DNS Lookup

Query A, AAAA, CNAME, MX, TXT, NS, SOA, CAA, SRV or PTR records for a domain or IP address and see the answer with its TTL.

Loading tool…

About the DNS Lookup

Queries are sent from your browser over DNS-over-HTTPS (RFC 8484) to Cloudflare's public resolver 1.1.1.1, or to Google's 8.8.8.8 if you pick it, using their JSON API. The answer is what a recursive resolver sees right now, including the remaining TTL in seconds — how long resolvers may cache the record before asking the authoritative servers again. After you change a record, old values can persist for up to the old TTL. The DNSSEC validated flag appears when the resolver verified the answer's signatures (the AD bit).

Record types: A and AAAA map a name to IPv4 and IPv6 addresses; CNAME aliases one name to another; MX lists mail servers with their priority (lower is preferred); TXT carries SPF (v=spf1 …), DKIM, DMARC and domain-verification tokens; NS names the authoritative servers; SOA holds the zone's serial number and timers; CAA restricts which certificate authorities may issue TLS certificates; SRV locates services such as _sip._tcp.example.com.

Type an IP address to do a reverse lookup: 8.8.8.8 becomes the query 8.8.8.8.in-addr.arpa of type PTR, and IPv6 addresses are expanded into ip6.arpa nibble format. “All common types” runs eight queries at once for a quick overview. An NXDOMAIN status means the name does not exist; NOERROR with no records means it exists but has no record of that type, in which case the zone's SOA is shown.

How to use it

  1. Enter a domain name (a URL is fine — the host is extracted) or an IP address.
  2. Pick the record type, or “All common types”.
  3. Click “Look up” and read the records, TTLs and response status.
  4. Copy the result in a dig-like text format.

Frequently asked questions

How do I check a domain's SPF or DMARC record?
Look up the TXT records of the domain for SPF (the one starting v=spf1). For DMARC, look up TXT for _dmarc.example.com. DKIM keys live at selector._domainkey.example.com.
Why do different DNS checkers show different results?
Resolvers cache answers for the record's TTL, so after a change some still return the old value until it expires. Geo-DNS and CDNs also return different addresses depending on where the query comes from.
What is a PTR record?
A PTR record maps an IP address back to a host name (reverse DNS). Mail servers often check that the sending IP has a PTR record matching its host name.
Why is the lookup blocked?
Some corporate networks, browser extensions and DNS filters block DNS-over-HTTPS endpoints. Try the other resolver, or run dig example.com A on the command line.

Related tools