DNS Lookup

Check all DNS records of a domain. See the A, AAAA, MX, TXT, NS, CNAME and SOA records in one click.

Fetching DNS records...

What is a DNS lookup?

A DNS lookup retrieves the DNS records (Domain Name System records) of a domain name. DNS is the system that translates domain names into IP addresses and other configuration data. When you run a DNS lookup, you request this data from the nameservers that are responsible for the domain.

With our free DNS lookup tool you can retrieve all the important DNS records of any domain: A records for IPv4 addresses, AAAA records for IPv6, MX records for mail servers, TXT records for verifications and SPF, NS records for nameservers, CNAME records for aliases and SOA records with zone information. This tool is indispensable for webmasters, system administrators and anyone who needs to troubleshoot DNS issues.

What types of DNS records are there?

DNS has several record types, each with its own purpose:

Record Type Purpose
A IPv4 address of the domain (e.g. 213.154.231.150)
AAAA IPv6 address of the domain (the newer version of IP addresses)
MX Mail Exchange servers that receive email for the domain
TXT Text information such as SPF, DKIM, DMARC and site verifications
NS Nameservers that are authoritative for the domain
CNAME Alias that points to another domain
SOA Start of Authority with zone information and refresh settings

Each of these record types plays a specific role in the DNS infrastructure. A and AAAA records tell your browser which IP address to connect to, MX records make sure email is delivered to the right mail server, and TXT records hold anything from domain verifications to email security policies.

Why check DNS records?

Checking DNS records matters for several reasons:

  • Website troubleshooting: if your website is unreachable, check the A or AAAA records to see whether the domain points to the right IP address
  • Fixing email problems: check the MX records and the TXT records with your SPF/DKIM settings when email doesn't arrive
  • Verifying a migration: after switching hosts, check that DNS has been updated correctly and the domain points to the new server
  • Checking security: verify your SPF, DMARC and DNSSEC settings to make sure your domain is properly protected
  • Tracking DNS propagation: after a DNS change, check whether the new values are active
  • Technical analysis: examine a domain's configuration for technical work, migrations or audits
  • Performance optimization: review TTL values and the DNS setup to optimize load times

DNS propagation: how long does it take?

When you change DNS records, it takes a while before those changes are active worldwide. This is called DNS propagation. How fast it happens depends on the TTL (Time To Live) of the DNS records:

  • Low TTL (300-3600 seconds): changes within 5 minutes to 1 hour
  • Standard TTL (3600-86400 seconds): changes within 1 to 24 hours
  • High TTL (86400+ seconds): can take up to 48 hours

At Theory7 we use a default TTL of 3600 seconds (1 hour), so DNS changes take effect quickly while caching stays efficient. Before a migration, you can lower the TTL to 300 seconds (5 minutes) in advance so the switch goes faster.

It's important to understand that DNS propagation is not linear. Some DNS resolvers pick up new values right away, while others keep using the old cached values until the TTL expires.

Email authentication with DNS records

TXT records are often used for email authentication and security. The most important ones are:

  • SPF (Sender Policy Framework): specifies which mail servers are allowed to send email on behalf of your domain. Example: v=spf1 mx a include:_spf.theory7.net ~all
  • DKIM (DomainKeys Identified Mail): adds a digital signature to outgoing email, so recipients can verify that the email really came from you
  • DMARC (Domain-based Message Authentication): specifies what happens to email that fails the SPF/DKIM checks and asks mail servers to send reports

These records help prevent spammers from impersonating your domain (spoofing) and improve the deliverability of your email. Without SPF and DKIM, your emails are more likely to end up in the spam folder.

How does DNS work?

The Domain Name System is a distributed, hierarchical system that translates domain names into IP addresses. When you visit a website, a whole chain of DNS lookups happens behind the scenes:

Step 1: Recursive resolver
Your computer sends a DNS query to a recursive resolver (usually from your internet provider or a public DNS service such as Google DNS or Cloudflare). This resolver does the heavy lifting of finding the answer.

Step 2: Root nameservers
The recursive resolver first asks one of the 13 root nameservers where to find the TLD nameservers. For a .nl domain, the root server points to the .nl nameservers.

Step 3: TLD nameservers
The TLD nameserver (.nl, .com, .net, etc.) knows which authoritative nameservers are responsible for the specific domain.

Step 4: Authoritative nameservers
The authoritative nameserver holds the actual DNS records of the domain (A, AAAA, MX, TXT, etc.).

Step 5: Caching
The recursive resolver stores the answer for the duration of the TTL, so subsequent queries can be answered faster.

This whole process takes milliseconds. A single web page can require dozens of DNS lookups for the domain itself and all its external resources.

Setting up DNS records for your website

To put a website online, you need to configure a few DNS records:

Setting up an A record
The A record translates your domain name into the IPv4 address of your web server:

  • @ (root domain) → IP address of your server (e.g. 213.154.231.150)
  • www → the same IP address (or use a CNAME)

CNAME for the www subdomain
Instead of a separate A record for www, you can use a CNAME: www CNAME @. The advantage: if your server IP changes, you only need to update one A record.

MX records for email
If you want to receive email, you need MX records. The number (10, 20) is the priority: lower numbers are tried first.

TXT records for email authentication
Add SPF, DKIM and DMARC records as TXT records to secure your email.

Once everything is set up, you can use our DNS lookup tool to check that it's all configured correctly.

