PADNS Timeline Chart

Prev Next

Use the PADNS timeline chart in Total View to see when DNS records appeared, how long they lasted, and which answers overlapped. The chart uses the same records as the table, so you can switch views without exporting data or comparing first seen and last seen dates by hand.

Where the chart is available

Open Total View, go to the PADNS tab, then open a record-type tab. The chart is available in:

  • A

  • AAAA

  • CNAME

  • NS

  • MX

  • SOA

  • TXT

  • PTR

PTR is available only when you query an IPv4 address. Each tab uses a title that matches that record type.

Switch between table and chart

Each record-type tab opens in the table view. In the top-right, use the Table and Chart icons to switch between them. Only one view is shown at a time, in the same content area. The active icon stays selected.

Data table showing DNS queries, answers, and timestamps for various domains.

Switching views does not change your filters, sort, or page in the table.

If the tab has no records, the Chart icon is unavailable. The rest of the empty state is unchanged.

How to read the chart

The chart is a stacked bar chart.

  • The X-axis is time, from the earliest first seen date to the latest last seen date in the current view.

  • The Y-axis is each Answer value.

  • Each bar is one table row.

  • Bar length is the time between first seen and last seen. If those timestamps are the same, the bar still has a minimum width so you can see it.

Time labels on the X-axis change with the range you are viewing:

  • 1 hour when the range is 24 hours or less

  • 1 day when the range is more than 24 hours and up to 7 days

  • 7 days when the range is more than 7 days and up to 90 days

  • 1 month when the range is more than 90 days and up to 365 days

  • 3 months when the range is more than 1 year and up to 2 years

  • 6 months when the range is more than 2 years and up to 4 years

  • 1 year when the range is more than 4 years

Scroll and sort

If there are more records than fit on screen, scroll the chart vertically. The X-axis and its labels stay visible at the bottom while you scroll.

Records are listed from the top down in the same sort order as the table. The first record in that sort is at the top.

What the chart includes

The chart shows the same records you currently see in the table, up to 100 rows. If you filter, sort, or change pages in the table, the chart updates to match.

Fields on each record type

Labels on each bar read left to right as follows.

A

  • Domain query: Query (domain), Answer (IP), Answer ASN, Answer AS Name, Country Code

  • IP query: Query (domain), Answer ASN, Answer AS Name, Country Code

AAAA

Answer (IP), Answer ASN, Answer AS Name, Country Code

CNAME

Answer (domain), Answer ASN, Answer AS Name, Country Code

NS

Answer (nameserver), NS Hash

MX

Answer (MX) only. Answer ASN, Answer AS Name, and Country Code are not shown because the MX answer is a hostname, not an IP.

SOA

Answer, SOA Hash

TXT

Answer (TXT), TXT Hash

PTR

Answer only. This chart appears only for IPv4 queries.