 04 WebRTC. Press Start test; the candidate table fills as the browser finds addresses, tagged private, public, IPv6 or mDNS. 05 Speed Test. Press Start test; the button becomes Abort while latency, download and upload run, reporting latency statistics, download speed, bytes downloaded and upload speed. A full run moves about 50 MB.
Worked examples Readouts below were captured in one session; TTLs count down, so a fresh query returns different numbers.
A null MX. Domain example.com, type MX, provider Cloudflare: Status NOERROR ; one row — example.com, MX, TTL 300, Data 0 .. A lone 0 . is a null MX (RFC 7505): the name deliberately accepts no mail.
A missing name. Domain no-such-host.invalid, type A: Status NXDOMAIN , the table replaced by No records .
An alias chain. Domain www.wikipedia.org, type A: rows www.wikipedia.org CNAME TTL 86055 data dyna.wikimedia.org., then dyna.wikimedia.org A TTL 16 data 103.102.166.224 — an A query can carry a CNAME row.
What a peer-to-peer page could see. With WebRTC started, the cards read Local IPs hidden via mDNS? yes ✓ and Candidates 2 ; rows were host · local with an mDNS badge and srflx · public (STUN) with a public badge, and the srflx address 103.151.173.97 matched the Connection trace IP. With STUN unreachable: none detected and Candidates 1 .
How the panels reach the network
Connection makes two ordinary HTTPS requests, so it follows any HTTP proxy in the path; the trace IP is what Cloudflare's edge saw, and the geolocation block fails independently (one session showed Request failed: HTTP 429).
DNS Lookup sends the question as an HTTPS request to the chosen resolver (DNS-over-HTTPS), bypassing the device's DNS settings; two resolvers can hold different cached answers, hence Compare.
WebRTC gathers ICE candidates: host is local and often replaced by a .local mDNS name, srflx is the address a STUN server saw, and relay needs a TURN server this panel does not configure.
Speed Test times generated payloads against speed.cloudflare.com; its latency samples are HTTPS round trips, not pings.
Limits
Readings belong to the moment. Latency, jitter and throughput depend on device, Wi-Fi, ISP and the remote edge, so two runs differ. They are measurements, not guarantees.
Third-party answers. DNS results come from the resolver you picked, not the device's DNS settings, and cached TTLs count down: another device can see a different answer. Not a subnet or packet tool. No CIDR, mask or VLSM work (that is the IP Subnet tool ), no traceroute, packet capture, port scan or header inspector; encoding, hashing, JSON and regex live in Dev Tools , and keypad arithmetic in the standard calculator .
Pitfalls
"DNSSEC: not validated" is not proof that a zone is unsigned. The card reports whether that one resolver response carried the AD flag. In testing, example.com type A read "not validated" on one query and "AD ✓ validated" on another, while one.one.one.one type A stayed not validated.
A green mDNS "yes" hides the LAN, not the public address. Host candidates become .local names, but the srflx candidate still reports the address the STUN server saw, even behind a VPN.
The record-type box sets the question, not a filter. The www.wikipedia.org lookup above returned a CNAME row inside an A query.
Where it is useful Diagnosing before calling support The trace cards say whether traffic reaches a nearby edge, and Local info can go into a ticket while the network is down.
Checking mail and DNS changes A null MX (0 .) is a deliberate "no mail here". After a record change, query the same name on both providers to watch caches catch up.
Seeing what a peer-to-peer page could see A video call runs the same ICE exchange: srflx is the address a remote peer would learn, and the host row is what mDNS hides.
Privacy Each panel talks directly from the browser to the service named on it; this site does not proxy, store or log your readings.
References
IETF, RFC 1035: Domain Names — Implementation and Specification , rfc-editor.org (访问日期:2026-10-01)— DNS message format, record types and TTL.
IETF, RFC 8484: DNS Queries over HTTPS (DoH) , rfc-editor.org (访问日期:2026-10-01)— the HTTPS transport behind the DNS Lookup panel.
IETF, RFC 8445: Interactive Connectivity Establishment (ICE) , rfc-editor.org (访问日期:2026-10-01)— host, server-reflexive and relayed candidate types.
IETF, RFC 6762: Multicast DNS , rfc-editor.org (访问日期:2026-10-01)— .local host names.
IETF, RFC 7505: A Null MX No Service Resource Record for Domains That Accept No Mail , rfc-editor.org (访问日期:2026-10-01)— the 0 . record in the worked example.
IETF, RFC 2606: Reserved Top Level DNS Names , rfc-editor.org (访问日期:2026-10-01)— example.com and the reserved .invalid test name.
Calculators in this hub
Hand-picked tools, one click away. The mini versions compute live and carry your values into the full calculator.
Sources & review
Reviewed by CalcX Editorial Team
Updated 2026-10-01