DNS Lookup

See a domain's A, AAAA, CNAME, MX, NS, TXT, SOA and CAA records at once. Enter an IP address to see its reverse DNS (PTR) record.

What Is a DNS Lookup?

The Domain Name System (DNS) is the internet's address book: it translates domain names such as example.com into the IP addresses computers use to connect. A domain's DNS records decide which server hosts its website, where its email is delivered and which name servers are in charge of the domain. A DNS lookup shows what those records say right now, which comes in handy when you launch a website, troubleshoot email delivery or want to know whether a DNS change has propagated yet.

How This Tool Works

  • The A, AAAA, CNAME, MX, NS, TXT, SOA and CAA records of the domain you enter are queried in parallel through Cloudflare's public resolver (1.1.1.1) using DNS over HTTPS.
  • Every record is listed with its TTL, and you can see whether the answer was validated with DNSSEC (the AD flag).
  • Enter an IP address instead of a domain name to see its reverse DNS (PTR) record.
  • Names that contain underscores, such as _dmarc.example.com or DKIM selectors, are supported.
  • Results are cached for 5 minutes, and each IP address can run up to 10 lookups per minute.

DNSSEC is a security extension that uses digital signatures to prove DNS answers weren't tampered with on the way to you. If a domain is signed and the resolver could verify its signatures, the answer carries the AD (Authenticated Data) flag. Many domains aren't signed at all, so a missing AD flag isn't an error in itself.

DNS Record Types

RecordWhat it doesExample value
APoints a name to an IPv4 address.203.0.113.10
AAAAPoints a name to an IPv6 address.2001:db8::10
CNAMEMakes a name an alias of another name; not allowed at the root of a domain (example.com).www.example.com → example.com
MXThe mail servers that accept email for the domain; the lowest preference number is tried first.10 mx1.example.com
NSThe authoritative name servers that host the domain's records.ns1.example.com
TXTFree-form text: SPF, DKIM, DMARC and site verification codes.v=spf1 include:_spf.example.com ~all
SOAThe zone's primary name server, the responsible mailbox, a serial number and refresh timers.ns1.example.com hostmaster.example.com 2026092801 …
CAAWhich certificate authorities may issue SSL/TLS certificates for the domain.0 issue "letsencrypt.org"
PTRThe reverse record that maps an IP address back to a name. It's set by whoever owns the IP address (the ISP or hosting company), not by the domain owner.8.8.8.8 → dns.google

Checking SPF, DKIM and DMARC Records

To keep your email out of spam folders, your domain needs three authentication records, all published as TXT records:

  • SPF: a record on the domain itself that starts with v=spf1 and lists the servers allowed to send mail on your behalf. A domain should have only one SPF record.
  • DKIM: a public key published at selector._domainkey.example.com. Your email provider chooses the selector name; you'll find it in the s= tag of the DKIM-Signature header of a message you've sent.
  • DMARC: a record at _dmarc.example.com that starts with something like v=DMARC1; p=none. It tells receivers what to do with messages that fail SPF and DKIM checks: none, quarantine or reject.

Since 2024, Gmail and Yahoo have required all three from domains that send email in bulk.

TTL and DNS Propagation

TTL (time to live) is the number of seconds resolvers may cache a record: 300 means five minutes, 3600 one hour and 86400 one day. When you change a record, any server that cached the old answer keeps serving it until the TTL runs out. That delay is what people call “DNS propagation.” If you lower the TTL to something like 300 at least one full TTL period before a planned change, the switch completes within minutes. Name server (NS) changes take longer, often a day or two, because the delegation records at the domain's registry are cached as well.

DNS Lookups from the Command Line: nslookup and dig

You can run the same queries with nslookup or PowerShell's Resolve-DnsName on Windows, and with dig on macOS and Linux:

nslookup -type=mx example.com
nslookup -type=txt _dmarc.example.com 1.1.1.1
Resolve-DnsName example.com -Type AAAA
dig example.com NS +short
dig @1.1.1.1 example.com A +dnssec
dig -x 8.8.8.8 +short

If the flags line of the dig output includes ad, the answer was validated with DNSSEC. On Windows, ipconfig /flushdns clears stale records from your computer's cache. To see where an IP address from a record is located and which provider it belongs to, use our IP lookup; for a domain's registration and expiry dates, try the WHOIS lookup.

DNS Lookup FAQ

I changed a DNS record. Why do I still see the old value?

Resolvers cache every record for its TTL, so any server that cached the old answer keeps returning it until that time runs out. Wait for the old TTL to expire. Our tool also caches results for 5 minutes. To clear your own computer's cache on Windows, run ipconfig /flushdns.

How long does DNS propagation take?

It depends on the old TTL of the record you changed: with a TTL of 300 seconds, a change usually spreads within minutes; with 86400 seconds, it can take up to a day. Name server (NS) changes can take 24–48 hours because the delegation records at the domain's registry are cached as well.

How do I look up DMARC and DKIM records?

For DMARC, query _dmarc.yourdomain.com; for DKIM, query selector._domainkey.yourdomain.com. Both are TXT records. Replace selector with the selector your email provider uses; you'll find it in the s= tag of the DKIM-Signature header of a message you've sent.

What does the AD flag (DNSSEC validated) mean?

The AD (Authenticated Data) flag means the answer was validated with DNSSEC signatures, so the records weren't altered in transit. If a domain isn't signed with DNSSEC, the flag doesn't appear; that isn't an error, it just means the extra security layer isn't in use. If validation fails for a signed domain, the resolver returns an error (SERVFAIL) instead of an answer.