DNS lookup
Look up the DNS records published for a domain, one type or all common types at once, or the reverse DNS name of an IP address.
Choosing a check opens its page. With the keyboard, use the arrow keys, then press Enter.
What we check
We ask public DNS resolvers (Quad9 first, then Cloudflare) for the records published for the name you enter. Choose one record type, or "All common types" to see A, AAAA, CNAME, MX, NS, TXT, SOA and CAA together. Enter a public IP address to see its reverse DNS (PTR) name.
Record types
- A and AAAA: the IPv4 and IPv6 addresses of the name.
- CNAME: the name is an alias for another name.
- MX: the mail servers that receive email for the domain.
- NS: the name servers that hold the domain's DNS.
- TXT: text records, used for SPF, DMARC, site verification and more.
- SOA: the zone's primary name server, contact mailbox and timers.
- CAA: which certificate authorities may issue certificates for the domain.
Why the result can differ elsewhere
Resolvers keep answers for the record's TTL. After a change, some places can show the old value until that time runs out.
Frequently asked questions
Which DNS servers do you ask?
Public resolvers: Quad9 first, then Cloudflare if Quad9 can't answer. We never use the hosting company's own DNS. The answer is what most of the internet sees, but a change you've just made may take a while to appear, depending on the record's TTL.
Why don't you use an ANY query for "All"?
Many DNS servers now answer ANY queries with only a minimal reply (RFC 8482), so the result would be misleading. "All" asks for each common type separately: A, AAAA, CNAME, MX, NS, TXT, SOA and CAA.
What does TTL mean?
Time to live: how many seconds resolvers may keep the answer before asking again. A record changed recently can still show its old value elsewhere until the TTL runs out.
What does "Validated by DNSSEC" mean?
Quad9 checked the DNSSEC signatures on the answer and they were valid. It doesn't mean the records are correct, only that they came from the domain's own DNS unchanged. A fuller DNSSEC check is planned as its own tool.
Can I look up an IP address?
Yes. Enter a public IP address to see its reverse DNS (PTR) name. Private and reserved addresses, such as 192.168.x.x, can't be looked up.
Related tools
-
MX Lookup
See which mail servers receive email for a domain, in priority order, with each server's addresses.
-
SPF Checker
Check that a domain's SPF record is valid, stays within the 10-lookup limit, and says what you expect about servers that may send its mail.
-
DMARC Checker
Find the DMARC policy that applies to a domain, see what each setting means, and spot mistakes that make receivers ignore it.
-
CAA Checker
See which certificate authorities a domain allows to issue its certificates.
-
DNSSEC Checker
Check whether a domain is signed with DNSSEC and whether validating resolvers accept it.
-
HTTP Header Checker
See the HTTP status and every response header a website sends, for the final page and each redirect on the way.
-
Redirect Checker
Follow a web address through every redirect, with the status code, destination and timing of each hop.
-
Website Down Checker
Check whether a website is responding right now, from our server: status, response time, redirects, IP addresses and HTTPS.
-
SSL Certificate Checker
Check whether a site's HTTPS certificate is valid and trusted, which names it covers, and when it expires.
-
Website Health Check
Run the main website, DNS and email checks on one site at once and get a short report, area by area, with links to the full results.