VMHeaven

Free tool

DNS lookup

Free DNS lookup: A, AAAA, CNAME, MX, NS, TXT, SOA, CAA, SRV and DS records of any domain, or the reverse DNS (PTR) of an IP, with TTLs and DNSSEC status.

Look up DNS records

Try:

Answered by our own validating resolver in Amsterdam (TechTies network, NL), which asks each domain’s name servers directly and checks DNSSEC signatures.

DNS record types

TypeWhat it holdsExample value
AThe IPv4 address a name points to203.0.113.10
AAAAThe IPv6 address a name points to2001:db8::10
CNAMEAn alias: this name is another namewww → example.com
MXThe mail servers for a domain, lowest number first10 mx1.example.com
NSThe name servers that answer for the domainns1.example.net
TXTFree text: SPF, DKIM, DMARC, site verificationv=spf1 mx -all
SOAThe zone's primary server, contact, serial and timersns1.example.net hostmaster.example.com 2026101001 …
CAAWhich certificate authorities may issue for the domain0 issue "letsencrypt.org"
SRVA service's host and port, for SIP, XMPP, Minecraft and others_minecraft._tcp → 0 5 25565 mc.example.com
DSThe DNSSEC key fingerprint the parent zone holds for the domain2371 13 2 1F98…
PTRReverse DNS: the name an IP address points back to10.113.0.203.in-addr.arpa → mail.example.com

How to read the result

  • TTL is how long a resolver may keep the answer before asking again. It is what decides how fast a change reaches everybody: a record with a one-hour TTL can be served from caches for up to an hour after you edit it.
  • A CNAME line above an A or AAAA answer means the name is an alias, and the addresses belong to the name it points to.
  • NXDOMAIN means the name does not exist; no records means it exists without that type. A newly registered domain answers NXDOMAIN until its name servers are set at the registry.
  • All asks for the eight common types at once (everything but SRV, DS and PTR). It is the quickest way to see a domain’s whole setup before you point it at a new server.

The answers come from our own resolver on the test server in Amsterdam. It asks each domain’s name servers itself, keeps answers only for their TTL, and checks DNSSEC signatures: “DNSSEC validated” appears when the zone is signed and the signatures check out, and a zone whose signatures are broken answers SERVFAIL here, as it does for every validating resolver. To see whether the big public resolvers already have a new value, use the DNS propagation checker.

The same lookups from a terminal

Linux · macOS
dig example.com A +short
dig example.com MX +short
dig _dmarc.example.com TXT +short
dig -x 203.0.113.10 +short          # reverse DNS (PTR)
dig @1.1.1.1 example.com AAAA       # ask a particular resolver
Windows · PowerShell
Resolve-DnsName example.com -Type MX
nslookup -type=txt example.com

If the shell answers dig: command not found, install dnsutils on Debian and Ubuntu or bind-utils on Rocky Linux and AlmaLinux. When names stop resolving on a server altogether, the error is usually Temporary failure in name resolution, a problem with the server’s own resolver rather than with the domain.

Frequently asked

What does a DNS lookup show?

What the Domain Name System holds for a name: the IPv4 (A) and IPv6 (AAAA) addresses a website lives at, the mail servers (MX) that take its e-mail, the TXT records that carry SPF, DKIM and verification strings, the name servers (NS) responsible for it and more. This tool asks our own resolver in Amsterdam, which goes to the domain's name servers itself and checks DNSSEC signatures where the zone has them, and shows each record with its TTL — the seconds a resolver may keep it cached.

How do I look up the MX records of a domain?

Choose MX and enter the domain itself, not the mail server. Each answer has a preference number and a host; sending servers try the lowest number first. A domain without MX records gets mail delivered to its A record, if it accepts mail at all.

How does a reverse DNS (PTR) lookup work?

The address is turned around into a name under in-addr.arpa for IPv4 or ip6.arpa for IPv6 — 203.0.113.7 becomes 7.113.0.203.in-addr.arpa — and the PTR record at that name gives the host name. It is set by whoever holds the address block, which for a server usually means its hosting panel. Mail servers check that it points to a name that resolves back to the same address.

What does NXDOMAIN mean?

That the name does not exist at all, with no records of any type. “No records of this type” is something else: the name exists but has nothing of the type you asked for — a domain without IPv6 has no AAAA records, for example.

Why does the result differ from what my computer sees?

Every resolver caches an answer for the record's TTL, so after a change some keep returning the old value until their copy expires, and large sites hand out different addresses depending on where the question comes from. The DNS propagation checker asks twelve public resolvers and the domain's own name server at once, to show which ones already have the new value.

Related guides

More free tools

All tools