Query any DNS record type the way a real resolver does. Choose a public resolver (Google, Cloudflare, Quad9, OpenDNS and others) or ask the domain’s authoritative name server directly to see what is published before caches catch up. Enter an IP address instead of a domain to get its PTR record.
Table of Contents
Reading the results
Each row shows the record type, the name that answered, the remaining TTL in seconds and the value. A TTL lower than the zone’s configured value means the answer came from a cache. “ALL” queries the common types one by one, because most resolvers no longer answer ANY queries.
The DNSSEC line reports whether the resolver validated the answer (the AD flag). “Signed and validated” means the zone has DNSSEC and the chain of trust checks out; if a signed zone ever fails validation, validating resolvers such as Google and Cloudflare return SERVFAIL instead of an answer.
DNS lookup at a glance



How to use this tool
- Enter a domain name such as
example.comor a host such asmail.example.com. You can paste a full URL: the scheme, path and port are stripped, and internationalised names are converted to punycode automatically. - Pick a record type. The list covers A, AAAA, CNAME, MX, NS, TXT, SOA, CAA, SRV, PTR, DS, DNSKEY and HTTPS. ALL runs A, AAAA, CNAME, MX, NS, TXT, SOA, CAA, HTTPS, DS and DNSKEY one after another; SRV and PTR are not part of ALL, so query them on their own.
- Pick a resolver. Cloudflare (1.1.1.1) is the default. Authoritative name server finds the NS records for the zone and asks the first listed name server directly, which shows what the zone publishes right now, without any cache in between. The other 17 entries are public resolvers in North America, Europe and Asia.
- To look up a PTR record, type an IP address (IPv4 or IPv6). The tool switches the type to PTR and builds the
in-addr.arpaorip6.arpaname for you. - Press Look up. Identical queries are cached on our side for five minutes; a cached answer is marked “(cached result)” next to the check time.
For SRV records, include the service and protocol labels in the name, for example _sip._tcp.example.com or _autodiscover._tcp.example.com. The tool queries exactly the name you type.
How to read the results
Above the table you see which resolver answered (with its IP), the response time of the last query in milliseconds and the DNSSEC line. The table itself has four columns.
| Column or value | What it means |
|---|---|
| Type | The record type of each answer row. When you ask for an A record on a name that is a CNAME, you get a CNAME row first and then the A rows of the target, exactly as the resolver returned them. |
| Name | The owner name of the record. With a CNAME chain this changes from row to row, which shows you where the alias leads. |
| TTL | Seconds the answer may still be cached. From the authoritative server it is the configured TTL; from a public resolver it counts down. |
| Value | The record data. MX shows preference and host, SRV shows priority, weight, port and target, CAA shows flags, tag and value. |
| No A records (or another type) | The name exists but has no record of that type (often called NODATA). A missing record, not a missing domain. |
| NXDOMAIN | The name does not exist at all. With ALL selected the tool stops at the first NXDOMAIN, because every other type would give the same answer. |
| SERVFAIL | The resolver could not get a usable answer: the authoritative servers did not respond, the delegation is broken, or DNSSEC validation failed. |
| REFUSED | The server refused to answer. Typical when an authoritative server is asked about a zone it does not host. |
| Error: timeout | No reply within 2 seconds from the chosen resolver. Try another resolver; if all time out for one domain, check its name servers. |
A few values are easier to read once you know their layout:
- SOA: primary name server, contact mailbox (the first dot stands for @), serial, refresh, retry, expire and minimum. The last number also sets how long resolvers cache a “does not exist” answer.
- MX “0 “ with an empty host is a null MX (RFC 7505, written
0 .in a zone file). It states that the domain accepts no mail. - DNSKEY rows show flags 257 (key signing key, KSK) or 256 (zone signing key, ZSK), the protocol, the algorithm number and the key tag. DS rows show key tag, algorithm, digest type and digest; the key tag in the DS at the parent must match a KSK here.
- HTTPS shows the priority and target name; a target of “.” means the record applies to the name itself. The parameters are summarised as a byte count.
The DNSSEC line depends on the resolver. Authoritative servers never set the AD flag, so a signed zone queried with “Authoritative name server” shows “Not validated”. Use a validating resolver such as Cloudflare, Google or Quad9, or the DNSSEC checker, to test the chain of trust.
