Skip to content
SPCXTools

DNS Lookup

Check the DNS records of any domain, or find the hostname behind an IP address.

Private — nothing you enter is logged or stored

Loading tool…

How to use DNS Lookup

  1. 1Enter a domain name such as example.com — you can also paste a full URL and the hostname will be extracted.
  2. 2Choose a record type, or keep All common types to check A, AAAA, CNAME, MX, NS, TXT, SOA and CAA at once.
  3. 3Click Look up. Records are shown with their type, name, TTL and value.
  4. 4To find the hostname for an IP address (reverse DNS), enter the IP — a PTR lookup runs automatically.

Look up DNS records for any domain

The Domain Name System (DNS) is the internet's address book: it turns names like example.com into IP addresses and tells the world which servers handle a domain's website, email and security policies. This DNS lookup tool shows those records directly. Check all common record types at once or query a specific type, and run reverse lookups on IP addresses. Queries are made over encrypted DNS-over-HTTPS from our server to Cloudflare's public resolver.

Record types explained

Type What it does
A Maps a name to an IPv4 address
AAAA Maps a name to an IPv6 address
CNAME Makes a name an alias of another name
MX Lists the mail servers that receive email, with priorities
NS Names the authoritative nameservers for the domain
TXT Free text — used for SPF, DKIM, DMARC and domain verification
SOA Start of authority: primary nameserver, admin contact and timers
CAA Which certificate authorities may issue SSL/TLS certificates
SRV Locates services such as SIP, XMPP or game servers
PTR Reverse DNS: maps an IP address back to a hostname
HTTPS Connection hints for browsers, such as HTTP/3 support

Common uses

Launching or moving a website. After pointing a domain at new hosting, check that the A/AAAA or CNAME records show the new addresses.

Fixing email delivery. Missing or wrong MX records stop incoming mail; missing SPF, DKIM or DMARC TXT records cause outgoing mail to land in spam. Look them up to confirm they're published correctly.

Domain verification. Services like Google Search Console and Microsoft 365 ask you to add a TXT record. Confirm it's visible before clicking "verify".

SSL certificates. If certificate issuance fails, check whether a CAA record restricts which authorities may issue for your domain.

Investigating a domain. NS and SOA records show which DNS provider hosts a domain; PTR records identify the hostname behind an IP address seen in logs.

Understanding TTL

Each record has a TTL (time to live) in seconds, telling resolvers how long they may cache it. A TTL of 300 means changes propagate within about five minutes; 86400 means up to a day. Before migrating a site or mail server, lower the TTL a day in advance for a faster switch-over.

To see the IP address your own connection uses, try What Is My IP.

Frequently asked questions

Where do the DNS results come from?
Queries are sent from our server to Cloudflare's public resolver (1.1.1.1) using encrypted DNS-over-HTTPS, then returned to you. You see what a typical public resolver sees. Results may be cached for up to the record's TTL, and we don't log the domains you look up.
Why don't I see a DNS change I just made?
DNS records are cached by resolvers for the duration of their TTL (time to live). If the old record had a TTL of 3600, resolvers may keep returning it for up to an hour. Lower TTLs before planned changes to make them take effect faster.
What does NXDOMAIN mean?
NXDOMAIN ("non-existent domain") means the domain or subdomain doesn't exist in DNS — it may be misspelled, unregistered, expired, or the subdomain was never created.
Why does a lookup show a CNAME instead of an IP address?
A CNAME record makes one name an alias for another. The resolver follows the chain, so you'll see the CNAME followed by the A or AAAA records of the target. This is common for CDNs and hosted services.
How do I check email (MX, SPF, DKIM, DMARC) records?
Select MX to see which mail servers receive email for the domain. SPF is a TXT record on the domain itself (starting with v=spf1). Look up _dmarc.example.com as TXT for DMARC, and selector._domainkey.example.com as TXT for DKIM, replacing selector with the one your email provider uses.
Can I look up DNS for internal or private domains?
No. The lookup uses a public resolver, so it can only see records published on the public internet, not names that exist only on a company network.