Troubleshooting DNS problems

DNS problems are common. Here are the most frequent errors and how to fix them:

NXDOMAIN (Non-Existent Domain)
The domain does not exist in DNS. Possible causes: a typo, an expired domain, nameservers that aren't set up correctly, or a DNS zone that hasn't been created. Solution: check the domain name and use a WHOIS lookup to see whether the domain is active.

SERVFAIL (Server Failure)
The DNS server could not answer. Causes: the nameserver is offline, DNSSEC validation fails, a misconfiguration, or a firewall blocking queries.

Timeout / No response
No answer within the timeout period. Causes: a wrong nameserver IP, a firewall blocking port 53, or an overloaded server.

Wrong IP address
DNS returns an IP address, but not the right one. Causes: the DNS change hasn't propagated yet, the A record is incorrect, or the DNS resolver is caching old data. Solution: wait for propagation, flush your local DNS cache, or try another resolver such as 8.8.8.8 (Google) or 1.1.1.1 (Cloudflare).

DNSSEC: DNS security

DNSSEC (DNS Security Extensions) is a security protocol that digitally signs DNS responses. This prevents DNS spoofing and cache poisoning attacks, in which attackers inject fake DNS responses.

How DNSSEC works
DNSSEC adds cryptographic signatures to DNS records. The recursive resolver validates the signature to verify that the response is authentic. It does this through a chain of trust that runs from the root zone all the way down to your domain.

Implementing DNSSEC

  • Enable DNSSEC with your DNS hosting provider
  • Add DS (Delegation Signer) records at your domain registrar
  • Sign the DNS records with a ZSK and a KSK
  • Rotate keys regularly for the best security

With a DNS lookup tool you can see whether DNSSEC is active by looking at the RRSIG and DNSKEY records.

DNS when moving a domain

When you move your domain, the DNS configuration is crucial. Follow these steps for a smooth migration:

  1. Take stock of your current DNS records: run a full DNS lookup and write down all the records as a backup
  2. Lower the TTL: 24 hours before the migration, lower your TTL to 300 seconds
  3. Set up the new DNS zone: configure all DNS records with your new hosting provider
  4. Test the new zone: check the configuration before you change the nameservers
  5. Change the nameservers: update the nameservers at your domain registrar
  6. Track DNS propagation: use a DNS lookup tool to check regularly whether your domain points to the new nameservers
  7. Raise the TTL again: once the migration is complete, raise the TTL back to the default (3600+)

Tip for email continuity: If you're only migrating your website but want to keep email on the old server, change only the A records and not the MX records.

DNS hosting vs domain registration

Many people confuse DNS hosting with domain registration, but they are two different services:

Domain registration is the process of reserving a domain name through a registrar. You pay an annual fee and get the right to use that domain name.

DNS hosting is the service that manages your domain's DNS records. DNS hosting runs on nameservers that answer DNS queries 24/7.

Why they can be separate:

  • Better DNS infrastructure: some providers have faster nameservers on Anycast networks
  • Advanced features: providers such as Cloudflare offer free DNSSEC and DDoS protection
  • Central management: keep all your DNS zones with a single provider

Common DNS mistakes

Here are the most common DNS mistakes and how to avoid them:

Wrong TTL during a migration: the TTL wasn't lowered before the migration. Result: old DNS values stay cached for hours. Solution: lower the TTL 24 hours in advance.

Forgotten MX records: during a website migration the A records were updated but the MX records were forgotten. Result: email stops arriving. Solution: use a DNS lookup to check that all MX records are correct.

SPF syntax errors: common issues are multiple SPF records (not allowed), incorrect syntax and too many DNS lookups (max 10). Solution: test your SPF record with a validator.

CNAME on the root domain: a CNAME is not allowed on the root domain when other records exist there (MX, TXT). Solution: use an A record for the root domain.

No DMARC policy: SPF and DKIM without DMARC means mail servers don't know what to do when checks fail. Solution: add a DMARC TXT record.

Ignoring the DNS cache: testing after changes without flushing the cache. Solution: flush your DNS cache after making changes and test from multiple locations.

With this knowledge and our free DNS lookup tool, you can quickly identify and fix DNS problems. Combine it with our SSL Check and HTTP Headers Check for a complete technical overview of your website.

Frequently asked questions

What is a DNS lookup?

A DNS lookup retrieves the DNS records of a domain. DNS (Domain Name System) translates domain names into IP addresses and also holds information about mail servers, nameservers and other settings. A DNS lookup shows you exactly how a domain is configured.

What types of DNS records are there?

The main DNS record types are A (IPv4 address), AAAA (IPv6 address), MX (mail server), TXT (text information such as SPF and DKIM), NS (nameserver), CNAME (alias) and SOA (Start of Authority with zone information). Each record type has a specific role in the DNS configuration.

What is the difference between A and AAAA records?

An A record holds an IPv4 address (e.g. 213.154.231.150), while an AAAA record holds an IPv6 address (e.g. 2001:db8::1). IPv6 is the modern successor to IPv4 and offers a much larger address space. Both record types translate a domain name into an IP address, but they use different versions of the Internet Protocol.

How long does it take for DNS changes to take effect?

DNS changes go through worldwide within a few minutes to a few hours, depending on the TTL (Time To Live) of the records. At Theory7 we use a default TTL of 1 hour, so changes are usually active everywhere within 1 to 2 hours. In some cases it can take 24 to 48 hours before every DNS server has the new values.

What are MX records for?

MX (Mail Exchange) records specify which mail servers receive email for a domain. Each MX record has a priority: lower numbers are tried first. If the primary mail server (priority 10) is unavailable, the backup (priority 20) is used. Without MX records, a domain cannot receive email.