DNS Lookup and DNS Trace

Look up any domain's A, AAAA, CNAME, MX, NS, TXT, SOA or CAA records from two or three public resolvers side by side, with TTLs and differences flagged. You can also trace the name from the root servers and check the answer from five countries.

DNS lookup tool

For example google.co.in or _dmarc.example.com. If you paste a link, only the name is kept.

Resolvers to compare

Pick two or three.

Ready. Nothing is sent until you press Look up.

  1. Type a domain above, or paste a full link.
  2. Pick a record type and press Look up.
  3. Optional: trace the delegation or check other countries. These run on Globalping probes.

Your records will appear here, one column per resolver.

DNS records returned by each resolver
RecordResolvers
No lookup yet.

TTL DNSSEC (AD) Differs

The two checks below run on Globalping volunteer probes, not on your device. Globalping publishes every test, including the domain you enter. They use the domain and record type above.

A probe in India asks the root servers, then the servers for the top-level domain, then the domain's own name servers, like dig +trace.

Not started.

One probe each in India, Singapore, Germany, the United States and Brazil looks up the same record with its local resolver.

Not started.

Globalping allows 250 free tests per hour for each IP address. Probes: Globalping

How to read your DNS lookup

Each column is one resolver and each row is one record it returned, with its TTL. A record marked "Differs" came back from some resolvers but not from all of them. The top rows show whether each resolver found the name, how long it took and whether it checked DNSSEC.

What the answer code means
AnswerMeaningWhat to do
NOERRORThe name exists. If no rows appear, it has no records of the type you picked.Try another record type, such as A or CNAME
NXDOMAINThe name does not existCheck the spelling, or whether the domain has expired
SERVFAILThe resolver could not get a valid answer from the domain's name serversRun a DNS trace below to see which step fails
REFUSEDThe resolver declined to answerTry another resolver

DNS record types explained

Each record type holds one kind of information about a name. Most people only need A, CNAME, MX and TXT.

  • A and AAAA: the IPv4 and IPv6 addresses a browser connects to.
  • CNAME: an alias. It says "this name is really that other name", and the lookup continues there.
  • MX: the servers that receive email for the domain. The lower number is tried first.
  • NS: the name servers that hold the domain's records. Your registrar sets these.
  • TXT: free text, used for SPF email rules, DMARC (at _dmarc. plus the domain) and ownership checks by Google, Microsoft and others.
  • SOA: the zone's main name server, the admin contact, a serial number that changes with each edit, and the timers other servers use.
  • CAA: which certificate authorities may issue HTTPS certificates for the domain.

DNS route and trace: how a name is found

A DNS trace shows the route a lookup takes from the top of the DNS tree down to your domain. No single server knows every name, so the answer comes in steps.

  1. The root servers say which servers handle the top-level domain, such as .com or .in.
  2. Those servers say which name servers handle the domain itself.
  3. The domain's own name servers give the final answer.

The first row of the trace is the probe's own resolver handing over the list of root servers. If a step is very slow, or the trace stops before the final answer, that step is where lookups for this domain go wrong. A DNS trace follows name servers, not network hops; to see the network path to a server, run a traceroute from your provider's network.

Why resolvers give different answers

Different answers from different resolvers are often normal. Many large sites hand out addresses close to whoever asks, so Cloudflare, Google and a probe in Brazil may each see their own set.

  • Caching: a resolver keeps an answer until its TTL runs out. After you change a record, some resolvers still hold the old one for a while.
  • Location: some resolvers pass part of your network address on, so the domain can pick a nearby server for you.
  • Filtering: resolvers that block malware or ads return no address, or a different one, for blocked names. This page compares unfiltered resolvers only.

Your own ISP's resolver can answer differently again. To see which resolver your device uses and how fast the public ones are, test your DNS speed.

DNS propagation and TTL

DNS "propagation" is really old answers expiring from caches. When you change a record, each resolver keeps the old answer until the TTL it received runs out, then asks again and gets the new one.

So the wait depends on the TTL, not on a fixed number of hours. A record with a TTL of 300 is refreshed within 5 minutes; one with 86400 can take up to a day. Before a planned change, lower the TTL and wait for the old TTL to pass. Then use "Check from other countries" above to confirm that resolvers in several places see the new answer.

How this DNS lookup works

This page asks public resolvers over DNS-over-HTTPS, the same encrypted method browsers use. Your browser sends each question straight to Cloudflare, Google, Control D, DNS.SB or AliDNS, whichever you tick, and asks each one to report whether it validated DNSSEC. Answers can differ from what your ISP's resolver returns.

The delegation trace and the country check do not run in your browser. They run on Globalping volunteer probes, and each result names the probe's city, network and ASN. Globalping's measurement data is public, so the domain you check becomes public too. Each IP address gets 250 free Globalping tests per hour; a trace uses one and the country check uses five.

A lookup sends only a few small DNS messages, so it costs almost no data. Read the full method on our About page and what each service sees in our privacy policy.

Questions about DNS lookups

Why does my DNS lookup fail?

A DNS lookup fails when the name does not exist (NXDOMAIN), when the domain's name servers do not answer properly (SERVFAIL), or when your network blocks the request. If every resolver on this page shows the same error, the problem is with the domain. If only your own device fails, the problem is your resolver or connection.

How do I do a DNS lookup in Command Prompt?

Use nslookup: type nslookup example.com for addresses, or add a type, such as nslookup -type=MX example.com. To ask a particular resolver, put its address last: nslookup example.com 1.1.1.1. Microsoft lists every option on its nslookup command page.

How long does DNS propagation take?

DNS propagation takes as long as the TTL of the old record, because resolvers drop an old answer only when its TTL runs out. Look up the record here before you change it and note the TTL: 3600 means up to an hour. There is no single fixed time that applies to every domain.

What is the difference between a DNS trace and a traceroute?

A DNS trace follows the chain of name servers that answer for a domain, from the root down. A traceroute follows the routers your data passes through on the way to an IP address. Use the DNS trace when a name does not resolve, and a traceroute when a site resolves but is slow or unreachable.

Why does the lookup show a different IP address than my computer?

Your computer usually asks your provider's resolver, while this page asks public resolvers over DNS-over-HTTPS. Sites that serve users from many locations give each resolver an address near that resolver, and caches may hold older answers. Both addresses can be correct.