DNS Lookup (A and AAAA)
See which IPv4 and IPv6 addresses a host name points to, what TTL they carry, and whether the zone's own servers give the same answer as a normal resolver.
Run A and AAAA records
No sign-up required. Public hosts and addresses only; results show what was observed, nothing is simulated.
What A and AAAA records do
An A record maps a host name to an IPv4 address and an AAAA record maps it to an IPv6 address. They are the records a browser, API client or mail server finally needs once it has a name and wants somewhere to connect. A name may carry several of either type, and clients normally try the addresses in an order of their own choosing, so the order shown in a response is not a priority.
This tool asks for both types of the host name you enter. It sends the question to the system resolver of the scanner and also finds the zone's authoritative name servers and asks them directly with recursion switched off. Showing both views lets you tell the difference between what the zone says and what a cache is currently repeating.
How to read the result
Each address family is reported separately, because a name can have a healthy A record and no AAAA record at all. The lookup for each type ends in one of a small set of states, and they mean different things.
The most common mistake when reading a DNS answer is to treat every empty result as 'the record does not exist'. The tool keeps the precise state of every query so that a failed query is never shown as an absent record.
- Records found: the addresses are listed with the remaining TTL. The tool notes whether the answer came through an alias (a CNAME) and shows the chain target, because the addresses then belong to the target name rather than to the name you typed.
- NODATA: the name exists but has no record of that type. For AAAA this usually just means the host is not published over IPv6, which is informational rather than a fault.
- NXDOMAIN: the name itself does not exist. Check for typos, a missing label, or a record that was never created or was deleted.
- SERVFAIL, REFUSED, timeout or transport error: the server could not give an answer. Nothing is known about the record, and the headline says explicitly that this is not evidence of absence.
- Non-public addresses: if an address is private, loopback or otherwise not routable on the internet, the tool flags it, since outside clients cannot reach it.
Authoritative servers versus the system resolver
The authoritative answer is what the zone currently publishes. The system resolver answer may be older, because resolvers keep a record until its TTL runs out. If the two differ shortly after you edited a record, that is usually ordinary caching, and the TTL tells you how long it can last. If they still differ long after the TTL has passed, look at whether all authoritative servers agree with each other; the NS tool reports that, and the propagation tool compares ten public resolvers.
The tool queries up to eight authoritative servers per run and uses one address for each server. A zone served by anycast or by a load balancer can answer differently from places this scanner cannot see.
Common address-record problems
- Wrong or stale IP after a migration: the A record still points at the old host. Compare the address with the one your hosting provider gave you, and remember that resolvers may serve the old value until the TTL expires.
- AAAA published but broken: a AAAA record that points at a host that does not listen on IPv6 can make dual-stack clients slow or fail on their first attempt. Either fix the IPv6 service or remove the AAAA record until it works.
- Private address in public DNS: an A record such as a 10.x or 192.168.x address works only inside one network. It is a common leftover from internal testing.
- CNAME at a name that also needs other records: the lookup follows aliases, but an alias cannot sit beside other record types at the same name. The CNAME tool checks this.
- Missing record on the bare domain: many sites publish www but forget the apex name, so example.com fails while www.example.com works.
How to change address records safely
Before editing, copy the current records and their TTL from the zone editor, and note the old addresses so you can restore them. If the change is planned, lower the TTL a day or more ahead so caches hold the old value for less time, then change the address, and restore a longer TTL once you are satisfied.
Bring the new server up and serving the right content before you point DNS at it, and keep the old server running until traffic has drained. Changing an A record is easy to undo in DNS, but the TTL you set before the change decides how fast the undo reaches clients.
- Record the current A and AAAA values and the TTL.
- Lower the TTL in advance and wait at least the old TTL.
- Change the address at the authoritative provider.
- Run this lookup again and confirm the authoritative servers show the new value.
- Check the new host over HTTPS from outside your network, then raise the TTL.
- To roll back, put the old addresses back; clients converge after the TTL you set.
What this test does not cover
A lookup shows that DNS publishes an address. It does not prove that anything answers on that address, that a certificate matches, or that a firewall allows the visitor in. Use the web and network tools for that. Results are a single measurement from one scanner at one moment, not a view from every region, and a content delivery network that gives different answers to different resolver locations will only show you the answer given to this scanner.
Frequently asked questions
What is the difference between an A and an AAAA record?
An A record holds a 32-bit IPv4 address and an AAAA record holds a 128-bit IPv6 address. A host can have either, both or several of each.
Why does the tool say 'no AAAA record' without calling it an error?
A name with only IPv4 addresses is valid and still works for IPv4 clients. The tool reports it as information, because whether you want IPv6 is a decision rather than a fault.
The system resolver and the authoritative servers show different addresses. Which is right?
The authoritative servers define the current truth. The resolver may still hold a cached older value until its TTL expires. Wait for the TTL and look again before assuming a fault.
Does a timeout mean the host has no address?
No. A timeout, SERVFAIL or REFUSED means the server gave no usable answer, so nothing is known. Only NXDOMAIN or NODATA from a server that answered says the record or name is absent.
Why do I see more than one address?
Round-robin or multi-homed services publish several addresses. Clients choose among them, so do not read the order as a ranking.
Does the tool check that the web server responds?
No. It only reads DNS. Use the HTTPS and port tools to test the service on the address.
Scope of this tool
- Reachability of the addresses is not tested.
Written by DNS Tools editorial · Last updated 2026-10-09