DNS Checker

Look up the DNS records of a domain and see whether public resolvers such as Google, Cloudflare, Quad9 and OpenDNS give the same answer. The lookup is made by the ToolCMB server; only the name you enter is sent.

  • A · MX · TXT · CNAME
  • Several public resolvers
  • SPF and DMARC
  • TTL per record
This tool works through our server

Browsers cannot send DNS queries, so the lookup is done by the ToolCMB server, which asks several public DNS resolvers (Google, Cloudflare, Quad9, OpenDNS and others). Only the domain name is sent — we do not store it or the answers.

Record types

Tap to switch a type on or off. Enter an IP address for a reverse (PTR) lookup.

How it works

How to check DNS records

A domain name is all you need.

  1. 1

    Enter a domain or IP address

    Type a name such as example.com, or an IP address for a reverse lookup. The name is sent to the ToolCMB server, because a browser cannot send DNS queries itself.

  2. 2

    Choose the record types

    Tap the types you want — A, AAAA, CNAME, MX, NS, TXT, SOA, CAA, SRV, DS or DNSKEY. Your selection is remembered in this browser for the next visit.

  3. 3

    Compare the answers

    Each type shows its records with their TTL and how many resolvers agree. The propagation table lists every resolver, and the mail check explains SPF and DMARC.

Why ToolCMB

One lookup, several resolvers

See the records and whether the world already agrees on them.

Eleven record types

A, AAAA, CNAME, MX, NS, TXT, SOA, CAA, SRV, DS and DNSKEY for domain names. Enter an IPv4 or IPv6 address and the tool looks up its PTR record instead.

Asked at several resolvers

Our server sends each question to a fixed list of public DNS resolvers — Google, Cloudflare, Quad9, OpenDNS and others — and shows the answer most of them gave.

Propagation table

A grid of resolver by record type shows who agrees, who differs, who found no such name and who did not answer. Differing answers are listed under the record.

TTL in readable form

Every record shows how long resolvers may cache it, in seconds, minutes, hours or days — the time you have to wait after a change.

E-mail records explained

The check reads the SPF record and the DMARC record of the domain and says in plain words how strict they are, or that they are missing or duplicated.

Zone file and CSV

Copy the records in zone-file form, save them as CSV, copy a single value with one tap or share a link that opens the tool with the name filled in.

Honest about what is sent

The check runs on our server because a browser is not allowed to do it. Only the address you enter is sent; it is not stored.

Protected against abuse

Only public addresses can be checked, and the number of checks per minute is limited so the tool cannot be misused against other sites.

DNS records and propagation explained

The Domain Name System translates names into the data computers need: an A or AAAA record gives the IP address of a website, MX names the mail servers, NS the name servers responsible for the zone, and TXT carries free text such as SPF rules and ownership proofs. The records live on the authoritative name servers of the domain. Everyone else asks a resolver — run by an internet provider or a public service — which fetches the answer once and then keeps it in its cache for as long as the record’s TTL allows.

This tool sends your question from our server to several public resolvers at the same time and parses each answer separately. For every record type it shows the answer the majority gave and counts how many resolvers agree. Because each resolver has its own cache, a recent change can be visible at one and not yet at another: that is what people call propagation. The resolvers are large public services, not probes in particular countries, so the table tells you whether the well-known resolvers agree, not what every provider in the world currently has cached.

A few mistakes come up again and again. A CNAME cannot share its name with other records, so it does not belong on the bare domain next to MX and NS records. A domain may have only one SPF record; two of them make SPF fail. Lowering the TTL helps only if you do it before the change, at least one old TTL in advance. Differing answers long after a change usually mean that the name servers themselves are out of sync. And if every resolver reports that the name does not exist, check the name-server entries at your registrar first.

Common DNS record types

RecordContainsUsed for
A / AAAAAn IPv4 / IPv6 addressPointing a name to a server
CNAMEAnother host name (alias)Subdomains that follow a CDN or hosted service
MXMail server and priorityReceiving e-mail for the domain
TXTFree textSPF, DKIM, DMARC, domain verification
NS / SOAName servers / zone settingsDelegating the zone, serial number and timers
CAAAllowed certificate authoritiesLimiting who may issue certificates for the domain

Tips

  • After pointing a domain to a new server, confirm that the certificate there is valid with the SSL Checker.
  • DNS is right but the site still answers with an error? Check the response with the HTTP Status Checker.
  • Moving to a new domain as well? Trace the old addresses with the Redirect Checker.
  • DKIM is not part of the mail check, because its record sits under a selector name chosen by your mail provider. Enter the full name — selector._domainkey.example.com — and look up its TXT record.
FAQ

Frequently asked questions

Can’t find your answer? Contact us — we reply quickly.

How long does DNS propagation take?

As long as the TTL of the old record: resolvers that cached it keep it until that time runs out. With a TTL of one hour, most of the world sees the change within an hour. The often-quoted “up to 48 hours” is a cautious upper limit that mainly applies to name-server changes.

What is a TTL in DNS?

Time to live: the number of seconds a resolver may keep a record in its cache before asking again. A short TTL (5 minutes) makes changes visible quickly; a long one (a day) reduces lookups. Public resolvers show the time that is left, so the value can differ from one to the next.

What is the difference between an A record and a CNAME?

An A record points a name directly to an IPv4 address. A CNAME points a name to another name, whose address is then looked up. A CNAME must be the only record at its name, which is why it is used for subdomains such as www and not for the bare domain.

How do I check the SPF and DMARC records of a domain?

Enter the domain, keep TXT selected and leave the e-mail check switched on. The tool reads the SPF record from the TXT records of the domain and the DMARC record from the _dmarc subdomain, and tells you whether each is present, unique and how strict its policy is.

What is sent to your server?

Only the address or domain name you enter. A browser is not allowed to make this kind of request itself, so our server makes it for you and returns the result. We do not store the address or the result, and the content of the checked pages is never passed on.

Why is there a limit on the number of checks?

Each check makes our server contact another website. To keep the tool from being used to flood or probe other sites, the number of checks per minute and per day is limited, and private or internal network addresses are refused. Wait a moment and try again.

More free SEO and website tools

Generate tags and files, check status codes, redirects, DNS and certificates — free, without an account.

Browse all tools