Reverse DNS lookup
Enter an IP address to get the host name it answers to. The lookup then checks that the name points back to the same address, which is the test mail servers run before they’ll accept a message.
The DNS, read backwards
Most of the time, the DNS turns a name into an address: dns.google gives 8.8.8.8. A reverse lookup goes the other way and asks which name belongs to 8.8.8.8. The DNS has no index by address, so the question gets dressed up as an ordinary name. The four numbers are written in reverse order and placed under a special domain:
8.8.4.4 → 4.4.8.8.in-addr.arpa
For IPv6, the 32 hexadecimal digits of the full address are reversed one by one under ip6.arpa. The answer, when there is one, is a PTR (“pointer”) record that holds a host name. The results show the exact name that was queried, which comes in handy the day you have to create the record yourself.
The order is reversed for the same reason a domain name reads from specific to general. That way the range 8.8.4.x can be handed to one organization as the zone 4.8.8.in-addr.arpa.
Who controls the answer
This part surprises most people. The reverse record of an address doesn’t live in your domain’s DNS zone. It belongs to whoever was assigned the address range, which means the hosting company, the cloud platform or the internet provider. Owning example.com gives you no say over what 203.0.113.25 answers.
To change it, look for “reverse DNS”, “rDNS” or “PTR” in the server’s control panel, or open a ticket with the provider. Home and mobile connections usually get an automatic name built from the address, such as host-203-0-113-25.dynamic.provider.net, and you can’t change it.
Forward-confirmed reverse DNS
The owner of an address range can write anything in a PTR record, including mail.your-bank.com, so a reverse name by itself proves nothing. The proof comes from going back the other way. Take the name, look up its A record (or AAAA for IPv6), and see whether the original address is in the answer. If it is, the owner of the address and the owner of the name agree, and the pair is called forward-confirmed (FCrDNS).
This lookup does that for up to five names per address and reports one of these:
- Confirmed both ways
- The name resolves to the address you entered.
- Not confirmed
- The name resolves to other addresses, or to none. For a mail server this counts as a failure.
- No PTR record
- The address has no name. That’s normal for many devices and a problem for a server that sends mail.
Mail is where all this matters most. Gmail requires a sending address to have a PTR record, and that record to be forward-confirmed. The other large mailbox providers apply the same rule, and mail from an address that fails gets rejected or sent to junk. Many receivers also compare the name with the one the server announces in its greeting. To test the mail servers of a domain, use the MX and TLS test. To see whether an address has a bad reputation, there’s the blocklist lookup.
Addresses with nothing to look up
Some ranges are set aside and never show up on the public internet. The lookup recognizes them and explains them without sending a query:
| Range | What it is |
|---|---|
10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, fc00::/7 | Private networks: home, office, data center |
127.0.0.0/8, ::1 | Loopback: the machine itself |
169.254.0.0/16, fe80::/10 | Link-local: self-assigned, one network segment only |
100.64.0.0/10 | Carrier-grade NAT: the provider’s shared inner network |
192.0.2.0/24, 198.51.100.0/24, 203.0.113.0/24, 2001:db8::/32 | Documentation examples |
224.0.0.0/4, ff00::/8 | Multicast groups |
If “Use my address” lands in one of these, you’re looking at a local copy of the page or sitting behind an unusual proxy.
A reverse name tells you what the operator of the address chose to publish. It doesn’t list the websites hosted on the address, and this page doesn’t try to. When our server has a network database available, the result also names the network and country of the address, read locally without contacting any outside service.
Questions people ask
How do I set a PTR record for my server?
Ask the provider of the IP address, not your domain registrar. Most hosting and cloud panels have a “reverse DNS” field next to each address. Set it to the server’s full host name, then make sure that name has an A (or AAAA) record with the same address.
Why does my IP address have no reverse DNS?
Because the owner of the address range never created a PTR record for it, and nothing requires one. It only becomes a problem when the address sends mail or when a service you connect to insists on it.
Can one IP address have several PTR records?
The DNS allows it, but it’s discouraged. Most programs read a single name, some fail when the answer grows too large, and mail servers may pick one that doesn’t match. The safe setup is one name per address.
Does the PTR record have to match my domain name?
Not your website’s domain. For a mail server, it should match the host name the server uses in its SMTP greeting (for example mail.example.com), and that name has to resolve back to the address. Plenty of sites on one address share a single reverse name with no trouble at all.
Can a reverse lookup show every website hosted on an IP address?
No. A PTR record holds the name the operator chose, usually one. Lists of “other sites on this IP” come from databases built by crawling the web, not from the DNS, and this tool doesn’t provide them.
What do in-addr.arpa and ip6.arpa mean?
They’re the two branches of the DNS reserved for reverse lookups: in-addr.arpa for IPv4 and ip6.arpa for IPv6. An address is written backwards under one of them to form the name whose PTR record is queried.