Skip to content
netscanner

DNS lookup

For pros and the curious: See all the records that control where a domain points, who receives its email and which services it has been verified with.

Examples:

  • Free
  • No sign-up
  • Live data
  • Made in Switzerland

What does the DNS lookup show?

DNS is the “phone book” of the internet: it translates names like example.ch into the addresses of the right servers. If you want to check after a website move whether everything is set up correctly, you’ve come to the right place. If you simply want to find out who is hosting a website or where, the website hosting checker is the better choice.

Our DNS lookup reads the most important record types at the same time and displays them clearly:

Type What it’s used for
A The server’s IPv4 address, e.g. 192.0.2.10
AAAA The server’s IPv6 address, e.g. 2001:db8::10
CNAME Alias that points to another name, e.g. www → example.ch
MX Mail servers that accept email for the domain
NS Name servers responsible for the zone
TXT Free text, e.g. SPF, DMARC or verifications for Google and Microsoft
SOA Administrative data of the zone: primary name server, serial number, timers
CAA Which certificate authorities are allowed to issue SSL certificates

For IP addresses, we show the PTR record (reverse DNS), which is the name assigned to an address.

Typical use cases

After moving a website, you see right away whether the A record already points to the new server. If the address is correct but you still see the old site, it’s usually down to the cache of your internet provider or browser.

When setting up email, you can check MX and TXT records. For a complete check of SPF, DKIM and DMARC, use the email checker.

Before switching name servers, for example to Cloudflare, write down all existing records. That way nothing gets lost during the move. Our domain migration checklist walks you through the process step by step.

Understanding TTL and DNSSEC

Next to each record you see the TTL in seconds. It tells resolvers how long they may cache an answer. Before planned changes, it’s a good idea to lower the TTL to 300 seconds one or two days in advance.

If a domain is signed with DNSSEC and the signature is valid, we show a green notice. DNSSEC prevents attackers from slipping in fake DNS answers. All record types are explained in detail in our guide DNS records explained.

Frequently asked questions

Which DNS server does the lookup use?

We query Cloudflare's public resolver 1.1.1.1 via DNS over HTTPS. It validates DNSSEC and returns very up-to-date answers.

Why do I still see the old record?

Resolvers cache answers for as long as the TTL allows. If a record with a TTL of 3600 seconds was changed, it can take up to an hour for the new value to show up everywhere. Learn more in our guide to DNS propagation.

Can I look up subdomains too?

Yes. Simply enter the full name, for example www.example.ch or shop.example.ch. Each subdomain can have its own records.

What does NXDOMAIN mean?

NXDOMAIN means that the name you looked up doesn't exist. This happens with typos, with unregistered domains or when a subdomain was never created.