DNS Lookup and DNS Trace
Look up any domain's A, AAAA, CNAME, MX, NS, TXT, SOA or CAA records from two or three public resolvers side by side, with TTLs and differences flagged. You can also trace the name from the root servers and check the answer from five countries.
DNS lookup tool
Ready. Nothing is sent until you press Look up.
- Type a domain above, or paste a full link.
- Pick a record type and press Look up.
- Optional: trace the delegation or check other countries. These run on Globalping probes.
Answers by resolver
Your records will appear here, one column per resolver.
| Record | Resolvers |
|---|---|
| No lookup yet. | |
TTL Time to live: how many seconds a resolver may keep this answer before asking again. Resolvers count it down, so two resolvers often show different TTLs for the same record. DNSSEC (AD) "Validated" means the resolver checked the answer's DNSSEC signatures and set the AD (authenticated data) flag. "Not validated" usually means the domain is not signed. Differs The record came back from some resolvers but not from all of them. Big sites often do this on purpose; for your own domain it usually means a change that has not reached every cache yet.
CNAME chain
The two checks below run on Globalping volunteer probes, not on your device. Globalping publishes every test, including the domain you enter. They use the domain and record type above.
Trace delegation from the root
A probe in India asks the root servers, then the servers for the top-level domain, then the domain's own name servers, like dig +trace.
Not started.
| Step | Server asked | Time | What it answered |
|---|
Check from other countries
One probe each in India, Singapore, Germany, the United States and Brazil looks up the same record with its local resolver.
Not started.
| Country | Probe | Answer | TTL | Compared with the others |
|---|
How to read your DNS lookup
Each column is one resolver and each row is one record it returned, with its TTL. A record marked "Differs" came back from some resolvers but not from all of them. The top rows show whether each resolver found the name, how long it took and whether it checked DNSSEC.
| Answer | Meaning | What to do |
|---|---|---|
| NOERROR | The name exists. If no rows appear, it has no records of the type you picked. | Try another record type, such as A or CNAME |
| NXDOMAIN | The name does not exist | Check the spelling, or whether the domain has expired |
| SERVFAIL | The resolver could not get a valid answer from the domain's name servers | Run a DNS trace below to see which step fails |
| REFUSED | The resolver declined to answer | Try another resolver |
DNS record types explained
Each record type holds one kind of information about a name. Most people only need A, CNAME, MX and TXT.
- A and AAAA: the IPv4 and IPv6 addresses a browser connects to.
- CNAME: an alias. It says "this name is really that other name", and the lookup continues there.
- MX: the servers that receive email for the domain. The lower number is tried first.
- NS: the name servers that hold the domain's records. Your registrar sets these.
- TXT: free text, used for SPF email rules, DMARC (at
_dmarc.plus the domain) and ownership checks by Google, Microsoft and others. - SOA: the zone's main name server, the admin contact, a serial number that changes with each edit, and the timers other servers use.
- CAA: which certificate authorities may issue HTTPS certificates for the domain.
DNS route and trace: how a name is found
A DNS trace shows the route a lookup takes from the top of the DNS tree down to your domain. No single server knows every name, so the answer comes in steps.
- The root servers say which servers handle the top-level domain, such as .com or .in.
- Those servers say which name servers handle the domain itself.
- The domain's own name servers give the final answer.
The first row of the trace is the probe's own resolver handing over the list of root servers. If a step is very slow, or the trace stops before the final answer, that step is where lookups for this domain go wrong. A DNS trace follows name servers, not network hops; to see the network path to a server, run a traceroute from your provider's network.
Why resolvers give different answers
Different answers from different resolvers are often normal. Many large sites hand out addresses close to whoever asks, so Cloudflare, Google and a probe in Brazil may each see their own set.
- Caching: a resolver keeps an answer until its TTL runs out. After you change a record, some resolvers still hold the old one for a while.
- Location: some resolvers pass part of your network address on, so the domain can pick a nearby server for you.
- Filtering: resolvers that block malware or ads return no address, or a different one, for blocked names. This page compares unfiltered resolvers only.
Your own ISP's resolver can answer differently again. To see which resolver your device uses and how fast the public ones are, test your DNS speed.
DNS propagation and TTL
DNS "propagation" is really old answers expiring from caches. When you change a record, each resolver keeps the old answer until the TTL it received runs out, then asks again and gets the new one.
So the wait depends on the TTL, not on a fixed number of hours. A record with a TTL of 300 is refreshed within 5 minutes; one with 86400 can take up to a day. Before a planned change, lower the TTL and wait for the old TTL to pass. Then use "Check from other countries" above to confirm that resolvers in several places see the new answer.
How this DNS lookup works
This page asks public resolvers over DNS-over-HTTPS, the same encrypted method browsers use. Your browser sends each question straight to Cloudflare, Google, Control D, DNS.SB or AliDNS, whichever you tick, and asks each one to report whether it validated DNSSEC. Answers can differ from what your ISP's resolver returns.
The delegation trace and the country check do not run in your browser. They run on Globalping volunteer probes, and each result names the probe's city, network and ASN. Globalping's measurement data is public, so the domain you check becomes public too. Each IP address gets 250 free Globalping tests per hour; a trace uses one and the country check uses five.
A lookup sends only a few small DNS messages, so it costs almost no data. Read the full method on our About page and what each service sees in our privacy policy.
Questions about DNS lookups
Why does my DNS lookup fail?
A DNS lookup fails when the name does not exist (NXDOMAIN), when the domain's name servers do not answer properly (SERVFAIL), or when your network blocks the request. If every resolver on this page shows the same error, the problem is with the domain. If only your own device fails, the problem is your resolver or connection.
How do I do a DNS lookup in Command Prompt?
Use nslookup: type nslookup example.com for addresses, or add a type, such as nslookup -type=MX example.com. To ask a particular resolver, put its address last: nslookup example.com 1.1.1.1. Microsoft lists every option on its nslookup command page.
How long does DNS propagation take?
DNS propagation takes as long as the TTL of the old record, because resolvers drop an old answer only when its TTL runs out. Look up the record here before you change it and note the TTL: 3600 means up to an hour. There is no single fixed time that applies to every domain.
What is the difference between a DNS trace and a traceroute?
A DNS trace follows the chain of name servers that answer for a domain, from the root down. A traceroute follows the routers your data passes through on the way to an IP address. Use the DNS trace when a name does not resolve, and a traceroute when a site resolves but is slow or unreachable.
Why does the lookup show a different IP address than my computer?
Your computer usually asks your provider's resolver, while this page asks public resolvers over DNS-over-HTTPS. Sites that serve users from many locations give each resolver an address near that resolver, and caches may hold older answers. Both addresses can be correct.