DNS Record Lookup

Look up A, AAAA, MX, TXT, NS, CNAME, CAA and SOA records for any domain through Cloudflare or Google Public DNS. The query goes from your browser straight to the resolver over HTTPS.

Resolver

Your browser sends the query straight to the resolver you pick, over HTTPS. It never passes through iseeu.cc.

What it does

Your browser asks Cloudflare (1.1.1.1) or Google Public DNS (8.8.8.8) for the records published under a domain name, using the resolver's JSON DNS-over-HTTPS interface, and this page lays out the reply.

Each record is listed with its name, type, TTL and data. The TTL appears in seconds and as a readable duration, so 300 also reads as 5 min. You also get the response code (NOERROR, NXDOMAIN, SERVFAIL or REFUSED), whether the resolver set the AD flag (DNSSEC-validated), and how long the query took in your browser. TXT strings are printed in full, which matters for SPF, DMARC and long verification tokens.

Internationalized names work too: bücher.example is converted to xn--bcher-kva.example before it is sent, because that ASCII form is what actually lives in DNS.

How to use it

  1. Enter a domain name such as example.com or mail.example.com, without https:// or a path.
  2. Pick a record type: A, AAAA, MX, TXT, NS, CNAME, CAA or SOA. All queries each of those eight types in turn.
  3. Choose Cloudflare or Google Public DNS as the resolver.
  4. Run the lookup and check the response code before reading the records.
  5. To keep or share the result, copy the page address. The query rides after the #, as in #example.com/MX, so the lookup can be bookmarked or sent to a colleague.

The question does not pass through iseeu.cc's servers. Your browser talks directly to the resolver you picked, so that resolver sees your IP address and the name you asked about, under its own privacy policy. Google's resolver may pass part of your IP address to some authoritative servers (EDNS Client Subnet) so they can choose a nearby answer; Cloudflare's resolver says it does not. The part after # is never sent to any server, and iseeu.cc keeps no request logs or visitor database, sets no cookies and shows no ads.

Use cases

  • Checking a change you just made. Look up the new A record on both resolvers. If one still shows the old address, its TTL tells you roughly how long that cached copy has left.
  • Email delivery problems. Check MX, the v=spf1 TXT string on the domain, and TXT on _dmarc.example.com. Two separate SPF records are a common mistake that receivers treat as an error.
  • Before requesting a TLS certificate. Public CAs must check CAA before issuing, so a CAA record that names only your former CA will block the request.
  • Domain verification. When a hosted service asks for a TXT token, query TXT and compare the string character by character.
  • Moving DNS hosting. NS shows where the domain is delegated, and the SOA serial, which usually changes on every edit, helps confirm that the zone being served is the one you edited.
  • Spotting filtering or a stale cache. If Cloudflare and Google agree but dig against your usual resolver returns NXDOMAIN or a different address, the difference lies in your local resolver, not in the zone.

Reading the answer

NOERROR with no records, often called NODATA, means the name exists but holds nothing of the requested type, such as AAAA on an IPv4-only host. It also covers names that exist only because something sits below them: b.example.com when only a.b.example.com is defined. NXDOMAIN is stronger: the name does not exist for any type. Negative answers are cached too, for a period set by the zone's SOA record, so a name you queried before creating it can keep showing as missing for a while.

SERVFAIL means the resolver could not produce an answer. Both resolvers validate DNSSEC, and a frequent cause is a broken chain, such as a DS record left at the registrar after moving to a DNS host with different keys; unreachable authoritative servers cause it too. REFUSED means the server declined, which is uncommon from these two. The AD flag needs a signed domain; most are unsigned, so its absence is normal.

When the name is a CNAME, the answer lists the alias and then its target's records. A CNAME is not allowed at the zone apex; DNS hosts that emulate one there publish plain A and AAAA records, which is what you will see here. MX data reads as a preference and a host, as in 10 mail.example.com., lower numbers first; a lone 0 . is a null MX, meaning the domain accepts no mail.

