What a DNS lookup shows
DNS is the address book of the internet. When someone types a domain, their computer asks a resolver, the resolver asks the domain's nameservers, and the answer says where the website lives, which mail server takes its email and which services are allowed to act for it. This DNS lookup asks the same questions for eight record types at once and shows the answers in one table, with the TTL that says how long resolvers may keep each one.
It is the first thing to check when a site does not load after a move, when email bounces, or when a service like Google Workspace or a shop builder asks you to add a record and you want to see whether it is live.
The DNS record types
| Type | What it does | Example value |
|---|---|---|
| A | The IPv4 address the domain points to. Browsers connect to it. | 93.184.215.14 |
| AAAA | The IPv6 address, the newer and longer kind of address. | 2606:2800:21f:cb07::1 |
| CNAME | An alias: this name is another name. Common for www and for services like a shop or a CDN. | shops.myshopify.com |
| MX | The mail servers that accept email for the domain, lowest priority number first. | 10 mx1.mail.example |
| TXT | Free text, used for SPF, site verification codes for Google or Microsoft, and DKIM keys. | v=spf1 include:_spf.google.com ~all |
| NS | The nameservers that hold the domain’s DNS zone. Change them and every other record moves with them. | lana.ns.cloudflare.com |
| SOA | Start of authority: the primary nameserver, a contact and the serial number of the zone. | ns1.example.com, serial 2026100801 |
| CAA | Which certificate authorities may issue SSL certificates for the domain. | 0 issue "letsencrypt.org" |
SPF and DMARC: does the email get through?
Below the table the tool reads two records that decide whether mail from the domain lands in the inbox. The SPF record, a TXT record that starts with v=spf1, lists which servers may send mail. It should exist only once, end with ~all or -all, and stay within 10 DNS lookups, because receivers stop counting after that and treat the record as broken.
The DMARC record lives at _dmarc. plus the domain. Its p= policy says what receivers do with mail that fails: none only watches, quarantine sends it to spam and reject refuses it. Start with none and a report address in rua=, read the reports for a few weeks, then tighten the policy. DKIM keys live under a selector name that only the sender knows, so they are not part of this check.
Why a change does not show everywhere at once
Each answer carries a TTL in seconds. 3600 means resolvers may keep the answer for an hour before they ask again. When you plan a move to a new server, lower the TTL of the A record a day ahead, make the change, and raise it again afterwards. If the nameservers themselves change, expect up to 48 hours, because the servers of the domain ending (.com, .de and so on) hand them out with a long TTL. To see which registrar controls the nameservers, use the WHOIS lookup; to check the certificate once the new server answers, use the SSL checker.
How to check the DNS records of a domain
- 1Type the domain, or paste a full web address or an email address; the tool takes the domain part.
- 2Read the counts first, then filter the table by type, for example MX when mail does not arrive.
- 3Check the SPF and DMARC notes, and copy the result or the link to send it to whoever manages the DNS.
Frequently asked questions
Why do I see old records after I changed my DNS?
Resolvers keep an answer for as long as its TTL says, often an hour or a day. Until that time runs out, some people still get the old value. The TTL column shows how long the current answer may be kept. Our server also keeps answers for 10 minutes, so check again after that if you just made a change.
What does a missing record type mean?
Nothing is wrong when a domain has no AAAA, CAA or CNAME record; many domains use only some types. A domain without MX records cannot receive email, and one without NS or A records usually means it is not set up or not registered.
Can a domain have a CNAME and other records?
Not at the same name. A CNAME says this name is only an alias, so it must stand alone. That is why the bare domain (example.com) usually has A records, while www often is a CNAME. Some DNS providers offer a flattened CNAME at the root that answers with A records.
What are SPF and DMARC?
Both are TXT records that protect a domain’s email. SPF lists the servers allowed to send mail for the domain. DMARC tells receiving servers what to do with mail that fails the SPF or DKIM check and where to send reports. Gmail and Yahoo require both from bulk senders since 2024.
Which DNS server does this tool ask?
Our server asks Google Public DNS (8.8.8.8) over an encrypted connection, and Cloudflare (1.1.1.1) if Google does not answer. Both ask the domain’s own nameservers and follow the TTL like any other resolver, so you see what the public internet sees, not what your own computer or network may have cached.