Skip to content

DNS Lookup

Check every DNS record of a domain - including SPF and DMARC - in one click.

FreeDNS over HTTPSRuns in your browser
Queried from your browser via Google Public DNS (dns.google) over HTTPS.

DNS record types explained

RecordWhat it does
APoints the domain to an IPv4 address
AAAAPoints the domain to an IPv6 address
MXMail servers that receive email for the domain
TXTFree text - used for SPF, domain verification and more
NSName servers that are authoritative for the domain
CNAMEAlias that points one name to another name
SOAStart of authority - primary server and zone serial
CAACertificate authorities allowed to issue SSL certificates

DNS records that protect your domain

  • SPF (TXT) lists the servers allowed to send email for your domain.
  • DMARC (TXT on _dmarc) tells receivers what to do with mail that fails SPF or DKIM.
  • CAA limits which companies can issue certificates for you.

Missing SPF and DMARC make it easy for scammers to send email pretending to be you. Check the full picture with the Email Header Analyzer and the SSL Checker.

Frequently asked questions

What is a DNS lookup?

DNS translates a domain name like example.com into the IP addresses and settings computers use. A DNS lookup asks the internet's DNS servers which records a domain has right now.

Which DNS server does this tool use?

Queries go from your browser to Google Public DNS over HTTPS, so you see what most of the internet sees. Results can differ briefly from your own provider while changes propagate.

How long does DNS propagation take?

Each record has a TTL (time to live) in seconds. Resolvers may keep the old value until the TTL expires - usually 5 minutes to 24 hours. Lower the TTL a day before planned changes.

How do I check SPF and DMARC records?

Choose TXT for the domain to see its SPF record (starts with v=spf1). For DMARC, look up TXT records of _dmarc.yourdomain.com. The "All records" mode checks DMARC for you.

What is a CAA record?

A CAA record lists which certificate authorities may issue SSL certificates for the domain. It is a simple way to stop attackers from getting certificates from other providers.