DNS Lookup
Enter a domain name and choose a record type. Answers are compared across three public resolvers, so you can see whether a DNS change has propagated.
Free, no sign-up. Everything runs in your browser.
The DNS record types you’ll check most often
- A / AAAA: the IPv4 / IPv6 address a domain points to, such as the IP of the VPS hosting your website.
- CNAME: an alias to another domain name, commonly used for
wwwor third-party services. - MX: the servers that receive email for the domain. The number in front is the priority; lower values are preferred.
- NS: the authoritative nameservers for the domain. NS changes at the registrar take time to propagate.
- TXT: free-form text, used for verification (Google, Microsoft) and for SPF, DKIM and DMARC email security.
- SOA: zone information, including the primary nameserver and serial number.
- CAA: restricts which certificate authorities (CAs) may issue SSL certificates for the domain.
- PTR: reverse DNS, from an IP address to a hostname. Important for mail servers so their email isn’t flagged as spam.
Reading the TTL column
TTL is the remaining time (in seconds) an answer may be kept in a resolver’s cache. When you change a server’s IP, resolvers holding the old cached answer only ask again once the TTL runs out. That is what people usually mean by “DNS propagation”.
To check email security, use the SPF, DKIM & DMARC Checker.
Frequently asked questions
Why do results differ between resolvers?
Each resolver caches DNS answers for the TTL (time to live). After a record changes, a resolver still holding the old cached answer keeps returning it until the TTL expires. Differences can also come from GeoDNS or load balancing that returns different answers by location.
How long does a DNS change take to propagate?
It depends on the old record’s TTL. With a TTL of 3600 seconds, some resolvers may show the old data for up to about an hour after the change. For a migration, lower the TTL (for example to 300 seconds) a day before you change the record.
What do NXDOMAIN and SERVFAIL mean?
NXDOMAIN means the domain or subdomain does not exist. SERVFAIL means the resolver could not get an answer, often because the nameserver is not responding or DNSSEC is misconfigured.
What does “DNSSEC validated” mean?
It means the resolver successfully verified the DNSSEC signatures on the answer, so the data was not tampered with in transit. If the domain does not use DNSSEC, this label will not appear.
Does Cloudku store my lookups?
No. Queries go straight from your browser to public resolvers (Cloudflare, Google, AliDNS) over DNS-over-HTTPS, without passing through Cloudku’s servers.
Moving servers without DNS headaches?
Cloudku helps you migrate to our VPS or colocation, including setting up the right DNS records so your services stay online.