NETWORK
DNS Lookup
Check A, AAAA, CNAME, MX, TXT, NS, and SOA records via DNS-over-HTTPS.
PUBLIC DNS QUERY
Look up a DNS record
Answer records
| Type | Name | TTL | Value |
|---|---|---|---|
DNS lookup runs from your browser. NAB Tools does not proxy or store your query.
DNS lookup guide
Check the public DNS records for a domain, hostname, or specific record name. Enter a name such as example.com, www.example.com, or _dmarc.example.com, choose a record type, and run the lookup.
The request goes directly from your browser to the Cloudflare or Google DNS-over-HTTPS resolver you select. NAB Tools does not proxy or store the query; the selected resolver receives the name you look up.
How to check a DNS record
Enter a DNS name without https://, a path, or a port. The correct name depends on the record you need: a website may use the root domain or www hostname, while email-authentication records often live at a prefixed name.
- Use A or AAAA to find the IPv4 or IPv6 addresses returned for a website hostname.
- Use CNAME to check whether one hostname is an alias of another.
- Use MX on the domain that receives email to find its mail exchangers.
- Use TXT on the exact owner name. SPF is often at the root domain, DMARC at _dmarc.example.com, and DKIM at a provider-specific selector such as selector._domainkey.example.com.
- Use NS or SOA on the domain to inspect its authoritative DNS delegation and zone information.
What the DNS record types mean
Each record type answers a different question. A lookup can return more than one answer, and an address lookup can include a CNAME followed by the address of its target.
- A — maps a DNS name to a 32-bit IPv4 address.
- AAAA — maps a DNS name to a 128-bit IPv6 address.
- CNAME — aliases one DNS name to another. The target must then be resolved for the requested service.
- MX — identifies mail exchangers. The leading number is the preference value; lower values are tried before higher values.
- TXT — carries text used by systems including SPF, DKIM, DMARC, and domain-verification services.
- NS — identifies authoritative nameservers for a DNS zone.
- SOA — describes the start of authority for a zone, including its primary nameserver, responsible-party field, serial number, and timing values.
How to read the result
Name is the owner of the returned record, Type identifies its format, TTL is the remaining cache lifetime reported by the recursive resolver, and Value contains the record data. A trailing dot on a returned hostname means it is a fully qualified DNS name.
Do not assume every answer row has the type you selected. For example, an A lookup for an aliased hostname can return its CNAME and the target A record in the same answer chain. The Type column shows what each row actually contains.
No record, NXDOMAIN, and DNS failures
NOERROR with no answer means the lookup itself succeeded but the resolver returned no record of the requested type. The DNS name may still exist and publish other types. NXDOMAIN is different: it means the queried DNS name does not exist.
SERVFAIL usually means the resolver could not complete validation or reach a usable authoritative answer. REFUSED means the server declined the query. If a resolver fails temporarily, retry once or compare the other resolver; two public resolvers are useful checkpoints, not a complete test of every cache worldwide.
TTL and DNS changes
TTL is measured in seconds. Recursive resolvers may reuse a cached answer until its TTL expires, so old and new answers can coexist after a DNS change. The TTL shown here may already be counting down from the value configured at the authoritative DNS provider.
Before a planned migration, operators often lower the authoritative TTL in advance, wait for older cached answers to expire, and then make the change. Raising the TTL again afterward reduces repeat queries. A DNS lookup shows the answer from the selected resolver at that moment; it does not prove that every resolver has refreshed.
What DNS-over-HTTPS protects
DNS-over-HTTPS encrypts the request between your browser and the selected resolver, preventing observers on that network path from reading or changing the DNS message directly. It does not make the query anonymous: Cloudflare or Google receives the DNS name and your network address.
DoH transport encryption is also separate from DNSSEC, which lets a validating resolver verify signed DNS data. An HTTPS connection to the destination still provides its own certificate checks after DNS resolution.
Frequently asked questions
What is a DNS lookup?
A DNS lookup asks a resolver for a particular record type at a DNS name—for example, A addresses for a website hostname, MX records for a mail domain, or TXT records for an email-authentication name.
Why does the lookup say NOERROR but show no records?
The resolver completed the query but returned no answer of the requested type. The name may exist and have other DNS records. NXDOMAIN instead means the queried DNS name does not exist.
How do I check a DMARC or DKIM TXT record?
Enter the complete record name. DMARC normally uses _dmarc.example.com. DKIM uses a provider-specific selector followed by _domainkey, such as selector._domainkey.example.com. Then select TXT.
Why can an A lookup show a CNAME row?
If the requested hostname is an alias, the resolver can return the CNAME and the A record for its target as one answer chain. Read the Type column rather than assuming every row is an A record.
What does TTL mean in DNS?
TTL is the number of seconds an answer may remain cached. The value returned by a recursive resolver may be the remaining cache time, so it can be lower than the TTL configured at the authoritative provider.
How long do DNS changes take?
Clients and recursive resolvers can continue using an older answer until its previous TTL expires. There is no single worldwide propagation timer; the effective delay depends mainly on prior caching and resolver behavior.
Is a DNS-over-HTTPS lookup private?
The DNS message is encrypted between your browser and the selected resolver, and NAB Tools does not proxy it. The resolver still receives the queried name and your network address, so DoH is encrypted transport rather than anonymity.
Privacy note: DNS lookup sends your query directly from the browser to the selected public resolver. It is not submitted to or stored by NAB Tools.