What this lookup shows
Type a domain and the tool asks a public recursive resolver for each common record type at once. The answers are the same ones your own devices would get from that resolver: they come from its cache when the record is already there, or from the domain’s authoritative nameservers when it is not. The TTL column is how much longer the resolver will keep serving that answer before checking again — a useful number when you are waiting for a change to take effect.
Type an IP address instead and the tool performs a reverse DNS lookup, asking for the PTR record under in-addr.arpa (IPv4) or ip6.arpa (IPv6). Mail servers in particular are expected to have one.
The record types, briefly
- A / AAAA — the IPv4 and IPv6 addresses a name points to.
- CNAME — an alias: this name is another name. Resolvers follow the chain for you, and the table shows each step.
- MX — the servers that accept email for the domain, lowest priority number first.
- NS — the authoritative nameservers for the zone.
- TXT — free-form text, used for SPF, DMARC, DKIM and ownership verification. SPF and DMARC records are tagged; the email DNS checker analyses them in depth.
- SOA — the zone’s primary server, contact, and serial number. The serial usually increases every time the zone is edited.
- CAA — which certificate authorities may issue TLS certificates for the domain.
- HTTPS — connection hints for browsers: supported protocols such as HTTP/3, address hints, and Encrypted Client Hello keys.
- DS / DNSKEY — the DNSSEC keys and the fingerprint of them held by the parent zone.
How the DNSSEC check works
Both resolvers on this page validate DNSSEC. For a domain, the tool asks for its SOA, DS and DNSKEY records with the DNSSEC flag set and reads the resolver’s verdict:
- Signed and validated — the resolver set the Authenticated Data flag: it checked signatures all the way from the root.
- Not signed — there is no DS record in the parent zone, so there is nothing to validate. Most domains are in this state.
- Signed, but not anchored — the zone publishes keys but the registrar never received the DS record.
- Validation fails — the resolver returned SERVFAIL, and the same query with checking disabled succeeded. That combination means the signatures are broken, and every validating resolver will refuse to answer. If the resolver attached an Extended DNS Error code explaining why, it is shown.
The most common way to break DNSSEC is to move a domain to a new DNS host while the old DS record stays at the registrar. Remove the DS first, wait out its TTL, then move.
Limits worth knowing
A lookup through a public resolver shows what that resolver has, which can lag the authoritative servers by up to the record’s TTL. Sites behind a CDN or GeoDNS may give different addresses to different resolvers; the propagation checker lines several up side by side. Browsers cannot send classic port-53 DNS queries, which is why every query here travels over DNS-over-HTTPS — the DoH explainer covers what that changes.
More free tools
Last reviewed 2026-10-02. Results come live from the servers named above; DNS Benchmark Pro does not cache, proxy or store them.