sysadmintools

DNS Lookup

Query DNS records for any domain. Powered by dig running server-side.

Reading a DNS answer

This page runs dig on the server and returns the raw answer section. Records resolve for A, AAAA, MX, TXT, NS, CNAME, SOA, PTR and ANY. Leaving the nameserver field blank queries the site's default resolver; filling it in sends the same question to a resolver you name, which is how you compare what different caches hand back.

TTL governs everything you are looking at. A record can be correct at the authoritative server and still stale in a local cache until the old TTL drains, which is the usual explanation for a record that is set but still resolves to the old value. Querying the zone's authoritative NS directly bypasses intermediate caches, so if the answer there is right, the problem is propagation, not configuration.

A and CNAME are not interchangeable. A name ending in a CNAME cannot also carry A or MX records at the same point, and a CNAME is illegal at a zone apex, where the provider's A, AAAA or an ALIAS record belongs. If you ask for a CNAME and get A records back, the resolver followed the chain and reported the terminal address.

ANY is not a dump of the zone. RFC 8482 lets resolvers answer it with a minimal reply, and most public resolvers either refuse it or rate-limit it hard, so an empty ANY response means nothing is broken. When a record looks wrong, check the authoritative server, then the TTL, then whether a split-horizon view is serving a different answer internally.

Related reading