TTLs, caches and propagation

DNS changes do not travel outward from your provider. Each resolver keeps a copy for as long as the TTL allows, then asks again. The TTL you see counts down from the published value: a record published with 3600 and cached 20 minutes ago shows about 2400. For up to one full TTL after an edit, some resolvers hold the new value and some the old. To make a change land quickly, lower the TTL first and wait at least the old TTL before editing. Name server changes take longer, because NS records in the parent zone often carry TTLs of a day or two. Different answers from the two resolvers are not always a fault: geographic DNS and load balancing tune answers to where the question appears to come from.

The same queries from a terminal

dig +short example.com MX @1.1.1.1
dig _dmarc.example.com TXT @8.8.8.8
dig +dnssec example.com A @1.1.1.1
nslookup -type=SOA example.com 8.8.8.8
Resolve-DnsName example.com -Type MX -Server 1.1.1.1

In full dig output, ad in the flags line is the same DNSSEC signal shown here. One difference matters: dig uses plain DNS on port 53, which some networks intercept and answer themselves. This page uses HTTPS, so if dig and this page disagree for the same resolver, something on your network is probably answering in its place.

Frequently asked questions

Why do Cloudflare and Google show different IP addresses for the same name?

Many large sites answer according to where the question seems to come from, using geographic DNS or load balancing. Google's resolver may pass part of your IP address to the authoritative server through EDNS Client Subnet, so its answer is tuned to your network, while Cloudflare's answer depends on the location of its own server. Two different addresses can both be correct. It only matters when one of them belongs to a host the domain owner has retired.

I changed a record an hour ago. Why do I still see the old value?

A resolver that cached the old record keeps serving it until its TTL runs out, and the TTL shown here is the time that copy has left. If the old record had a TTL of 86400 seconds, a cached copy can last up to a day. Run the query on the other resolver as well. If it shows the new value, your zone is correct and you are simply waiting for a cache to expire.

What is the difference between NXDOMAIN and an empty answer?

NXDOMAIN means the name does not exist at all, for any record type. NOERROR with no records means the name exists but has nothing of the type you asked for, such as an AAAA query for a host that only has an IPv4 address. If a name you just created returns NXDOMAIN, a resolver may still be holding a negative answer it cached before the name existed.

Does iseeu.cc see the domains I look up?

No. Your browser sends the query directly to Cloudflare or Google over HTTPS, and it does not pass through iseeu.cc's servers. The resolver you chose does see your IP address and the name, under its own privacy policy. The query kept after the # in the page address is never sent to any server. iseeu.cc keeps no request logs and no visitor database, sets no cookies and shows no ads.

Why can't I put a CNAME on my bare domain?

The zone apex must hold SOA and NS records, and a CNAME is not allowed to share its name with any other record. Some DNS hosts offer an apex alias, called ALIAS, ANAME or flattening depending on the company, which looks up the target for you and publishes ordinary A and AAAA records. A lookup on this page will show those addresses rather than a CNAME.

The answer is not marked as DNSSEC-validated. Is something wrong?

Usually not. The resolver sets the AD flag only when the domain is signed and the signatures check out from the root down. Most domains are unsigned, so they come back without it. The case to worry about is a signed domain that fails validation: validating resolvers then return SERVFAIL instead of an answer, often because a DS record at the registrar no longer matches the zone's keys.

How do I check a domain's email setup with this tool?

Query MX on the domain to see which hosts receive its mail. Query TXT on the same name and look for exactly one string that starts with v=spf1. Then query TXT on _dmarc in front of the domain, for example _dmarc.example.com, to read the DMARC policy. DKIM keys sit under a selector name inside _domainkey, and you need the selector from the sending service.

DNS answers change as records are edited and caches expire. The results reflect what the chosen resolver returned at the moment you asked, not a guarantee of what every resolver holds.