DNS record lookup
Query A, AAAA, MX, TXT, NS, CNAME and SOA records.
| Host | TTL? | Value |
|---|---|---|
| google.com | 300 | 142.251.14.139 |
| google.com | 300 | 142.251.14.100 |
| google.com | 300 | 142.251.14.113 |
| google.com | 300 | 142.251.14.102 |
| google.com | 300 | 142.251.14.101 |
| google.com | 300 | 142.251.14.138 |
| Host | TTL? | Value |
|---|---|---|
| google.com | 300 | 2a00:1450:4001:c15::8b |
| google.com | 300 | 2a00:1450:4001:c15::64 |
| google.com | 300 | 2a00:1450:4001:c15::71 |
| google.com | 300 | 2a00:1450:4001:c15::65 |
| Host | TTL? | Value |
|---|---|---|
| google.com | 300 | google-site-verification=4ibFUgB-wXLQ_S7vsXVomSTVamuOXBiVAzpR5IZ87D0 |
| google.com | 300 | onetrust-domain-verification=0d477fe608074e6f9c12bca7826035cc |
| google.com | 300 | cisco-ci-domain-verification=47c38bc8c4b74b7233e9053220c1bbe76bcc1cd33c7acf7acd36cd6a5332004b |
| google.com | 300 | Z29vZ2xl |
| google.com | 300 | docusign=05958488-4752-4ef2-95eb-aa7ba8a3bd0e |
| google.com | 300 | MS=E4A68B9AB2BB9670BCE15412F62916164C0B20BB |
| google.com | 300 | work-accounts-domain-verification=Tcj6JjIMZOw2KsSEw2Nt2rLae89tN6 |
| google.com | 300 | apple-domain-verification=30afIBcvSuDV2PLX |
| google.com | 300 | globalsign-smime-dv=CDYX+XFHUw2wml6/Gb8+59BsH31KzUr6c1l2BPvqKX8= |
| google.com | 300 | docusign=1b0a6754-49b1-4db5-8540-d2c12664b289 |
| google.com | 300 | google-site-verification=TV9-DBe4R80X4v0M4U_bd_J9cpOJM0nikft0jAgjmsQ |
| google.com | 300 | google-site-verification=wD8N7i1JTNTkezJ49swvWW48f8_9xveREV4oB-0Hf5o |
| google.com | 300 | facebook-domain-verification=22rm551cu4k0ab0bxsw536tlds4h95 |
| google.com | 300 | onetrust-domain-verification=6d685f1d41a94696ad7ef771f68993e0 |
| google.com | 300 | v=spf1 include:_spf.google.com ~all |
| Host | TTL? | Value |
|---|---|---|
| google.com | 21600 | ns2.google.com |
| google.com | 21600 | ns1.google.com |
| google.com | 21600 | ns3.google.com |
| google.com | 21600 | ns4.google.com |
google.com. 300 IN A 142.251.14.139 google.com. 300 IN A 142.251.14.100 google.com. 300 IN A 142.251.14.113 google.com. 300 IN A 142.251.14.102 google.com. 300 IN A 142.251.14.101 google.com. 300 IN A 142.251.14.138 google.com. 300 IN AAAA 2a00:1450:4001:c15::8b google.com. 300 IN AAAA 2a00:1450:4001:c15::64 google.com. 300 IN AAAA 2a00:1450:4001:c15::71 google.com. 300 IN AAAA 2a00:1450:4001:c15::65 google.com. 113 IN MX 10 smtp.google.com. google.com. 300 IN TXT "google-site-verification=4ibFUgB-wXLQ_S7vsXVomSTVamuOXBiVAzpR5IZ87D0" google.com. 300 IN TXT "onetrust-domain-verification=0d477fe608074e6f9c12bca7826035cc" google.com. 300 IN TXT "cisco-ci-domain-verification=47c38bc8c4b74b7233e9053220c1bbe76bcc1cd33c7acf7acd36cd6a5332004b" google.com. 300 IN TXT "Z29vZ2xl" google.com. 300 IN TXT "docusign=05958488-4752-4ef2-95eb-aa7ba8a3bd0e" google.com. 300 IN TXT "MS=E4A68B9AB2BB9670BCE15412F62916164C0B20BB" google.com. 300 IN TXT "work-accounts-domain-verification=Tcj6JjIMZOw2KsSEw2Nt2rLae89tN6" google.com. 300 IN TXT "apple-domain-verification=30afIBcvSuDV2PLX" google.com. 300 IN TXT "globalsign-smime-dv=CDYX+XFHUw2wml6/Gb8+59BsH31KzUr6c1l2BPvqKX8=" google.com. 300 IN TXT "docusign=1b0a6754-49b1-4db5-8540-d2c12664b289" google.com. 300 IN TXT "google-site-verification=TV9-DBe4R80X4v0M4U_bd_J9cpOJM0nikft0jAgjmsQ" google.com. 300 IN TXT "google-site-verification=wD8N7i1JTNTkezJ49swvWW48f8_9xveREV4oB-0Hf5o" google.com. 300 IN TXT "facebook-domain-verification=22rm551cu4k0ab0bxsw536tlds4h95" google.com. 300 IN TXT "onetrust-domain-verification=6d685f1d41a94696ad7ef771f68993e0" google.com. 300 IN TXT "v=spf1 include:_spf.google.com ~all" google.com. 21600 IN NS ns2.google.com. google.com. 21600 IN NS ns1.google.com. google.com. 21600 IN NS ns3.google.com. google.com. 21600 IN NS ns4.google.com. google.com. 14 IN SOA ns1.google.com. dns-admin.google.com. 953810495 900 900 1800 60
What does each field mean?
