DNS DIAGNOSTICS

DNS Tools

Look up any record type, check that a zone is delegated and signed correctly, and compare what different resolvers say. Each tool separates a missing record from a failed lookup, so you do not mistake a timeout for an empty answer.

DNS Tools directory

DNS Lookup (A and AAAA)

Look up the IPv4 (A) and IPv6 (AAAA) addresses of a host name, compared between the system resolver and the zone's own authoritative servers.

MX Lookup

Check MX records, priorities, null MX and whether each mail server name resolves to a public address. Understand how inbound mail is routed for a domain.

TXT Lookup

List the TXT records at a name and see which are SPF, DMARC, DKIM-looking or verification tokens, with checks for duplicate SPF and misplaced records.

DNS Propagation Checker

Compare a record's authoritative answer with ten named public resolvers to see who agrees, who still serves an older value, and when cached data should expire.

DNS Resolver Comparison

Ask the system resolver and ten public resolvers for up to four record types, then see where answers differ, who filters, who validates DNSSEC and who is slow.

NS Lookup

Check a domain's name servers, compare parent and child delegation, detect lame servers and glue problems, and see whether SOA serials agree across servers.

SOA Lookup

Read a zone's SOA record: serial, refresh, retry, expire and negative-caching timers, checked against RFC guidance and compared across authoritative servers.

DNSSEC Checker

Check DNSSEC for a domain: DNSKEY and DS presence, DS-to-key match, algorithms, signature validity window and what validating public resolvers return.

CNAME Lookup

Follow a CNAME chain hop by hop, detect loops, long chains, dangling targets and a CNAME at the zone apex, and confirm the final name resolves to addresses.

PTR Lookup

Look up the reverse DNS (PTR) name of a public IP and check forward-confirmed reverse DNS: whether the PTR name resolves back to the same address.

CAA Lookup

Find the CAA policy that applies to a host name, including the parent-name tree climb, issue and issuewild rules, iodef contacts and critical flags.

SRV Lookup

Look up SRV records for a service and protocol: priority, weight, port and target, and check that targets resolve to public addresses and are not aliases.

How DNS diagnostics fit together

A DNS question passes through several layers, and a fault in any one of them looks like 'the site is down'. The registry holds the delegation that says which name servers are responsible. Those authoritative servers hold the zone with its records. Recursive resolvers fetch and cache answers on behalf of users, and DNSSEC may add signatures that validating resolvers check. Good diagnosis works from the top of that chain down: is the delegation right, do the authoritative servers agree, is the record what you intended, and are resolvers still serving something older.

The tools on this page map onto those layers. The delegation and SOA tools look at who is authoritative and whether they carry the same zone version. The record tools read what the zone publishes for a type. The propagation and resolver tools look at what caches say, and the DNSSEC tool looks at whether the signatures and the chain of trust hold together.

Records the zone publishes

Use DNS Lookup for the IPv4 and IPv6 addresses of a host and MX Lookup for where a domain receives mail. TXT Lookup shows text records and sorts out SPF, DMARC and DKIM-looking values, CNAME Lookup follows alias chains, SRV Lookup finds services on non-default ports, and CAA Lookup shows which certificate authorities may issue for the name. PTR Lookup goes the other way, from an IP address to a name, and checks that the name leads back.

Each of these tools queries the system resolver and the zone's own authoritative servers, which means you see both what the zone says and what a cache may still be repeating.

Zone health and trust

NS Lookup compares the delegation at the parent with the zone's own name server list, and looks for lame servers, missing glue and name servers on one network. SOA Lookup decodes the serial and the timers, including the negative-caching time that controls how long a missing record is remembered, and compares serials across servers. The DNSSEC Checker tests the DS and DNSKEY relationship, the signature window and what validating resolvers return, which is where a mismatch can make a domain unreachable for some users.

Watching a change take effect

The DNS Propagation checker compares the authoritative answer with ten named public resolvers for one record type and reports who agrees and when old cached data should expire. The DNS Resolver Comparison puts the same question for up to four record types to the same resolvers and highlights filtering, AD flags and slow responses. Neither is a geographic map; they are queries made from one place to anycast addresses.

Reading results correctly

Every DNS answer ends in one of a few states, and they mean different things. A positive answer returns records. NXDOMAIN means the name does not exist. NODATA means the name exists but has no record of that type. SERVFAIL, REFUSED, a timeout or a transport error means the server did not give a usable answer, so nothing is known about the record. The tools keep these apart and never present a failure as an absent record. For a longer explanation, see the guide on troubleshooting NXDOMAIN, SERVFAIL and timeouts.

All checks are made from one scanner at one moment and do not replace testing from the networks that matter to you. Before you edit DNS, read the DNS change checklist so that you have a rollback.

Related reading

Written by DNS Tools editorial · Last updated 2026-10-09