What Is a DNS Lookup?
The Domain Name System (DNS) is the internet's address book: it translates domain names such as example.com into the IP addresses computers use to connect. A domain's DNS records decide which server hosts its website, where its email is delivered and which name servers are in charge of the domain. A DNS lookup shows what those records say right now, which comes in handy when you launch a website, troubleshoot email delivery or want to know whether a DNS change has propagated yet.
How This Tool Works
- The A, AAAA, CNAME, MX, NS, TXT, SOA and CAA records of the domain you enter are queried in parallel through Cloudflare's public resolver (1.1.1.1) using DNS over HTTPS.
- Every record is listed with its TTL, and you can see whether the answer was validated with DNSSEC (the AD flag).
- Enter an IP address instead of a domain name to see its reverse DNS (PTR) record.
- Names that contain underscores, such as
_dmarc.example.comor DKIM selectors, are supported. - Results are cached for 5 minutes, and each IP address can run up to 10 lookups per minute.
DNSSEC is a security extension that uses digital signatures to prove DNS answers weren't tampered with on the way to you. If a domain is signed and the resolver could verify its signatures, the answer carries the AD (Authenticated Data) flag. Many domains aren't signed at all, so a missing AD flag isn't an error in itself.
DNS Record Types
| Record | What it does | Example value |
|---|---|---|
| A | Points a name to an IPv4 address. | 203.0.113.10 |
| AAAA | Points a name to an IPv6 address. | 2001:db8::10 |
| CNAME | Makes a name an alias of another name; not allowed at the root of a domain (example.com). | www.example.com → example.com |
| MX | The mail servers that accept email for the domain; the lowest preference number is tried first. | 10 mx1.example.com |
| NS | The authoritative name servers that host the domain's records. | ns1.example.com |
| TXT | Free-form text: SPF, DKIM, DMARC and site verification codes. | v=spf1 include:_spf.example.com ~all |
| SOA | The zone's primary name server, the responsible mailbox, a serial number and refresh timers. | ns1.example.com hostmaster.example.com 2026092801 … |
| CAA | Which certificate authorities may issue SSL/TLS certificates for the domain. | 0 issue "letsencrypt.org" |
| PTR | The reverse record that maps an IP address back to a name. It's set by whoever owns the IP address (the ISP or hosting company), not by the domain owner. | 8.8.8.8 → dns.google |
Checking SPF, DKIM and DMARC Records
To keep your email out of spam folders, your domain needs three authentication records, all published as TXT records:
- SPF: a record on the domain itself that starts with
v=spf1and lists the servers allowed to send mail on your behalf. A domain should have only one SPF record. - DKIM: a public key published at
selector._domainkey.example.com. Your email provider chooses the selector name; you'll find it in thes=tag of the DKIM-Signature header of a message you've sent. - DMARC: a record at
_dmarc.example.comthat starts with something likev=DMARC1; p=none. It tells receivers what to do with messages that fail SPF and DKIM checks:none,quarantineorreject.
Since 2024, Gmail and Yahoo have required all three from domains that send email in bulk.
TTL and DNS Propagation
TTL (time to live) is the number of seconds resolvers may cache a record: 300 means five minutes, 3600 one hour and 86400 one day. When you change a record, any server that cached the old answer keeps serving it until the TTL runs out. That delay is what people call “DNS propagation.” If you lower the TTL to something like 300 at least one full TTL period before a planned change, the switch completes within minutes. Name server (NS) changes take longer, often a day or two, because the delegation records at the domain's registry are cached as well.
DNS Lookups from the Command Line: nslookup and dig
You can run the same queries with nslookup or PowerShell's Resolve-DnsName on Windows, and with dig on macOS and Linux:
nslookup -type=mx example.com
nslookup -type=txt _dmarc.example.com 1.1.1.1
Resolve-DnsName example.com -Type AAAA
dig example.com NS +short
dig @1.1.1.1 example.com A +dnssec
dig -x 8.8.8.8 +short
If the flags line of the dig output includes ad, the answer was validated with DNSSEC. On Windows, ipconfig /flushdns clears stale records from your computer's cache. To see where an IP address from a record is located and which provider it belongs to, use our IP lookup; for a domain's registration and expiry dates, try the WHOIS lookup.