Field reference
TTL
Seconds a downstream resolver is allowed to cache the record before re-asking the authoritative server. Short TTL (60–300) means changes propagate fast but every resolver hits you more often; long TTL (1h–1d) reduces load but slows DNS changes.
A record
Maps a hostname to a 32-bit IPv4 address (e.g., <code>example.com → 93.184.216.34</code>). Most common DNS record type; web traffic begins with an A lookup.
AAAA record
IPv6 equivalent of A — 128-bit address (e.g., <code>2606:2800:220:1::93:184:216:34</code>). Modern hosts publish both A and AAAA; the resolver picks one per the client's connectivity.
MX record
Lists the hostname(s) of mail exchangers plus a priority number — lowest priority is tried first. Without an MX, email cannot be delivered to the domain. Examples: <code>10 mail.example.com</code>.
CNAME
Canonical Name: tells the resolver "to find me, look up X instead". Cannot coexist with any other record on the same name and cannot exist at the zone apex (the bare domain). Useful for CDNs and SaaS providers.
TXT
Originally arbitrary text, today carries machine-readable policies: SPF (allowed mail senders), DKIM (signing keys), DMARC (email-auth policy), and domain-ownership tokens for Google/Microsoft/AWS.
NS
Lists the servers that hold the actual zone data. The TLD registry returns NS records during the referral chain; resolvers then ask these servers for everything else. Changing NS effectively re-delegates the domain.
PTR
Maps an IP back to a name. Required for mail servers — many providers reject SMTP from IPs with missing or generic PTR. The owner of the IP block (not the domain owner) controls PTR records.
SOA
Each zone has exactly one SOA: master NS, contact email, serial number (incremented on changes — secondaries use it to detect updates), refresh/retry/expire timers, default negative-cache TTL.
CAA
Certification Authority Authorization restricts which CAs may issue certificates for the domain. Example: <code>0 issue "letsencrypt.org"</code> blocks every CA except Let's Encrypt. CAs are required to honor CAA before issuance.
Resolver
Public recursive resolver we asked: Cloudflare (1.1.1.1), Google (8.8.8.8), Quad9 (9.9.9.9). Different resolvers may return different answers because of TTL races, anycast, or geo-targeted DNS.
About this tool
A DNS lookup asks an authoritative or recursive resolver what records a domain publishes. Our tool runs a live query against Google, Cloudflare, or Quad9 and shows you every record with its TTL — the same data dig prints on the command line, formatted for quick scanning.
You can pull the common record types on a single page: A and AAAA for hosts, MX for mail routing, TXT for SPF/DKIM/verification strings, NS for delegation, SOA for zone metadata, plus CNAME, SRV, CAA, and reverse PTR. Pick only the types you need to keep the answer compact.
When to use this tool
- After a DNS change. Query multiple resolvers to confirm a new record is live before pointing traffic at it.
- Debugging email deliverability. Inspect
MX,SPF,DKIM, andDMARCrecords in one pass. - Verifying ownership. Pull the
TXTrecord a third-party service asked you to publish. - Reverse DNS. Run a
PTRquery on an IP to find the hostname a mail server or logger will attribute to it.
Why you may see different answers
Public resolvers cache records for the TTL you configured at your authoritative nameserver. Google may still serve the old value while Cloudflare already shows the new one. Switch the resolver to compare — the TTL column tells you when the cache will expire. For a global view across 20+ vantage points, see the propagation check linked below.Frequently asked questions
Which DNS resolver should I use?
What is the TTL column?
Do you query the authoritative nameserver directly?
+norecurse dig or a hosting-specific tool.
Why do PTR records look different?
.in-addr.arpa (IPv4) or .ip6.arpa (IPv6) reverse zone. To avoid mixing record types that live in different zones, pick PTR on its own and enter an IP address instead of a domain.