REVERSE DNS DIAGNOSTICS

PTR Lookup

Find the host name published for a public IP address and test whether that name resolves back to the same address, the check mail servers and logs commonly rely on.

Run PTR / reverse DNS

No sign-up required. Public hosts and addresses only; results show what was observed, nothing is simulated.

What a PTR record is

Reverse DNS turns an IP address into a name. The address is rewritten backwards under a special domain: 192.0.2.25 becomes 25.2.0.192.in-addr.arpa for IPv4, and IPv6 uses ip6.arpa with each hexadecimal digit as a label. A PTR record at that name holds the host name. The crucial difference from ordinary DNS is who controls it: the reverse zone belongs to whoever was allocated the address block, usually your hosting provider or ISP, not to the owner of the domain name.

The tool accepts a public IP address, builds the reverse name and asks resolvers for the PTR. Then it looks up the forward A and AAAA records of every PTR name returned, to check whether any of them lead back to the same IP.

What forward-confirmed reverse DNS means

A PTR record on its own is only a claim, because whoever controls the reverse zone can write any name there. Forward-confirmed reverse DNS (FCrDNS) closes the loop: the address maps to a name, and that name maps back to the same address. Mail servers, logging systems and abuse filters often use this as a weak signal that the address is operated by someone who also controls the forward name. It is a consistency check and not a proof of identity.

How to read the result

  • PTR present and confirmed: the name resolves back to the address, which is the good state. The tool shows each PTR name with the forward addresses it found.
  • PTR present but not confirmed: none of the PTR names lead back to the IP. This is a low-severity improvement and matters most for mail servers.
  • Forward lookups failed: if the follow-up address lookups time out or SERVFAIL, confirmation is not concluded rather than reported as failed.
  • No PTR (NXDOMAIN or NODATA): no reverse name is published. This is informational, since most addresses used only for browsing never need one.
  • Multiple PTR names: informational. Some software reads only the first, so keep one PTR for addresses that send mail.
  • Resolvers return different sets: usually cache timing right after a change.
  • Non-public or malformed input: private, loopback and reserved addresses are refused, since their reverse zones are not part of public DNS.

Common reverse DNS problems

  • Generic provider name: the PTR still shows a default like a hyphenated address under the provider's domain. It confirms, but it will not match the HELO name your mail server presents.
  • PTR without a matching A or AAAA: the name was set in the control panel but the forward record was never created.
  • Forward record points elsewhere: the host name moved to another address, but the PTR remained.
  • IPv6 oversight: PTR set for IPv4 but not for the IPv6 address the server actually uses to send.
  • Trying to edit it in the wrong place: the zone file of your own domain has no effect on reverse DNS.

How to fix reverse DNS safely

First decide which name the address should identify, ideally the same host name your mail server uses when it introduces itself in SMTP, and make sure that name has an A or AAAA record pointing at the IP. Then ask whoever owns the address block to set the PTR; many cloud providers offer a field for it on the server or IP resource, while ISPs often need a support request.

The change is low-risk for a server that receives most of its traffic by name, but changing a PTR on a live mail sender can alter how recipients score it, so pick one stable name and avoid frequent changes.

  1. Choose the host name and create or confirm its A or AAAA record for the IP.
  2. Ask the address owner, or use the provider's control panel, to set the PTR.
  3. Wait for the PTR TTL, then run this lookup to confirm the new name.
  4. Check that FCrDNS is confirmed and that the name matches your mail server's HELO name.
  5. To roll back, ask for the previous PTR to be restored; keep the forward record meanwhile.

What this test does not cover

The tool reads reverse DNS from resolvers and does not know who owns the IP block, so use the RDAP and ASN tools to see that. A matching PTR does not mean mail will be accepted, as reputation, SPF, DKIM and DMARC are judged separately. Results come from one scanner at one moment and private address space cannot be tested.

Frequently asked questions

Why can't I edit PTR in my domain's DNS zone?

Reverse zones belong to the organisation that holds the IP allocation. Your provider or ISP controls them, so you ask them, or use their control panel.

What is FCrDNS?

Forward-confirmed reverse DNS: the IP has a PTR name, and that name has an A or AAAA record pointing at the same IP.

Do I need a PTR for a web server?

Usually not. Browsers do not need it. It matters mainly for mail servers, and for readable names in logs.

Can an IP have several PTR records?

Technically yes, but some software reads only one. For a mail sender, publish a single PTR.

Does the PTR need to match my domain?

It needs to resolve back to the IP. For mail, it is better when it matches the name your server announces, but it need not be inside your sending domain.

Why can't I look up a private IP like 10.0.0.1?

Private and reserved ranges are not delegated in public reverse DNS, so the tool only accepts public addresses.

Written by DNS Tools editorial · Last updated 2026-10-09