Network
DNS lookup
Real DNS queries against any domain, handy for verifying mail setup (SPF, DKIM, DMARC all live in TXT records), checking propagation after changes, or basic recon.
The domain name system is the internet's phone book: it maps human names like example.com to addresses and mail exchangers and arbitrary text policies via typed records. Almost every action online, opening a site, sending mail, validating paywalls, checking whether a new subdomain has propagated, starts with a query for one of those types.
This lookup issues live queries against any domain you supply, fetching A, AAAA, MX, TXT, NS, CNAME and SOA records in one pass. It is the fastest way to answer whether mail can be delivered, whether a security policy is published, or whether a recent change actually took effect.
Which record matters for which question
A and AAAA carry the addresses that the name currently resolves to for IPv4 and IPv6; when both exist, clients prefer AAAA under most modern stacks, which is why a missing AAAA after enabling IPv6 is not an error. CNAME aliases one name to another and cannot coexist with other types at the same owner name, a constraint that trips many first-time CDN setups.
MX names the mail exchangers that handle delivery for the zone; without MX, the zone falls back to A/AAAA semantics, but publishing explicit MX is the reliable and expected configuration. TXT is the extensible carrier for SPF, DKIM keys, DMARC and ownership verification tokens; if a domain sends mail without TXT records beginning with v=spf1 or v=DMARC1, its authentication is incomplete and it is easy to spoof.
NS and SOA describe delegation and authority: NS lists the authoritative nameservers for the zone, and SOA bundles serial, refresh and expiry timers that secondary servers use to decide when to resynchronize. A mismatch between the parent-delegated NS set and the zone's own NS points to propagation or configuration drift.
How to read a result without over-interpreting
The answer is near-live, but caching means two perspectives can briefly disagree. Authoritative servers show the freshest data; recursive resolvers may serve a cached copy for the remainder of its time-to-live. If you just changed records, query again after the lowest TTL among the types you modified, or query the authoritative nameservers directly from a separate vantage point.
Empty is not an error. A domain that never sends mail legitimately has no MX and may have no TXT, the absence is intended. The interesting cases are domains that do send mail yet lack the TXT triad of SPF, DKIM and DMARC, and domains whose operators claimed to publish DNSSEC but whose signatures are expired when validated.
- Verifying mail setup: look for v=spf1, v=DMARC1 and DKIM selectors under selector._domainkey in TXT results.
- Checking propagation: compare the answer you see here against your registrar's authoritative preview until TTLs expire.
- Basic recon: collect NS, MX and TXT together to understand who runs mail, who delegates DNS and what policies are declared.
Operational hygiene for domain owners
Treat DNS as a security policy surface, not just plumbing. Publish the narrowest SPF that covers every legitimate sender, sign mail with 2048-bit DKIM keys rotated via selector changes, and graduate DMARC from p=none monitoring to quarantine and finally reject once aggregate reports are clean. Monitor liveness with consecutive lookups after changes and with external validators for DNSSEC if you sign the zone.
Never publish secrets not designed for rotation in TXT; many credential leaks started as verification tokens added to DNS and never removed. If a provider asks you to publish a token, scope it to a host like _acme-challenge or provider-specific verification name where the blast radius is minimal.
Enter any bare domain without https:// or a path. The records that come back group by type, copy-ready, and are fresh enough to settle the practical question that prompted you to look.
How it works
Enter a bare domain like example.com (no https://, no paths).
Pick a record type or leave it on All types.
Records come back grouped by type, ready to copy.
Questions about this tool
Which records matter for email security?
TXT records. Look for v=spf1, v=DMARC1, and DKIM entries. A domain that sends mail without these is easy to spoof in phishing campaigns.
Are results cached?
Each request resolves fresh through the system resolver, so values are near-live, though upstream resolvers may cache for a few seconds.