Free DNS lookup
Look up public A, AAAA, CNAME, MX, TXT, NS, SOA, CAA, SRV, HTTPS, and PTR records for any domain, hostname, or IP address.
- Format
- Free browser tool
- Updated
- Updated
Live public DNS
Look up DNS records
Checking a new domain, mail setup, or DNS change? Enter the name and see what public resolvers return right now.
No account · No query stored by Bitfoo
Resolver response
DNS records
| Name | Type | TTL | Value |
|---|
No records found
The resolver returned no matching records for this query.
How to use the DNS lookup
- Enter a domain such as
example.com, a hostname such aswww.example.com, or a complete URL. - Choose “All common records” for a broad overview, or select one record type for a focused check.
- Use PTR with an IPv4 or IPv6 address when you need a reverse DNS lookup.
- Review the returned name, record type, time to live, value, resolver, response code, and DNSSEC status.
The tool sends separate requests for common record types instead of using an ANY query. Authoritative nameservers are not required to return every record in an ANY response, so explicit queries provide more useful results.
DNS record types this tool can check
| Record | What it tells you | Common use |
|---|---|---|
| A | The IPv4 address for a hostname | Pointing a website or service to an IPv4 server |
| AAAA | The IPv6 address for a hostname | Publishing IPv6 connectivity |
| CNAME | An alias pointing one hostname to another | Connecting subdomains to hosted services |
| MX | Mail servers and their priorities | Routing incoming email |
| TXT | Published text and policy values | SPF, DKIM, DMARC, ownership verification, and service configuration |
| NS | Nameservers published for a domain | Checking DNS delegation |
| SOA | Zone authority, serial number, and timing values | Checking zone version and cache settings |
| CAA | Certificate authorities allowed to issue certificates | Restricting TLS certificate issuance |
| SRV | A service target, port, priority, and weight | Locating services such as SIP or XMPP |
| HTTPS | Modern HTTPS service-binding information | Advertising alternative endpoints and connection parameters |
| PTR | The hostname associated with an IP address | Reverse DNS and mail-server identity checks |
How to read DNS lookup results
TTL, or time to live, is the number of seconds a recursive resolver may cache a record. A lower remaining TTL can make a recent change appear sooner at that resolver, but it does not prove that every resolver worldwide has refreshed.
NOERROR means the DNS query completed successfully, even when the selected record type does not exist. NXDOMAIN means the queried name does not exist. SERVFAIL means the resolver could not produce a valid answer, which can happen because of broken delegation, unreachable nameservers, or DNSSEC validation problems.
A “DNSSEC validated” result means the recursive resolver set the Authenticated Data flag after validating the response. When validation is not indicated, that alone does not prove the domain is unsafe or misconfigured.
Privacy, resolver view, and data sources
Bitfoo does not proxy or store the domain you enter. Your browser sends most queries directly to Cloudflare Public DNS over HTTPS. The tool uses the Google Public DNS JSON API for CAA and HTTPS records because it returns those values in a readable format, and as a fallback if Cloudflare cannot be reached. The domain or IP address is therefore disclosed to the resolver that answers the query.
Results show the public recursive resolver's current answer, including its cache. They are not a direct query to every authoritative nameserver and should not be presented as proof of worldwide DNS propagation. Record names and type numbers follow the IANA DNS parameters registry.
Common DNS lookup questions
Why does the lookup say no records were found?
A domain can exist without publishing every record type. For example, a hostname may have an A record but no AAAA or CNAME record. Check the exact hostname and choose the record type you expect.
Can this tool check DNS propagation?
It shows the answer from one public recursive resolver for each record type. Most queries use Cloudflare, while CAA and HTTPS queries use Google for readable values; either service may be used as a fallback. This is useful for confirming what a major resolver currently sees, but a true propagation comparison requires querying multiple independent resolvers and authoritative nameservers.
Can I check SPF, DKIM, or DMARC records?
Yes. Choose TXT and enter the exact hostname. SPF is commonly published at the domain, DMARC at _dmarc.example.com, and DKIM at a provider-specific selector such as selector._domainkey.example.com.
Why do I see a CNAME when I requested an A or AAAA record?
A resolver may include the alias chain needed to reach the final address. The CNAME shows the intermediate target, while the A or AAAA record shows the resulting address when it is available.
Does Bitfoo save my DNS query?
No. The lookup runs in your browser and the domain is not included in Bitfoo's tool analytics. The public DNS resolver still receives the query in order to answer it.
Continue troubleshooting DNS
Understand how DNS works
Follow a DNS request from a hostname through recursive and authoritative nameservers.
Troubleshooting guideDiagnose DNS errors
Separate record, delegation, caching, resolver, and DNSSEC problems before changing configuration.
Email guideUnderstand email DNS records
Learn how MX, SPF, DKIM, and DMARC work together without confusing routing and authentication.