DNS record lookup

Type a domain or a hostname and read everything DNS publishes for it, one record type at a time. Each block says what that type is for, and we point out the few records that contradict each other.

A subdomain works too: www.example.com, mail.example.com, _dmarc.example.com.

Or try github.com, wikipedia.org

One name, several kinds of answer

People like to call the DNS the phone book of the internet. The picture works if you imagine a book where each name has several lines, one for the street address, one for the mailbox, one for the notary who keeps the file. A browser only asks for the address. A mail server only asks for the mailbox. Each kind of line is a record type, and a question to the DNS always names both the domain and the type it wants.

That’s how a domain can load perfectly in a browser while its email bounces. The two rely on different records, edited separately, often by different people.

The record types this lookup reads

TypeHoldsRead by
A, AAAAThe IPv4 and IPv6 addresses of the serverBrowsers, and anything else that connects to the name
CNAMEAnother name to use in place of this oneResolvers, which start over with the target
MXThe servers that accept mail, each with a prioritySending mail servers
NSThe name servers that hold the zoneResolvers looking for the source of truth
SOAThe zone’s primary server, contact, serial number and timersSecondary name servers
TXTFree text: SPF, DKIM keys, ownership codesMail receivers and the services you sign up for
CAAThe certificate authorities allowed to issue for the domainCertificate authorities, before issuing
DS, DNSKEYThe keys that sign the zone and the parent’s fingerprint of themResolvers that validate DNSSEC

We request all of these at the same time from a public resolver, with a second resolver as a backup for any question that gets lost. The DMARC policy is looked up as well. It’s a TXT record, but it lives on its own name, _dmarc.example.com, so a plain TXT lookup on the domain never shows it.

TXT values are matched against known formats. A value starting with v=spf1 is labeled as SPF, google-site-verification= or MS= as proof of ownership for Google or Microsoft 365, and so on for several dozen services. Mail and name server hosts are matched the same way, so aspmx.l.google.com shows up as Google Workspace / Gmail.

What the TTL column tells you

Every record carries a time to live, in seconds. That’s how long a resolver may keep the answer before asking again, so it’s also the longest a visitor can go on getting the old value after you change the record. A TTL of 3600 means up to an hour of waiting, and 300 means five minutes.

A resolver that already holds the record reports the time left, not the value you configured, so asking twice can give 3600 and then 2954. To spare you that confusion, this lookup asks one of the zone’s own name servers for the TTLs whenever it can, and the note under the results says which source was used.

Two situations get a mention, for information only: a TTL under 60 seconds, and a TTL over one day on anything other than NS records. Neither is an error. Very short values are normal at providers that move traffic between data centers through DNS. Very long ones only hurt on the day you need to move.

The conflicts it points out

More than one SPF record
A domain may publish a single TXT record starting with v=spf1. With two, receivers return a permanent error and SPF fails for every message. Merge them into one, such as v=spf1 include:_spf.google.com include:sendgrid.net ~all.
A CNAME next to other records
An alias replaces the whole name, so it can’t share it with MX, TXT or anything else. This usually happens at the top of a domain, where NS and SOA records have to exist. Use A and AAAA records there, or your DNS host’s “ALIAS”, “ANAME” or “CNAME flattening” feature.
No address record
Without A or AAAA, nothing can connect to the name. That’s expected for a name that only carries mail or verification records. For a website it’s a problem.
A single name server, or DNSSEC keys with no DS record
With one name server, the site and the mail both depend on a single machine staying up. Keys without a DS record at the registrar mean the zone is signed but nobody checks the signatures.
Mail servers without SPF, or a DMARC record on the wrong name
Both leave the domain easier to impersonate. The email authentication check goes through SPF, DKIM and DMARC in detail.

The results are what one public resolver sees right now. After a recent change, other resolvers may still hold the previous value, and you can compare them with the DNS propagation check. Records on names you didn’t type, such as DKIM keys under selector._domainkey or SRV records, aren’t listed, because the DNS offers no way to ask a domain for all of its names.

Questions people ask

How do I see all DNS records for a domain?

You ask for each record type in turn, which is what this page does for the common ones. No “give me everything” query works reliably. Most servers today refuse the ANY type or answer it partially, and records on subdomains only appear if you look up those subdomains by name.

What is the difference between an A record and a CNAME?

An A record gives an IP address directly. A CNAME gives another name, and the resolver goes and looks up that name instead. Use a CNAME when a provider tells you to point at one of their hostnames, so they can change the address without bothering you. A name with a CNAME can’t carry any other record.

How long does a DNS change take to show up?

At most the TTL the record had before you edited it, plus the few seconds your DNS host needs to publish. If the old TTL was one hour, some visitors keep the old value for up to an hour. Changing name servers at the registrar follows the TTL of the parent zone, often one or two days.

Why does my domain have so many TXT records?

Every online service you connect, from mail platforms to analytics and document signing, asks you to add a TXT code to prove the domain is yours. They pile up, and most can be deleted once the service has verified them or after you stop using it. Keep the SPF record, and check the service’s documentation before removing a code it may verify again.

What does “no MX record” mean for my email?

No server is designated to receive mail for the domain. Senders then try the address in the A record, which is usually a web server that doesn’t accept mail, and the message bounces. If the domain should never receive mail, publish a “null MX” (0 .) so senders give up at once.

Can I look up a subdomain?

Yes. Type the full hostname, for example shop.example.com. A subdomain normally has no NS or SOA record of its own. The name servers of the zone above it answer for it, and the result names that zone.