Tools /

DNS lookup

A, AAAA, CNAME, NS, MX, TXT and CAA records for any public domain, in one lookup.

Public domain names · a pasted URL is reduced to its host · no IP addresses

Worker → Cloudflare DNS. The NetOkay Worker asks Cloudflare’s public resolver over HTTPS. Nothing is sent to the site itself, and the domain leaves this page only when you start.

What each record tells you

A and AAAA
The IPv4 (A) and IPv6 (AAAA) addresses a name resolves to. No AAAA record means the name has no IPv6 address, which is common and not an error.
CNAME
An alias: the name points at another name, and the resolver follows it to the final records. When you look up an alias, the CNAME card shows the chain first and every other record belongs to the name it points to.
NS
The nameservers that hold the zone, which tells you which DNS provider answers for the domain. Look up the registered domain (example.com), not a subdomain, to see them.
MX
The mail servers that accept email for the domain, with a preference number; lower numbers are tried first. A domain without MX records publishes no mail server. The MX lookup also resolves each mail server’s address.
TXT
Free-form text used for SPF policies (v=spf1 …) and site verification tokens. DMARC and DKIM sit on their own names, so the website check looks those up separately.
CAA
Which certificate authorities may issue TLS certificates for the domain. No CAA record means any authority may issue.

How this lookup works

Each record type is a separate DNS-over-HTTPS query from the NetOkay Worker to cloudflare-dns.com, the same resolver as 1.1.1.1. The TTL column is the remaining time, in seconds, that this resolver may keep reusing the answer.

  • Addresses that point into private or reserved ranges are withheld, not shown, under the same public-target policy as the website check.
  • A result for the same domain can be reused for up to five minutes, and requests are rate limited per connection; wait about a minute if the limit is reached.
  • The answer is one resolver’s view at one moment. It is not a propagation check across resolvers worldwide.

What this lookup does not show

  • Reverse DNS (PTR) for an IP address, and SRV or SOA records. Use dig from a terminal for those.
  • Whether DNSSEC signatures validate. The website check has a separate DNSSEC check.
  • What your own device resolves. A VPN, a corporate resolver or a hosts-file entry can return a different answer from Cloudflare’s. If the IP you reach is not the one listed here, start with browser or curl works, your app fails.

Do a DNS lookup from a terminal

The same query this page makes, against Cloudflare’s DNS-over-HTTPS endpoint:

curl -s -H 'accept: application/dns-json' \
  'https://cloudflare-dns.com/dns-query?name=example.com&type=MX'

With dig or nslookup, asking the same resolver:

dig @1.1.1.1 example.com A +noall +answer
dig @1.1.1.1 example.com NS +short
nslookup -type=TXT example.com 1.1.1.1

Leave out @1.1.1.1 (or the trailing server in nslookup) to see what your own configured resolver returns instead.

DNS lookup FAQ

Why does this show a different IP from the one my computer uses?

Large sites answer differently by location, and your device may use another resolver, a VPN’s DNS or a hosts-file entry. Both answers can be correct for where they were asked. Compare with dig on your machine to see your own view.

Why is there no NS record for my subdomain?

Nameservers are normally set once for the registered domain. A subdomain inherits them unless it is delegated to other servers, so an empty NS result at a subdomain is usual.

I changed a record. Why does it still show the old value?

Resolvers keep an answer until its TTL runs out, and this page may reuse a lookup for up to five minutes. Check the TTL on the old record and look again after it expires.

Can I look up an IP address?

Not here. This page resolves domain names only. Reverse lookups for IP addresses are out of scope.