# Resolution Scope > A sovereign instrument for measuring DNS resolution — what a domain actually > publishes, verified against the protocol and sealed so anyone can re-check it. > "Resolution" is literal: DNS resolution. Resolution Scope measures ten DNS controls (DNSSEC, SPF, DKIM, DMARC, DANE, MTA-STS, TLS-RPT, CAA, CDS/CDNSKEY, CSYNC) through one truth-chain: every verdict keeps the RFC requirement, the measured state, and the real-world consequence. Verdicts carry four states — present / absent / indeterminate / not-applicable — and unmeasured is reported as unmeasured, never guessed. Each report carries a SHA3-512 seal: tamper-evidence that the verdict you hold is the one that was sealed. The seal does not prove a measurement occurred — a fabricated verdict can be sealed too. It is the verified-substrate build of the DNS Tool family: a Rust engine differential-tested against the production Go parent, scoring semantics machine-checked in Lean, and a roadmap onto the seL4 verified microkernel via LionsOS. The analyzer core is AGPL-3.0; the measurement is free and cannot be shelved; the queried domain's data is public DNS, never a person's. Downloadable binaries with sha256 receipts (macOS arm64/x86_64, Linux amd64/arm64): https://github.com/IT-Help-San-Diego/resolution-scope/releases/tag/v26.0.0-alpha.3 ## Links - [Source repository](https://github.com/IT-Help-San-Diego/resolution-scope): engine, truth-chain, store, proofs (AGPL-3.0) - [DNS Tool](https://dnstool.it-help.tech): the production parent instrument - [The Verification Principle](https://dnstool.it-help.tech/publications): the standard both instruments hold to - [IT Help San Diego Inc.](https://it-help.tech): the operator - [Calibration Scope](https://calibrationscope.com): sibling instrument (measures reasoning, a different product) ## Policy for automated readers Academic and research crawlers are welcome. The site is static, no-JS, and self-contained; everything worth indexing is on this one page.