/

DNS Lookup

Query A, AAAA, CNAME, MX, TXT, NS, and SOA records for any domain, live, using Cloudflare's public DNS-over-HTTPS resolver.

Query

Uses Cloudflare DNS-over-HTTPS (1.1.1.1). Results reflect Cloudflare's resolver cache — propagation delays may apply. TTL is shown per record.

Records
Enter a domain name and select a record type to query.

Bookmark this tool now — skip the search next time you need it.

About DNS Lookup Tool

The DNS Lookup tool queries the live DNS records for any domain — A, AAAA, CNAME, MX, TXT, NS, and SOA — and shows each answer with its TTL. It is the browser equivalent of reaching for dig or nslookup: check whether a migration has propagated, confirm the MX records after a mail change, read the TXT records behind an SPF or domain-verification check, or find out which nameservers a domain is actually using. Queries are sent to Cloudflare’s public DNS-over-HTTPS resolver at cloudflare-dns.com, so the domain you look up is seen by Cloudflare — this is a real DNS query, not a local calculation.

Key features

  • Seven record types: A, AAAA, CNAME, MX, TXT, NS, and SOA
  • Live results from Cloudflare’s public DNS-over-HTTPS resolver, not a cached list
  • TTL shown next to every record, so you can see how long an answer stays cached
  • NXDOMAIN reported explicitly, so a domain that does not exist is distinguishable from one with no records of that type
  • Input cleaned up for you — paste a full URL and the protocol and path are stripped before the query
  • Per-record copy buttons, for pasting a single IP or TXT value elsewhere
  • Press Enter to run the lookup, and switch record types without retyping the domain
  • No installation, no terminal, and no account — useful on a locked-down machine without dig
  • Note: the domain you query is sent to Cloudflare’s resolver, since a DNS lookup cannot be performed locally in a browser

How to use it

  1. Type or paste the domain — a full URL works, since the protocol and path are removed automatically.
  2. Choose the record type you want.
  3. Press Lookup, or just hit Enter.
  4. Read the answers with their TTLs, and copy any individual value you need.
  5. Switch record type and run again to build a picture of the whole zone.

Tips & common mistakes

  • This queries Cloudflare’s resolver, not your own. That is exactly what you want when checking whether a change has propagated to the wider internet, and not what you want when diagnosing a problem specific to your local network or VPN.
  • DNS changes propagate at the speed of the old TTL, not the new one. If the previous record had a 24-hour TTL, resolvers that cached it may keep serving the old answer for that long, however quickly this tool shows the new value.
  • Lower the TTL a day before a planned migration. It costs you nothing and turns a day-long cutover into a minutes-long one.
  • SPF, DKIM, DMARC, and every domain-verification token live in TXT records. When a mail provider says verification failed, TXT is the first place to look.
  • MX records carry a priority — the lower number is tried first. Two records with the same priority are load-balanced rather than ordered.
  • NXDOMAIN and an empty answer mean different things. NXDOMAIN means the name does not exist at all; an empty result means the name exists but has no record of the type you asked for.
  • A CNAME cannot coexist with other records on the same name, which is why a root domain usually cannot be a CNAME and needs an A record or a provider-specific alias instead.
  • Want details about a specific IP — ASN, geolocation, type — rather than resolving a hostname? Use IP Address Info.

Related tools

Browse all 12 Development tools

Frequently asked questions

10

Type the domain — a full URL is fine, since the protocol and path are stripped — pick a record type, and press Lookup. Each answer is shown with its TTL.

A, AAAA, CNAME, MX, TXT, NS, and SOA. Switch the type without retyping the domain to build up a picture of the whole zone.

The interface does, but the query itself cannot: a browser has no DNS access. Lookups are sent to Cloudflare’s public DNS-over-HTTPS resolver, so the domain you enter is seen by Cloudflare.

This queries Cloudflare’s resolver rather than yours. That is what you want for checking public propagation, and not what you want for diagnosing a local network, VPN, or hosts-file problem.

Time to live — how many seconds a resolver may cache the answer before asking again. It is the reason DNS changes are not instant everywhere.

Up to the TTL of the previous record, not the new one. If the old record had a 24-hour TTL, some resolvers will serve the old answer for that long. Lower the TTL a day before a planned migration.

The domain does not exist at all. That is different from an empty result, which means the domain exists but has no record of the type you asked for.

They all live in TXT records, so query TXT for the domain. DKIM and DMARC use subdomains — _dmarc.example.com and selector._domainkey.example.com — so query those names directly.

Priority. Lower numbers are tried first, and records sharing a priority are load-balanced between rather than ordered.

A CNAME cannot coexist with other records on the same name, and a root domain must carry NS and SOA records. Use an A record, or a provider-specific alias such as ALIAS or ANAME.