What the DNS lookup does

The DNS lookup sends the name you type to the public resolver you choose (Cloudflare or Google Public DNS) through its DNS-over-HTTPS JSON interface and shows the returned records in a readable table. It helps when you move a website, check MX, SPF or DMARC records for email, look at CAA before issuing a TLS certificate or need the reverse record of an IP address.

Internationalised names are converted to their xn-- form before the query, so şeker.com.tr is asked as xn--eker-45a.com.tr. To inspect that conversion label by label, use the Punycode converter.

How to use

  • Type a domain name. If you paste a full URL, only the host name is used and a notice says so.
  • Pick a record type. “Common records” sends A, AAAA, CNAME, MX, TXT, NS, SOA and CAA queries together.
  • For a reverse lookup, type an IPv4 or IPv6 address; the tool builds the in-addr.arpa or ip6.arpa name and asks for PTR.
  • Choose the resolver and press Look up. Queries are sent only on this button, never while you type.
  • Copy the result or download it as a plain-text file similar to dig output.

If DNSSEC validation causes SERVFAIL, repeat the query with “Disable validation (CD)”. If the record appears this time, the problem is most likely in the DNSSEC setup of the zone.

Record types

TypeWhat it tells you
A / AAAAThe IPv4 and IPv6 addresses of the name
CNAMEThe name is an alias of another name
MXServers that accept email, with priorities
TXTSPF, DMARC, DKIM and verification strings
NS / SOAAuthoritative servers and the zone serial
CAAWhich certificate authorities may issue certificates
SRVServer and port for _service._proto names
PTRThe name an IP address maps back to

TXT records can consist of several strings; the tool joins them, counts the bytes and labels well-known prefixes such as SPF, DMARC or DKIM. The label only looks at the start of the text; it does not check whether the policy is correct.

Status codes and DNSSEC

Each query shows the response code returned by the resolver. NOERROR means the query succeeded; when the name exists but has no record of the requested type, the tool marks it as NODATA. NXDOMAIN means the name does not exist, SERVFAIL means the resolver could not produce an answer and REFUSED means it declined the query. Negative answers list the zone's SOA record in the authority section; its last field sets how long the negative answer may be cached.

The AD flag says the resolver validated the answer with DNSSEC signatures. A cleared flag is not an error by itself; the zone may simply be unsigned. Some providers also return Extended DNS Errors text, which the tool shows unchanged.

Caching, TTL and the resolver's view

Results come from the current view of the resolver you selected, not from the authoritative servers. When the resolver serves a record from cache, the TTL column shows the remaining seconds, so a change you just made may stay invisible until it expires. Cloudflare and Google cache at different times and can briefly disagree. Sites behind a CDN may also return different IP addresses depending on location.

Example and interpretation

The example button asks for the common records of yemre.com.tr. A shortened output can look like this (values change over time):

; yemre.com.tr (yemre.com.tr) @ Cloudflare
; A: status NOERROR; flags: rd ra
yemre.com.tr	300	IN	A	188.114.96.7
; MX: status NOERROR (NODATA); flags: rd ra
; authority: yemre.com.tr	1800	IN	SOA	gabriella.ns.cloudflare.com. dns.cloudflare.com. ...

Reading it: the A record exists and is cached with a 300-second TTL. The MX query returns NOERROR with NODATA, so no mail server is defined for this name; the SOA record only shows where the negative answer came from. An NXDOMAIN would instead mean that the name itself does not exist.

Limits and privacy

When you press Look up, the domain name or IP address is sent from your browser directly to the DoH provider you chose: Cloudflare (cloudflare-dns.com) or Google (dns.google). That provider sees your IP address and the query under its own privacy policy. Nothing about the query, the result or your IP is sent to yemre.com.tr; requests carry no cookies and no referrer, and client-subnet forwarding is switched off for Google.

The tool does not contact authoritative servers directly, does not perform zone transfers and cannot tell whether a provider blocks or filters a name. If a browser extension or a company network blocks DoH endpoints, the query ends with a network error. Each request times out after 8 seconds.

Frequently asked questions

Who receives the domain name I look up?

Only the DoH provider you select, Cloudflare or Google. The request goes straight from your browser; the yemre.com.tr server neither sees nor stores it.

Why does a record I changed still look old?

The resolver may keep the old record in cache until its TTL expires. Wait for the remaining time shown in the TTL column or compare with the other provider.

What is the difference between NXDOMAIN and NODATA?

NXDOMAIN says the name does not exist at all. NODATA says the name exists but has no record of the requested type, for example MX.

Is my site insecure if the AD flag is off?

No. A cleared AD flag means the answer was not DNSSEC-validated; the zone may not be signed. If you do use DNSSEC and the flag stays off, check the configuration.

How do I look up the reverse record of an IP address?

Type 8.8.8.8 or an IPv6 address directly into the field. The tool builds the reverse name and queries its PTR record.

Published: · Updated: