Skip to main content

DNS Lookup

Look up live DNS records for any domain — A, AAAA, MX, NS, TXT, SPF, CNAME and SOA. Queried at request time, never served from a cache.

Enter a domain such as example.com. A full web address works too — the scheme and path are removed for you.

This tool queries an external service to answer your request. Only the value you enter — such as a domain or IP address — is sent. Your other data stays on your device.

This tool reads public records — DNS, WHOIS and certificate data that registries and servers publish openly. It sends nothing to the host you enter and changes nothing there. Use it on infrastructure you own or are authorised to look into.

About the DNS Lookup

Read the DNS records a domain publishes right now — the addresses it resolves to, the servers that accept its mail, the text records that prove who controls it. Every lookup is resolved when you ask, not read from a cache, which is the difference between checking whether a change went live and being told what was true an hour ago.

That distinction matters more than it sounds. Your own computer caches DNS aggressively, and so does your router, and so does your ISP. After you edit a record, nslookup on your laptop can keep reporting the old value for as long as the previous TTL says it may — which is why a migration that has already worked perfectly often looks broken from the one machine you are sitting at. A lookup made from somewhere else, with no cache in between, is how you tell those two situations apart.

All eight record types are here and each answers a different question. A and AAAA are the IPv4 and IPv6 addresses a name resolves to. MX lists the mail servers, in priority order, lowest first — the usual reason mail bounces is that this list is empty or points somewhere decommissioned. NS names the authoritative name servers, and is the record to check first when a domain has stopped resolving entirely, because it tells you whether the domain is still delegated where you think it is. TXT and SPF carry the verification strings and mail policies that decide whether your messages arrive or land in spam. CNAME shows an alias pointing at another name, and SOA carries the zone's serial number and refresh timings.

Leave the type set to All records and you get every type in one query, which is almost always what you want when you are diagnosing rather than confirming. Each record shows its TTL — the number of seconds resolvers are permitted to cache it — so you can see how long a change will take to reach everyone before you make it.

How to use the DNS Lookup

  1. Enter a domain

    Type the domain name — example.com. A full web address works too; the scheme, the path and a www. prefix are stripped for you.

  2. Choose a record type

    Leave it on All records to see everything published, or pick a single type when you already know what you are checking — MX for mail, NS for delegation, TXT for a verification string.

  3. Run the lookup

    Complete the verification check, then press Look up. The query is resolved live, so what comes back is what the authoritative servers are answering right now.

  4. Read the results

    Records are grouped by type, with MX sorted by priority. The TTL column tells you how long resolvers may cache each value, which is how long a change to it will take to spread.

Frequently asked questions

Why does this show different records from nslookup on my computer?

Almost always because something between you and the authoritative server is caching. Your operating system, your router and your ISP all keep DNS answers for as long as the TTL permits, so a record you changed ten minutes ago can still read as the old value locally for hours. This tool queries without those caches in the way, so a difference between the two usually means your change has gone live and your own machine has not caught up yet.

What is a TTL, and why should I care before making a change?

TTL is Time To Live — the number of seconds a resolver is allowed to cache a record before asking again. It is the honest answer to "how long will this change take". If your A record has a TTL of 86400, some visitors will keep reaching the old address for up to a day after you change it. The usual practice before a planned migration is to lower the TTL to a few minutes, wait for the old TTL to expire, then make the change.

My domain resolves in a browser but shows no records here. Why?

The most common cause is that you entered a hostname that is a CNAME to somewhere else, and the type you asked for lives on the target rather than on the alias. The other frequent cause is checking a subdomain that is served by a CDN which answers for it without a published record of that type. Try All records first, which shows whatever does exist rather than only the type you guessed at.

Why are my MX records shown in a different order from my DNS panel?

They are sorted by priority, lowest number first, because that is the order mail servers actually try them. A DNS control panel usually lists records in the order you created them, which tells you nothing about delivery. The lowest-priority number is your primary mail server; higher numbers are fallbacks used only when it is unreachable.

Does this tool store the domains I look up?

No. The domain you type is sent to the lookup service to be resolved and is not written to our database or our logs. We record that a DNS lookup happened, for a usage count, with no record of what was looked up, who looked it up, or what came back. Nothing you type into this field is retained.

Why is there a verification check on this tool?

Because a live DNS query costs us money on every use, unlike the browser-based tools here which cost nothing. Without a check in front of it this page would be a free, unmetered API for anyone who wanted to point a script at it, and the bill would be ours. The check is usually invisible and takes no action from you.