Your country

Tools that support it use your country for local currency, number formats, units and paper size. Your choice is saved only in this browser.

Type a name or a two-letter code. Use the up and down arrow keys to move through the countries, Enter to choose one and Escape to close.

DNS Lookup

Every DNS record type, straight from Cloudflare or Google, explained in plain words.

Network Uses live data Free, no sign-up

Look up DNS records

Names with underscores work (_dmarc.example.com, _443._tcp.example.com). An IP address is looked up as reverse DNS (PTR).

Resolver
Advanced options

Choose Google to ask “what would a user on this network get?” — CDNs and GeoDNS answer by location. Cloudflare never sends the client subnet on.

Try:

Next steps

About the DNS Lookup

Type a domain name and see its DNS records the way the internet sees them: addresses (A, AAAA), aliases (CNAME), mail servers (MX), text records such as SPF and DMARC (TXT), name servers and the zone’s SOA, certificate rules (CAA), HTTPS service bindings, DNSSEC keys and signatures, DANE (TLSA) and more. Choose All common types to ask for eleven types at once.

The page asks Cloudflare’s 1.1.1.1 or Google’s 8.8.8.8 resolver over DNS-over-HTTPS (RFC 8484) and reads the raw DNS answer itself, so you get the TTL, the response code, the DNSSEC flag, alias chains and resolver diagnostics — and each record is explained: who handles your mail, which certificate authorities may issue certificates, what the SOA timers mean.

How to use it

  1. Enter a domain such as example.com, a service name such as _dmarc.example.com, or an IP address for reverse DNS.
  2. Pick a record type, or All common types (A, AAAA, CNAME, MX, NS, TXT, SOA, CAA, HTTPS, DS and DNSKEY).
  3. Choose the resolver. Under Advanced options you can show DNSSEC signatures, switch DNSSEC validation off, or send Google a client subnet to see what users on another network get.
  4. Press Look up. Records appear grouped by type with their TTL and a plain-language explanation; SPF, DMARC and DKIM records link to their checkers.
  5. Use Copy or Zone file for zone-file lines, or JSON for every flag and parsed field.

Examples

A domain that does not accept e-mail
Input
example.com — MX
Result
example.com. IN MX 0 .
Null MX (RFC 7505): this domain does not accept e-mail.

A single MX record with preference 0 and the root name “.” tells senders to give up at once instead of retrying for days.

An HTTPS service binding
Input
cloudflare.com — HTTPS
Result
1 . alpn=h3,h2 ipv4hint=104.16.132.229,104.16.133.229 ipv6hint=2606:4700::6810:84e5,2606:4700::6810:85e5

Browsers learn from this record (RFC 9460) that the site speaks HTTP/3 before they connect.

Reverse DNS for an IP address
Input
8.8.8.8
Result
8.8.8.8.in-addr.arpa. PTR dns.google.
A DNSSEC failure, explained by the resolver
Input
dnssec-failed.org — A
Result
SERVFAIL — Extended DNS Error 9 (DNSKEY missing): no SEP matching the DS found for dnssec-failed.org.

dnssec-failed.org is deliberately mis-signed for testing. Tick “Disable DNSSEC validation” to see the records anyway.

Common uses

  • Checking that a new A, CNAME or MX record is live after a change at your DNS host.
  • Finding the TXT verification token a service asked you to add — or spotting a duplicate SPF record.
  • Seeing which certificate authorities a CAA record allows before you order a TLS certificate.
  • Debugging DNSSEC: comparing DS and DNSKEY key tags, reading signature validity dates and the resolver’s error code.
  • Seeing which IP addresses a CDN hands to users in another region (Google + client subnet).

Reading the answer

  • NOERROR with records: the name exists and has records of that type. NOERROR without records: the name exists but not with that type.
  • NXDOMAIN: the name does not exist at all. Resolvers cache that for the SOA’s negative TTL (RFC 2308), which the page shows.
  • SERVFAIL: the resolver could not get a trustworthy answer — the domain’s name servers are down or answering wrongly, or DNSSEC validation failed. Resolvers add an Extended DNS Error code that says why (RFC 8914); the page shows it.
  • TTL is how many more seconds the resolver may keep its cached copy — the maximum wait before a change you made reaches that resolver.
  • DNSSEC validated means the resolver checked the signatures from the root down (the AD flag). Not validated means the zone is not signed, or a link in the chain is unsigned.

Why there is no “ANY” query

Asking a server for type ANY used to return every record at a name. RFC 8482 lets servers answer ANY with a single, arbitrary record set instead — often a placeholder HINFO record with the text “RFC8482” — because ANY was abused for attacks. All common types therefore sends one query per type, in parallel.

Client subnet: what users elsewhere see

Many CDNs and GeoDNS services answer with different addresses depending on where the user is. Google Public DNS passes a short prefix of the user’s address to such name servers (EDNS Client Subnet, RFC 7871), and lets you choose that prefix: enter a network such as 49.36.0.0/24 to see its answer. The “scope” in the result says how widely the answer applies — /0 means the same for everyone. Cloudflare’s resolver does not send client-subnet information, for privacy (1.1.1.1 FAQ), so the option is Google-only. To compare many locations at once, use the DNS propagation checker.

Sources

Limitations

  • You see what the chosen public resolver returns, including its cache. A change can take up to the old record’s TTL to appear there; your own ISP’s resolver may still show older data.
  • Browsers cannot send ordinary DNS packets, so the page cannot ask a domain’s own name servers directly or do zone transfers (AXFR).
  • Internal names that exist only on a company or home network (for example on a router) are not visible to public resolvers.
  • Very frequent lookups can be rate-limited by the resolver (HTTP 429); wait a minute and try again.

Privacy

Each query goes from your browser to Cloudflare (cloudflare-dns.com) or Google (dns.google), without cookies; that resolver sees your IP address and the name you look up, as it would for any DNS query. A client subnet you enter is sent to Google and on to the domain’s name servers. MySmartCoPilot’s servers are not involved and store nothing.

Frequently asked questions

Why does the page show a different IP address than my computer gets?

Large sites and CDNs give different addresses to different networks, and your computer may use another resolver with an older cached answer. Use the client-subnet option (Google) or the DNS propagation checker to compare locations.

How long until my DNS change is visible?

Up to the TTL of the old record, counted from when each resolver last fetched it. If you lowered the TTL a day before the change, it takes minutes; with a TTL of 86400 it can take a day. A record that did not exist before can be cached as “does not exist” for the SOA’s negative TTL.

What does NXDOMAIN mean?

The name does not exist in the DNS at all — not even with other record types. Check the spelling, and whether the record was created in the right zone (a common mistake is creating www.example.com.example.com).

Why are the records shown under a different name?

The name is an alias (CNAME). The resolver followed it, and the records belong to the final name in the chain, which the page shows. A CNAME cannot sit next to other records at the same name, which is why the zone apex usually cannot be a CNAME.

What do the DS and DNSKEY records tell me?

The DS record in the parent zone holds a hash of the child zone’s key-signing key. For DNSSEC to work, its key tag and algorithm must match a DNSKEY published by the domain — the page computes each DNSKEY’s key tag (RFC 4034, Appendix B) so you can compare them.

Is this the same as nslookup or dig?

It answers the same questions as dig example.com MX against a public resolver, with the flags, TTLs and DNSSEC data dig shows, and adds explanations. Unlike dig it cannot query a specific name server, because browsers can only use DNS-over-HTTPS services.

Quick answers and tool search

Type to search tools or to get a quick answer, for example 18% of 2500. Use the up and down arrow keys to move through the results, Enter to choose, and Escape to close.