Menu

DNS Lookup

Shows simulated DNS records. For authoritative results, use nslookup or a dedicated DNS tool.

DNS Lookup: How It Works

DNS translates names into addresses. When a website is unreachable, an email bounces, or a change 'has not taken effect yet', DNS is the first place to look — and a lookup tool answers most of those questions in seconds.

The record types

TypePoints toUsed for
AAn IPv4 addressThe main website record
AAAAAn IPv6 addressIPv6 connectivity
CNAMEAnother hostnameAliases — www to the root, CDN endpoints
MXA mail server, with priorityEmail delivery
TXTArbitrary textSPF, DKIM, DMARC, domain verification
NSAuthoritative nameserversDelegation
SOAZone metadataSerial number, refresh timings
PTRA hostname, from an addressReverse lookup, mail server reputation

Propagation is really caching

'DNS propagation' is a misleading phrase. Nothing spreads outward — a change is live at your authoritative nameserver immediately. What takes time is resolvers around the world expiring their cached copy of the old answer.

That expiry is governed by the record's TTL, in seconds. A 24-hour TTL means some resolvers serve the old value for up to a day. The practical technique: lower the TTL to 300 seconds at least 24 hours before a planned change, make the change, confirm it, then raise the TTL again. Doing this after the change has no effect, because the long TTL is already cached.

The email records

All three are now effectively required for reliable delivery to major providers. Mail from a domain without them is increasingly filtered or rejected outright, and a missing or broken record here is the usual cause of 'our emails go to spam'.

The CNAME restriction

A CNAME cannot coexist with any other record for the same name. This means the root of a domain — example.com with no subdomain — cannot use a CNAME, because it must carry SOA and NS records. Providers work around this with ALIAS or ANAME records that behave like a CNAME while returning an A record. This is why 'point your root domain at our CDN' is often more complicated than pointing www at it.

A diagnostic order

  1. Check the authoritative nameservers with an NS lookup — if those are wrong, nothing else matters.
  2. Query the authoritative server directly to see the intended answer.
  3. Query a public resolver to see what the world currently sees.
  4. Compare. A difference means caching, and the TTL tells you how long it will last.

Also check the registrar: a domain that has expired or has its nameservers unset will resolve to nothing regardless of how the zone is configured.

Frequently Asked Questions

How long do DNS changes take?
Up to the record's TTL, which is set in seconds. The change is live at your nameserver immediately; the delay is resolvers worldwide expiring their cached copy. Lower the TTL at least a day before a planned change.
Why do I still see the old site after updating DNS?
Caching — by your resolver, your operating system and your browser. Flushing local caches and testing from a different network or a mobile connection usually confirms the change is correct.
What is the difference between an A record and a CNAME?
An A record points a name directly at an IP address. A CNAME points it at another name, which is then resolved. CNAMEs cannot be used at the root of a domain because they cannot coexist with the required SOA and NS records.
Why are my emails going to spam?
Most often missing or broken SPF, DKIM and DMARC records. Major providers now effectively require all three. Check that exactly one SPF record exists — two makes both fail — and that DKIM and DMARC are published.
Why can't I use a CNAME on my root domain?
Because a CNAME cannot coexist with other records for the same name, and the root must carry SOA and NS records. Many providers offer ALIAS or ANAME records that behave similarly while returning an A record.
What does the TTL value mean?
How long, in seconds, resolvers may cache the answer before asking again. Low values make changes propagate quickly at the cost of more queries; high values reduce load but make changes slow to take effect.

Related Security Tools

Browse all Security tools →