DNS record types
| Type | What it holds | Example value |
|---|---|---|
| A | The IPv4 address a name points to | 203.0.113.10 |
| AAAA | The IPv6 address a name points to | 2001:db8::10 |
| CNAME | An alias: this name is another name | www → example.com |
| MX | The mail servers for a domain, lowest number first | 10 mx1.example.com |
| NS | The name servers that answer for the domain | ns1.example.net |
| TXT | Free text: SPF, DKIM, DMARC, site verification | v=spf1 mx -all |
| SOA | The zone's primary server, contact, serial and timers | ns1.example.net hostmaster.example.com 2026101001 … |
| CAA | Which certificate authorities may issue for the domain | 0 issue "letsencrypt.org" |
| SRV | A service's host and port, for SIP, XMPP, Minecraft and others | _minecraft._tcp → 0 5 25565 mc.example.com |
| DS | The DNSSEC key fingerprint the parent zone holds for the domain | 2371 13 2 1F98… |
| PTR | Reverse DNS: the name an IP address points back to | 10.113.0.203.in-addr.arpa → mail.example.com |
How to read the result
- TTL is how long a resolver may keep the answer before asking again. It is what decides how fast a change reaches everybody: a record with a one-hour TTL can be served from caches for up to an hour after you edit it.
- A CNAME line above an A or AAAA answer means the name is an alias, and the addresses belong to the name it points to.
- NXDOMAIN means the name does not exist; no records means it exists without that type. A newly registered domain answers NXDOMAIN until its name servers are set at the registry.
- All asks for the eight common types at once (everything but SRV, DS and PTR). It is the quickest way to see a domain’s whole setup before you point it at a new server.
The answers come from our own resolver on the test server in Amsterdam. It asks each domain’s name servers itself, keeps answers only for their TTL, and checks DNSSEC signatures: “DNSSEC validated” appears when the zone is signed and the signatures check out, and a zone whose signatures are broken answers SERVFAIL here, as it does for every validating resolver. To see whether the big public resolvers already have a new value, use the DNS propagation checker.
The same lookups from a terminal
dig example.com A +short
dig example.com MX +short
dig _dmarc.example.com TXT +short
dig -x 203.0.113.10 +short # reverse DNS (PTR)
dig @1.1.1.1 example.com AAAA # ask a particular resolverResolve-DnsName example.com -Type MX
nslookup -type=txt example.comIf the shell answers dig: command not found, install dnsutils on Debian and Ubuntu or bind-utils on Rocky Linux and AlmaLinux. When names stop resolving on a server altogether, the error is usually Temporary failure in name resolution, a problem with the server’s own resolver rather than with the domain.
Frequently asked
What does a DNS lookup show?
What the Domain Name System holds for a name: the IPv4 (A) and IPv6 (AAAA) addresses a website lives at, the mail servers (MX) that take its e-mail, the TXT records that carry SPF, DKIM and verification strings, the name servers (NS) responsible for it and more. This tool asks our own resolver in Amsterdam, which goes to the domain's name servers itself and checks DNSSEC signatures where the zone has them, and shows each record with its TTL — the seconds a resolver may keep it cached.
How do I look up the MX records of a domain?
Choose MX and enter the domain itself, not the mail server. Each answer has a preference number and a host; sending servers try the lowest number first. A domain without MX records gets mail delivered to its A record, if it accepts mail at all.
How does a reverse DNS (PTR) lookup work?
The address is turned around into a name under in-addr.arpa for IPv4 or ip6.arpa for IPv6 — 203.0.113.7 becomes 7.113.0.203.in-addr.arpa — and the PTR record at that name gives the host name. It is set by whoever holds the address block, which for a server usually means its hosting panel. Mail servers check that it points to a name that resolves back to the same address.
What does NXDOMAIN mean?
That the name does not exist at all, with no records of any type. “No records of this type” is something else: the name exists but has nothing of the type you asked for — a domain without IPv6 has no AAAA records, for example.
Why does the result differ from what my computer sees?
Every resolver caches an answer for the record's TTL, so after a change some keep returning the old value until their copy expires, and large sites hand out different addresses depending on where the question comes from. The DNS propagation checker asks twelve public resolvers and the domain's own name server at once, to show which ones already have the new value.