MX lookup
The mail servers for a domain or email address, in priority order, with their addresses.
Worker → Cloudflare DNS. The NetOkay Worker asks Cloudflare’s public resolver over HTTPS for the MX records and each mail server’s addresses. Nothing connects to the mail servers, and the domain leaves this page only when you start.
Reading the results
- Priority
- The MX preference number. Sending servers try the lowest number first and move to the next only if it does not answer. Records with the same number share the load.
- Mail server
- The host name that accepts email for the domain. It must be a name, not an IP address, and it should not be an alias (CNAME).
- Addresses
- The IPv4 and IPv6 addresses that mail server name resolves to. A server without an address cannot receive mail, whatever its priority.
- TTL
- How many more seconds the resolver may reuse the MX answer. After you change MX records, other servers can keep the old ones for up to the old TTL.
- Mail provider
-
Recognised from well-known host names, such as
google.comfor Google Workspace ormail.protection.outlook.comfor Microsoft 365. A filtering gateway or forwarder can sit in front of the real mailbox provider; DNS shows only the first hop. - Null MX
-
A single record of
0 .means the domain deliberately accepts no email (RFC 7505). Senders give up at once instead of retrying. - No MX record
- Senders then try the domain’s own A or AAAA address, called an implicit MX (RFC 5321). The lookup shows that address when it exists. Most domains that receive mail publish MX records instead of relying on this.
MX problems this lookup shows
- A mail server with no address. The MX names a host that does not exist or has no A or AAAA record, often after a provider change or a typo. Mail to that server fails, and if it is the only one, all mail to the domain bounces.
- An MX that points to an alias. RFC 2181 says an MX target must not be a CNAME. Most senders still follow it, but some refuse, so delivery becomes uneven.
- An MX written as an IP address. MX values must be host names. Many senders reject an address in that place.
- The old provider still listed. After a move, both the old and the new mail servers appear. Senders follow the priorities, so mail keeps reaching the old servers whenever they rank first or tie, until the old records are removed.
- The domain does not exist. An expired registration or a typo in the address. The lookup says so instead of showing an empty list.
How this lookup works
The NetOkay Worker sends one DNS-over-HTTPS query for the MX records to
cloudflare-dns.com, the same resolver as 1.1.1.1, then A and AAAA queries
for up to ten mail servers. When you enter an email address, only the domain after the @
is sent.
- A mail server that resolves to a private or reserved address is shown without that address, under the same public-target policy as the website check.
- A result for the same domain can be reused for up to five minutes, and requests are rate limited per connection; wait about a minute if the limit is reached.
- The answer is one resolver’s view at one moment, not a propagation check across resolvers worldwide.
What this lookup does not check
- Whether a mail server accepts connections on port 25 or offers STARTTLS. Nothing connects to the mail servers.
-
Whether a particular mailbox exists. An MX lookup tells you where mail for a domain
goes, not whether
name@that domain is a real address. - SPF, DMARC and DKIM. The website check looks those up in its mail section, and the DNS lookup lists the domain’s TXT records.
- Blocklist status or reputation of the mail server addresses, reverse DNS (PTR) for those addresses, or many domains at once.
Look up MX records from a terminal
The same MX query, against Cloudflare’s DNS-over-HTTPS endpoint:
curl -s -H 'accept: application/dns-json' \
'https://cloudflare-dns.com/dns-query?name=example.com&type=MX'
With dig, nslookup or PowerShell:
dig @1.1.1.1 example.com MX +short
nslookup -type=mx example.com 1.1.1.1
Resolve-DnsName -Name example.com -Type MX -Server 1.1.1.1
Then resolve a mail server name the same way, for example
dig @1.1.1.1 mx1.example.com A +short, to see its address.
MX lookup FAQ
What does the MX priority number mean?
It is a preference, not a rank of quality. Senders try the lowest number first. A higher number is a backup used only when the lower ones do not answer.
Can two MX records have the same priority?
Yes. Senders pick between them at random, which spreads mail across both servers. Large providers often publish several servers at the same priority.
I switched email providers. Why do I still see the old MX records?
Either the old records are still in the zone, or resolvers are still serving them until their TTL runs out. This page may also reuse a lookup for up to five minutes. Check the TTL, remove any old records at your DNS host, and look again after it expires.
Does an MX lookup tell me whether an email address exists?
No. It shows where mail for the domain is delivered. Whether a mailbox exists is known only to the receiving mail server.
Why does it show Proofpoint or Mimecast instead of Microsoft 365?
The domain routes its mail through a filtering gateway first. The gateway scans messages and then passes them to the mailbox provider, which DNS does not reveal.