DNS Lookup

Run a DNS lookup for A, AAAA, CNAME, MX, NS, TXT, SOA, and CAA in one pass. The table lists each record with its TTL.

This check runs on our server. The address you enter is used only for this check and is not stored.
Updated

This check runs on our server. The address you enter is used only for this check and is not stored.

How to use the DNS Lookup

  1. Enter a domain, such as example.com.
  2. Pick a resolver. Cloudflare is the default. Authoritative asks the domain's own name servers.
  3. Tick the robot check, then press Look up.
  4. Read the table. Empty types are simply absent from that zone.

How it works

This check runs on our server. The name you enter is used only for this check and is not stored.

The server sends a separate query for each record type to the resolver you chose. UDP is used first. If the answer is marked truncated, that query is repeated over TCP. International names are converted to punycode before the query. The DNSSEC AD flag on the answer is reported as yes or no. It means the resolver says it validated the signatures, when the zone is signed.

TXT results also include _dmarc.yourdomain, which is where DMARC lives. DKIM is not guessed: it sits under a selector you choose, such as selector._domainkey.yourdomain.

Examples

  • A name that exists with only an A record still returns that address. The other types stay empty.
  • An MX row is sorted by priority, lowest number first, and the mail host's A and AAAA addresses are listed beside it.
  • A name that is not delegated comes back as "This domain does not exist."

Limitations

  • The tool reads DNS. It does not change records at your registrar.
  • A resolver can still be serving a cached copy until the TTL ends.
  • DKIM selectors are not scanned. You need the selector name for that query.

Frequently asked questions

Why is one record type missing?

The zone has no records of that type. An empty row is a normal answer, not a failed query.

What does the AD flag mean?

AD means the resolver claims the answer passed DNSSEC checks. If the zone is not signed, the flag stays off even when the records are fine.

Can I look up a private IP or localhost?

No. Private, loopback, and link-local addresses are refused.

Often used together with the DNS Lookup.

  • MX Lookup

    Mail servers from MX records, with priority and the host's addresses.

  • Reverse DNS Lookup

    PTR name for an IP address, plus a forward check that the name resolves back.