Skip to main content

DNS Lookup Online

Look up A, AAAA, MX, TXT, NS, CNAME and SOA records for any domain using Google DNS over HTTPS.

How to use the lookup

Enter a domain and the tool queries seven record types in parallel, with no need for dig or nslookup. Answers come from Google DNS over HTTPS and carry the TTL of each record.

The lookup is for diagnosing sites that are down, checking email configuration, following a server migration, validating a nameserver change and investigating name resolution problems.

You can also query service names that begin with an underscore, such as _dmarc.example.com, used in email authentication.

What DNS is

DNS stands for Domain Name System. It is a distributed system that translates readable names, such as example.com, into the information computers need in order to communicate.

Its best-known job is mapping names to IP addresses, but DNS holds far more: where to deliver email for a domain, which servers answer for it, which keys authorize whoever signs its messages, and which authorities may issue certificates in its name.

DNS record types

The tool queries the seven types below, which cover most day-to-day diagnosis.

  • A — points a name at an IPv4 address. This is the record that decides which server a site resolves to.
  • AAAA — the same job as A, but for IPv6 addresses. A domain can hold both at once.
  • MX — Mail Exchange, naming the servers that receive email for the domain. The number before each server is its priority: the lowest is tried first and the rest serve as fallbacks.
  • NS — Name Server, naming the DNS servers authoritative for the zone. These reveal where the domain is actually administered.
  • TXT — free text attached to the domain. In practice it carries SPF, DKIM, DMARC and the ownership proofs required by services such as Google and Microsoft.
  • CNAME — creates an alias from one name to another. A www.example.com may point at another name rather than straight at an IP.
  • SOA — Start of Authority, holding the administrative data for the zone: primary server, responsible contact, serial number and the timers governing replication between servers.

TTL and propagation

TTL stands for Time To Live and says, in seconds, how long a resolver may keep an answer cached before asking again. A TTL of 3600 means one hour.

That is why a change does not reach everyone at the same moment. Each resolver cached the old answer at a different time and discards it when its own clock runs out. During that window it is normal for people on different networks to see different answers.

There is no universal 24- or 48-hour DNS propagation period. In most cases the previous TTL is the main factor determining how long cached records stay visible, although resolver behavior, negative caching and delegation changes can affect the result. This is why the recommended practice is to lower the TTL in advance, make the change, and only then restore the usual value.

Email authentication: SPF, DKIM and DMARC

SPF, DKIM and DMARC help receiving mail servers authenticate messages that claim to come from your domain, and determine how unauthenticated messages should be handled. All three live in TXT records and all three can be checked here.

SPF sits on the domain itself and lists who may send on its behalf. DKIM sits at a name like selector._domainkey.example.com and publishes the public key that validates the signature on messages. DMARC sits at _dmarc.example.com and tells receiving servers what to do when a message fails the other two checks.

To check the DMARC policy of a domain, look up _dmarc followed by the domain and read the TXT record returned.

What a DNS lookup is for

It confirms whether a domain points at the right server, reveals which servers receive its email, shows who administers the zone, exposes verification TXT records and lets you follow the effect of a recent change.

It is especially useful during hosting migrations, SaaS setup, CDN changes and investigations where a site works for some people and not others — the classic symptom of DNS caches in transition.

Frequently asked questions

How long does a DNS change take?

There is no single figure, and no universal 24- or 48-hour period. The previous TTL is the main factor: if it was an hour, most caches will have expired within an hour. Resolver behavior, negative caching and delegation changes can extend that in some cases.

Why does DNS look different on another computer?

Because each device may use a different resolver, and each resolver holds its own cached copy, stored at a different moment. During a recent change, divergent answers are normal.

What does NXDOMAIN mean?

It is the answer saying the domain queried does not exist, as opposed to existing without records of that type. This tool tells the two apart: a non-existent domain is flagged as not found, while a valid domain with no records of a type simply shows no section for it.

Why is there no CNAME on the main domain?

Because DNS rules do not allow a CNAME to coexist with other records at the same name, and the root of a domain must carry at least SOA and NS. That is why CNAME appears on subdomains such as www rather than on example.com. Some providers work around this with their own features, called ALIAS or ANAME.

Can I see which IP a domain points to?

Yes. The A and AAAA records carry the IPv4 and IPv6 addresses associated with the name, where they exist. A domain may hold several A records, which usually indicates load balancing.

Can I check email configuration through DNS?

Yes. MX records show which servers receive messages, and TXT records carry SPF and DMARC. For DMARC, look up _dmarc followed by the domain.

Why does a domain return no records at all?

It may be a domain that exists but publishes nothing beyond the minimum, a typo, or a domain never delegated to any DNS server. The tool indicates when the domain itself does not exist, which separates a typo from missing configuration.

Found an IP address in the records and want to know which network it belongs to? Look up IP geolocation

Want to check the address your own connection uses? See what your IP is