DNS Lookup

5 of 2 ratings
DNS Lookup

DNS Lookup is a free tool that finds A, AAAA, CNAME, MX, NS, TXT, SOA and CAA records for a host and displays their DNS values.

What does a DNS lookup check?

A DNS lookup checks the records published for a domain name or host. The Domain Name System, usually shortened to DNS, links readable names such as www.example.com to addresses and configuration data used by browsers, mail servers and other internet services.

Different record types answer different questions. An A record contains an IPv4 address, while an AAAA record contains an IPv6 address. A CNAME points one hostname to another. MX records direct email, NS records identify authoritative nameservers, TXT records publish text-based policies or verification values, and the SOA record contains administrative and timing information for the DNS zone.

The lookup runs on the server using the supplied host. Your Host input travels to the server over HTTPS and is not stored. The result describes only the returned A, AAAA, CNAME, MX, NS, TXT, SOA and CAA records and their fields. It does not test whether a website responds, whether an email server accepts messages or whether a TLS certificate is valid.

Diagram showing how a DNS lookup travels from the browser through a resolver to the root, TLD and authoritative nameservers and returns an IP address

How do I use DNS Lookup?

Enter the hostname you want to investigate in the Host field and run the lookup.

  1. Use the exact hostname affected by the problem, such as www.example.com or mail.example.com. Records for a subdomain can differ from records for the main domain.
  2. Prefer a bare hostname rather than a full page address containing a path, query string or fragment.
  3. Compare the returned addresses, targets and nameservers with the values supplied by your hosting, email or DNS provider.
  4. Check the TTL before assuming that an older result is a configuration error. A resolver may still have a previous value cached.
The DNS Lookup tool on digily.link, showing its input form

DNS names are case-insensitive, so WWW.EXAMPLE.COM and www.example.com refer to the same name. Spaces are not valid within an ordinary hostname. Internationalised domain names containing accented or non-Latin characters use ASCII A-labels in DNS; the encoded portion of an A-label uses Punycode, while the Unicode form is a U-label, so use the A-label form if the Unicode version does not resolve as expected.

Each DNS label is limited to 63 octets, and complete domain names also have a protocol length limit. Very long input may therefore be invalid even if its individual characters look acceptable. Numbers and hyphens are allowed in many hostname positions, but a label cannot begin or end with a hyphen under the usual hostname rules.

How do I read the DNS lookup result?

Read each field in the context of its record type, because several fields apply only to MX, SOA, TXT or other specific records.

  • Host identifies the name to which the returned record belongs.
  • TTL is the time to live in seconds. It tells DNS resolvers how long they may cache that record.
  • Target contains the destination or address associated with records that return a target.
  • IPv6 contains the address returned by an AAAA record.
  • Priority is used by MX records. A lower number has preference over a higher number.
  • Entries contains individual text strings supplied by a record, commonly where text is divided into separate parts.
  • MNAME is the primary nameserver named in an SOA record.
  • RNAME is the SOA contact address in DNS notation, with the first unescaped full stop representing the usual at sign.
  • Serial is the zone version number. Authoritative servers use it to recognise updated zone data.
  • Refresh tells secondary nameservers how often to check for a newer zone version.
  • Retry tells a secondary server when to try again after a failed refresh.
  • Expire sets how long a secondary server may continue using zone data when it cannot contact the primary server.
  • Min. TTL is the SOA MINIMUM field. It is not a general minimum TTL; together with the SOA record's TTL, it participates in determining the TTL for caching negative answers, such as a name that does not exist.
  • Flags, Tag and Value are structured fields used by policy records such as CAA when present.
  • Nameserver identifies a server named by an NS record.

DNS Lookup displays fields according to record type, so blank or absent fields can be expected: an A record has no MX priority, for example, and an MX record does not need an IPv6 field.

Example result produced by the DNS Lookup tool

Practical DNS troubleshooting scenarios

A DNS lookup is useful when the symptom points to a naming or routing problem. The example hostnames and record values in the scenarios below are hypothetical rather than live DNS data.

A website does not resolve. Look up www.example.com and inspect its A, AAAA and CNAME data. A plausible result might show a CNAME target of hosting.example.net, or an A target in IPv4 dotted-decimal form. If the returned target belongs to an old hosting service, update the relevant record at the authoritative DNS provider.

Email does not arrive. Look up the main domain and inspect its MX records. A hypothetical result could contain priority 10 with target mail.example.com and priority 20 with a backup mail host. Confirm that the targets match the mail provider's settings. The lookup cannot show whether a mailbox exists, whether the receiving server rejected a message or whether it entered a spam folder.

A certificate warning appears after a hosting change. Check the A, AAAA and CNAME records for the exact hostname shown in the browser. If DNS still directs some visitors to the previous server, they may receive that server's certificate. DNS Lookup does not inspect the certificate itself, so use a certificate checker after confirming the host points to the intended service.

Why is my DNS change not visible yet?

A correct DNS change may not appear immediately because recursive resolvers can retain the previous answer until its TTL expires. This delay is often called DNS propagation, although it usually reflects caches expiring at different times rather than records physically travelling across the internet.

The TTL shown on a new record does not necessarily describe how long the old record remains cached. The resolver may have stored the previous value using its previous TTL. Failed lookups can also be cached, so a newly created hostname may continue to appear missing for a while.

Check the NS records to confirm that the domain uses the nameservers where you made the change. If the nameservers are wrong, waiting will not correct the issue. For a deeper comparison, command-line tools such as dig or nslookup can query a chosen recursive or authoritative server directly.

Frequently asked questions

Can I enter an IP address instead of a hostname?

A forward DNS lookup is intended to find records associated with a hostname. To find a hostname published for an IP address, use Reverse IP Lookup, which checks reverse DNS data. Be aware that many IP addresses have no useful reverse record, and one reverse name does not list every website hosted on that address.

Why can a CNAME cause a conflict with other records?

A CNAME makes one DNS name an alias of another and generally cannot coexist at that same name with other ordinary record data. This is why the zone apex, such as example.com, usually uses A or AAAA records rather than a conventional CNAME. Some DNS providers implement proprietary flattening or alias records, but those are provider-specific features rather than standard CNAME behaviour.

Will public DNS show records from an internal company network?

Usually not. Organisations can use split-horizon DNS, where internal users receive different answers from those available publicly. Because this lookup runs on the server, its result reflects DNS visible from that server rather than records available only through your office network or VPN.

Does this lookup validate DNSSEC?

No DNSSEC validation status is included in the listed result fields. A domain can return ordinary DNS records even when its DNSSEC chain has a signing or delegation fault. Use a dedicated DNSSEC validator or a command-line query that requests DNSSEC data when investigating that type of failure.

Similar Tools

Reverse IP Lookup

Use the reverse IP lookup tool to find the domain or host associated with any IP address quickly and easily.

11,146
1,560
IP Lookup

Digily Link's IP lookup tool provides detailed information about any IP address. Use this free online service to get comprehensive IP data.

10,354
189
SSL Lookup

Use our SSL lookup tool to retrieve comprehensive details about any SSL certificate and ensure your website's security.

8,657
153

Popular Tools