DNS lookup
A, AAAA, MX, TXT and other records for a domain.
Asked from your browser of Cloudflare (1.1.1.1), only when you press Look up.
Try
Records
waiting for a domain…
About this tool
- Runs in
- your browser
- Your input sent to our servers
- Nothing
- Sent elsewhere
- The domain name, to the public DNS resolver you choose (Cloudflare or Quad9)
- Kept on this device
- nothing
More in the privacy policy.
How to use it
- 01Type a domain name, paste a URL, or type an IP address for a reverse lookup. Or pick one under Try.
- 02Choose who to ask: Cloudflare (1.1.1.1), Quad9 (9.9.9.9), or Compare to ask both. Choose All records (A, AAAA, CNAME, MX, TXT, NS, SOA, CAA, HTTPS) or one type; SRV, SVCB, DS, DNSKEY and TLSA are asked on their own.
- 03Press Look up (or Enter). The records appear by type, with how long resolvers may cache each; Copy all copies them as text.
Related tools
Questions
What do the record types mean?
A and AAAA give the IPv4 and IPv6 addresses. CNAME says the name is an alias of another. MX lists the mail servers, lowest number first. TXT holds text such as SPF rules and site verification codes. NS names the domain’s name servers, SOA its primary server and timers, and CAA which certificate authorities may issue certificates for it. HTTPS (and the general SVCB) tells browsers how to connect: supported protocols such as HTTP/3, address hints and encryption keys. SRV, asked at a service name such as _sip._tcp.example.com, gives the host and port of a service, and TLSA, asked at a name such as _443._tcp.example.com, the certificate a server should present (DANE). DS and DNSKEY are DNSSEC keys: DS, in the parent zone, vouches for the domain’s DNSKEY. PTR, asked for an IP address, gives the name behind it.
Why would two resolvers give different answers?
Usually it’s normal. Sites behind a CDN or a load balancer answer each resolver with nearby or rotating addresses, so their A and AAAA records often differ. And each resolver keeps an answer for as long as its time to live (TTL) allows, so right after a DNS change one may still give the old answer. Compare asks both at once and marks any record only one of them returned. TTLs differ between them all the time, as each counts down its own copy.
What is the TTL?
How long a resolver may reuse an answer before asking again, in seconds; this page writes it in words (3600 seconds is 1 h). A lower TTL makes changes show up sooner.
What does "validated with DNSSEC" mean?
The resolver checked the answers’ cryptographic signatures up to the root and they matched, so they weren’t altered on the way. It appears only when every answer shown was signed and checked; many domains aren’t signed at all.
Where does my lookup go?
When you press Look up, your browser sends the domain name straight to the resolver you chose, Cloudflare or Quad9, over an encrypted connection. It isn’t sent to our servers or put into the page address, and nothing is sent while you type. The resolver sees the domain and your IP address and handles them under its own privacy policy; our privacy policy links both.