DNS Lookup
Query DNS records for any domain. Powered by dig running server-side.
Reading a DNS answer
This page runs dig on the server and returns the raw answer section. Records resolve for A, AAAA, MX, TXT, NS, CNAME, SOA, PTR and ANY. Leaving the nameserver field blank queries the site's default resolver; filling it in sends the same question to a resolver you name, which is how you compare what different caches hand back.
TTL governs everything you are looking at. A record can be correct at the authoritative server and still stale in a local cache until the old TTL drains, which is the usual explanation for a record that is set but still resolves to the old value. Querying the zone's authoritative NS directly bypasses intermediate caches, so if the answer there is right, the problem is propagation, not configuration.
A and CNAME are not interchangeable. A name ending in a CNAME cannot also carry A or MX records at the same point, and a CNAME is illegal at a zone apex, where the provider's A, AAAA or an ALIAS record belongs. If you ask for a CNAME and get A records back, the resolver followed the chain and reported the terminal address.
ANY is not a dump of the zone. RFC 8482 lets resolvers answer it with a minimal reply, and most public resolvers either refuse it or rate-limit it hard, so an empty ANY response means nothing is broken. When a record looks wrong, check the authoritative server, then the TTL, then whether a split-horizon view is serving a different answer internally.
Related reading
- How to check DNS propagation (and how long it actually takes)Just changed an A record and your friend in another country still sees the old site? That's DNS propagation. Here's how to verify when it's actually done — and how long it can take.
- How to do a DNS lookup (and why you'd want to)DNS lookups are the first step in almost every network troubleshooting flow. Here's how they work, the record types that matter, and how to run them from your browser.
- How to read an open port (and when to actually worry)An 'open port' isn't a vulnerability by itself — it's information. Here's how to tell whether a port being open is fine, suspicious, or actively dangerous, and what to do about each case.