DNS Lookup Tool

Query A, AAAA, CNAME, MX, NS, TXT, and SOA records for any domain - encrypted via DNS-over-HTTPS, no install, no API key.

Quick Answer

A DNS lookup queries the Domain Name System to see what records are published for a domain: A (IPv4 address), AAAA (IPv6), CNAME (alias), MX (mail servers), NS (authoritative nameservers), TXT (text data like SPF/DMARC), and SOA (zone admin info). This tool performs the query over HTTPS using public resolvers (Cloudflare 1.1.1.1 or Google 8.8.8.8), so it works from any browser with no software installed - the same way a "dig" or "nslookup" command works on the command line.

Key Facts

  • A records map a domain to an IPv4 address
  • AAAA records map a domain to an IPv6 address
  • MX records define mail servers (lower number = higher priority)
  • NS records list the authoritative nameservers for the zone
  • TXT records carry SPF, DKIM, DMARC, and verification strings
  • Queries run over DNS-over-HTTPS (DoH) - encrypted, no local DNS required
  • Choose resolver: Cloudflare (1.1.1.1) or Google (8.8.8.8)
  • TTL shows how long the record may be cached before re-querying

Frequently Asked Questions

A DNS lookup asks a DNS resolver for the records associated with a domain name. It is the browser-level equivalent of typing "dig example.com" or "nslookup example.com" in a terminal. The result shows where the domain points (IP addresses), who hosts its mail, and its published policy records.

MX records tell the internet where to deliver email for a domain. If mail to your address is bouncing, a missing or misprioritized MX record is a common cause. Each MX entry has a preference number - mailers try the lowest number first.

They fight email spoofing. SPF (in a TXT record) lists which servers may send mail as the domain. DKIM signs outgoing mail cryptographically. DMARC (a _dmarc TXT record) tells receivers what to do with mail that fails SPF/DKIM. Check the TXT results here to see what a domain publishes.

Usually CDN or load balancing: large sites return different A records per resolver location (geo-DNS). The record you see is what that resolver was handed at query time. Compare both resolvers in this tool, or query at different times.

TTL (time to live) is how many seconds resolvers and ISPs may cache the record before re-asking. After a DNS change, the old value can linger up to the TTL - so changes take effect gradually, worldwide, over minutes to 48 hours.

The query is sent encrypted to the chosen public resolver (Cloudflare or Google) over HTTPS - the same resolvers your browser would use. Your ISP sees a connection to the resolver, not the query contents. No data is stored by this tool.