Common problems and how to fix them
The record exists in the zone editor but the lookup says “No TXT records”
Check the name first. Many panels append the domain automatically, so entering _dmarc.example.com as the host creates _dmarc.example.com.example.com. Query the doubled name to confirm, then recreate the record with only _dmarc as the host. Second suspect: the zone you edited is not the one the world uses. Compare the NS records shown here with the server where you made the change (for example a cPanel server whose domain is actually on Cloudflare DNS).
dig +short NS example.com
dig +short TXT _dmarc.example.com.example.com
SERVFAIL from Google, Cloudflare and Quad9, but the authoritative server answers
This pattern usually means DNSSEC is broken: the parent zone still has a DS record but the zone is no longer signed with a matching key, often after moving DNS to a new provider. Validating resolvers reject the answer; non-validating ones accept it. Either sign the zone at the new provider and publish its DS at the registrar, or remove the DS record at the registrar. You can confirm by repeating the query with checking disabled:
dig example.com A @1.1.1.1 +cd
dig example.com DS +short
The authoritative server returns the new value, public resolvers the old one
That is caching, not an error. The old answer stays until the TTL shown in the public resolver row reaches zero. The DNS propagation checker shows the remaining TTL on 17 resolvers at once.
CNAME record cannot be added at the root of the domain
A name with a CNAME may not carry any other records (RFC 1034), and the zone apex always has SOA and NS records. Use an A/AAAA record at the apex, or a provider feature that resolves the alias for you, such as Cloudflare CNAME flattening. A CNAME on www is fine.
The domain resolves to a Cloudflare IP instead of my server
A record set to Proxied (orange cloud) in Cloudflare always returns Cloudflare addresses, so your origin IP never appears in public DNS. That is intended. Mail host names such as mail.example.com must be DNS only (grey cloud), because Cloudflare does not proxy SMTP or IMAP.
Results differ from what my own computer shows
Your PC, router or company resolver keeps its own cache. Flush it and query a public resolver directly:
# Windows (PowerShell)
Clear-DnsClientCache
Resolve-DnsName example.com -Type MX -Server 1.1.1.1
# Linux with systemd-resolved
resolvectl flush-caches
dig example.com MX @1.1.1.1 +noall +answer
# macOS
sudo dscacheutil -flushcache; sudo killall -HUP mDNSResponder
Which record type answers which question
| Question | Query |
|---|---|
| Where does the website point? | A and AAAA (and CNAME for www) |
| Where is mail for the domain delivered? | MX, then A/AAAA of each MX host (or use the MX lookup) |
| Which DNS provider hosts the zone? | NS, then SOA for the primary server and serial |
| Is a verification, SPF or DMARC record live? | TXT on the exact name, e.g. _dmarc.example.com |
| Which CAs may issue certificates? | CAA on the domain (inherited by subdomains without their own CAA) |
| Is DNSSEC configured? | DS (published at the parent) and DNSKEY (in the zone) |
| Where does a service such as SIP or autodiscover live? | SRV on _service._proto.example.com |
| Which host name belongs to an IP? | Enter the IP to get its PTR record |
Official documentation: AlmaLinux wiki, Linux man pages.
Related guides: Cloudflare Tunnel (cloudflared): expose an internal service without opening ports · Cloudflare in front of cPanel: DNS, proxy mode and real visitor IPs done right · Adding MailBaby SPF, DKIM and DMARC records in Cloudflare DNS.
Frequently asked questions
Why does the authoritative server show a different value than Google?
The authoritative server always returns the current zone data, while public resolvers keep the previous answer until its TTL expires. Wait out the TTL or lower it before planned changes.
What does NXDOMAIN mean?
The name does not exist in DNS at all. Check the spelling, and for a new domain confirm the registrar is pointing at the right name servers.
Can I look up a PTR record here?
Yes. Enter the IP address and the tool converts it to its in-addr.arpa or ip6.arpa name and queries the PTR record.
Which resolvers can I choose?
Cloudflare, Google, Quad9, OpenDNS, Level3, Hurricane Electric, Comodo, CleanBrowsing, Control D, CIRA, AdGuard, DNS.SB, DNS4EU, Yandex, AliDNS, 114DNS and KT, plus the domain’s own authoritative name server.
Why does a signed domain show “Not validated” with the authoritative server?
Authoritative servers never set the AD (authenticated data) flag; only a validating resolver does. Repeat the lookup through Cloudflare, Google or Quad9 to see the DNSSEC result.
Why does ALL not show SRV or PTR records?
SRV records live on names such as _sip._tcp.example.com and PTR records on reverse names, so they are never found on the bare domain. Query them on their own name.
Why does the TTL change every time I look up the same record?
Public resolvers report how many seconds the cached copy has left, so the value counts down until the resolver fetches a fresh answer. The authoritative server always shows the configured TTL.
How do I query a record from the command line?
Use dig example.com MX @1.1.1.1 on Linux or macOS, and Resolve-DnsName example.com -Type MX -Server 1.1.1.1 or nslookup -type=mx example.com 1.1.1.1 on Windows.
What does a null MX record look like?
It is an MX record with preference 0 and the root name as host (0 .). This tool shows it as “0 ” with an empty host, and it means the domain does not accept email.