Skip to content

DNS Lookup

See the DNS records of any domain, checked live from our server.

Record type
Enter a domain to see its DNS records. Enter an IP address for a reverse (PTR) lookup.
We query the domain from our own DNS resolver on our server. Your lookups aren't shared with third-party DNS providers and results aren't stored.

How to use

  1. Enter a domain name or public IP address.
  2. Choose the record you want under Record type.
  3. Click Look up to see the records and their TTLs.
  4. Click Copy to copy the answer in zone-file format.
  5. Click Download JSON to save the full response.

Examples

Check Gmail's mail servers

Input
gmail.com
Output
gmail.com. 31 IN MX 5 gmail-smtp-in.l.google.com.
gmail.com. 31 IN MX 10 alt1.gmail-smtp-in.l.google.com.
gmail.com. 31 IN MX 20 alt2.gmail-smtp-in.l.google.com.
gmail.com. 31 IN MX 30 alt3.gmail-smtp-in.l.google.com.
gmail.com. 31 IN MX 40 alt4.gmail-smtp-in.l.google.com.

Check Google's DMARC policy

Input
_dmarc.google.com
Output
_dmarc.google.com. 300 IN TXT "v=DMARC1; p=reject; rua=mailto:mailauth-reports@google.com"

Look up an IP address's hostname

Input
8.8.8.8
Output
8.8.8.8.in-addr.arpa. 2227 IN PTR dns.google.

FAQ

What is the difference between NXDOMAIN and NODATA?

NXDOMAIN means the name doesn't exist in DNS. NODATA means the name exists but has no records of the type you requested.

Why is the TTL lower than the value in my DNS settings?

The TTL shown is the time remaining in the resolver's cache, not the original value in your DNS zone. It counts down while the record is cached.

Does this tool check DNS propagation worldwide?

No. Results show what our resolver sees from one location, not what DNS servers around the world see. A cached answer may still show your old records until its TTL expires.

What does the DNSSEC status mean?

"DNSSEC: validated" means the validating resolver checked the DNSSEC signatures and returned the AD flag. "DNSSEC: not signed or not validated" means the domain is unsigned or the answer was not validated; the status doesn't tell you which. "DNSSEC: not checked" means the configured resolver is not set up for DNSSEC validation.