DNS Lookup

This is the lookup I reach for first when a domain is not behaving. It shows the records the public resolver you pick hands back right now, which is the quickest way to see whether a change has landed or where mail is actually going.

Public names only, in ASCII or punycode. Underscore labels such as _dmarc.example.com are fine, a single label such as com works for the top of a zone, and a trailing dot is optional.

What the record types mean

RecordWhat it shows
AThe IPv4 address a name points to
AAAAThe IPv6 address a name points to
CNAMEAn alias: this name points at another name, and the answer usually shows the chain
MXThe mail servers that accept email for the domain, with a priority: lower numbers are tried first
TXTFree-form text. Domain verification, sender rules and other configuration live here
NSThe name servers the domain is delegated to
SOAThe domain's authority record: primary name server, contact mailbox and the timers that govern caching
CAAWhich certificate authorities are allowed to issue certificates for the domain

How to read the answer

The TTL is the number of seconds a resolver may keep the answer cached. If you just changed a record, expect to see the old value until the previous TTL has run out, and expect different resolvers to update at different times. Waiting out the TTL and asking again is how you confirm a change.

The status line is the resolver's own answer code. NOERROR means the name exists, NXDOMAIN means it does not exist, and SERVFAIL means the resolver failed to answer. NOERROR with no records is a third case: the name exists but has no record of the type you asked for.

The authenticated data flag (AD) only says whether this resolver validated the answer with DNSSEC and set the flag on it. An unset flag is not proof that a domain is insecure, and a set flag is not a security audit.

What this tool does not do

  • It shows one resolver's current view. It cannot prove that a change has reached every resolver, and an older cached answer is normal until the TTL expires.
  • It reads records, nothing more. It does not check mail deliverability, reputation or blocklists, and it is not a security audit or a complete email diagnosis.
  • Your query goes straight from your browser to the resolver you pick. That resolver receives the name you type and keeps its own logs, so do not submit internal or private names. I do not receive your query, and I do not collect lookup history on this site.
  • Names must be public and in ASCII. For an internationalized domain, use the punycode form, for example xn--bcher-kva.example.