About the DNS Lookup
Queries are sent from your browser over DNS-over-HTTPS (RFC 8484) to Cloudflare's public resolver 1.1.1.1, or to Google's 8.8.8.8 if you pick it, using their JSON API. The answer is what a recursive resolver sees right now, including the remaining TTL in seconds — how long resolvers may cache the record before asking the authoritative servers again. After you change a record, old values can persist for up to the old TTL. The DNSSEC validated flag appears when the resolver verified the answer's signatures (the AD bit).
Record types: A and AAAA map a name to IPv4 and IPv6 addresses; CNAME aliases one name to another; MX lists mail servers with their priority (lower is preferred); TXT carries SPF (v=spf1 …), DKIM, DMARC and domain-verification tokens; NS names the authoritative servers; SOA holds the zone's serial number and timers; CAA restricts which certificate authorities may issue TLS certificates; SRV locates services such as _sip._tcp.example.com.
Type an IP address to do a reverse lookup: 8.8.8.8 becomes the query 8.8.8.8.in-addr.arpa of type PTR, and IPv6 addresses are expanded into ip6.arpa nibble format. “All common types” runs eight queries at once for a quick overview. An NXDOMAIN status means the name does not exist; NOERROR with no records means it exists but has no record of that type, in which case the zone's SOA is shown.
How to use it
- Enter a domain name (a URL is fine — the host is extracted) or an IP address.
- Pick the record type, or “All common types”.
- Click “Look up” and read the records, TTLs and response status.
- Copy the result in a dig-like text format.