SecWeb

DNS Lookup

Inspect any domain's DNS records in seconds — A, AAAA, CNAME, MX, TXT, NS, SOA, and CAA. Free, instant, and no signup required.

Try:

What Is DNS and Why Does It Matter?

DNS stands for Domain Name System. It's often described as the phone book of the internet — but calling it a "phone book" undersells what it actually does. Every time someone visits your website, sends you an email, or connects to a service on your domain, DNS quietly does the work of translating a human-readable name like example.com into the machine addresses that computers actually use.

When DNS breaks, everything breaks. Your website stops loading. Emails bounce. SSL certificates fail to issue. That's why being able to inspect your DNS records directly is one of the most useful diagnostic skills for anyone who runs a website — from solo bloggers to growing SaaS teams.

This free DNS lookup tool queries authoritative nameservers in real time and returns every record associated with a domain. No caching delays, no signup, no rate-limit walls.

DNS Record Types Explained in Plain English

Every DNS record has a specific job. Understanding what each type does helps you diagnose problems and spot misconfigurations before they turn into outages.

A Record

Maps a domain to an IPv4 address. This is the record that tells browsers where your web server lives. If your A record points to the wrong IP, your site is unreachable — period.

AAAA Record

The IPv6 equivalent of an A record. As more of the internet migrates to IPv6, AAAA records become essential for reaching users on modern networks.

CNAME Record

An alias that points one hostname to another. Commonly used for www and CDN endpoints. For example, www.example.com often CNAMEs to the root domain or a CDN hostname.

MX Record

Directs email to the right mail server. Each MX entry has a priority value — lower numbers are tried first. If your MX records are wrong, email to your domain simply disappears.

TXT Record

Holds arbitrary text and is used for domain ownership verification, email authentication protocols (SPF, DKIM, DMARC), and security policies. This is where most email spoofing protection lives.

NS Record

Lists the authoritative nameservers responsible for your DNS zone. Changing your NS records is how you point a domain to a different hosting provider.

SOA Record

The "Start of Authority" record. It contains zone metadata — serial number, refresh intervals, retry timings, and the primary nameserver. You don't usually edit it manually, but it's essential for zone transfers.

CAA Record

Stands for Certificate Authority Authorization. It specifies which certificate authorities are allowed to issue SSL/TLS certificates for your domain — a strong defense against mis-issued certificates.

When You'll Actually Need a DNS Lookup

DNS lookups aren't just for sysadmins. Here are the practical scenarios where this tool saves you hours of guessing:

Frequently Asked Questions

A DNS lookup is a query sent to a domain name server asking it to return the records associated with a domain name. When you type example.com into a browser, your computer performs dozens of DNS lookups in the background to figure out which IP address to connect to, where to send email, and which certificates are valid.
It depends on the TTL (Time To Live) value of the record being changed. If the TTL is 300 seconds, the change propagates within 5 minutes in most regions. If the TTL is 86400 seconds (24 hours), old records can linger for up to a day. Best practice is to lower the TTL a day before making a major change, then raise it again once propagation is complete.
A DNS lookup returns the technical records that make your domain work (IPs, mail servers, etc.). A WHOIS lookup returns registration information — who owns the domain, when it was registered, when it expires, and which registrar manages it. Both are useful; they answer different questions. You can try our Domain Checker for WHOIS data.
DNS is cached at multiple layers — your local resolver, your ISP, and public resolvers. Even after adding a record, cached copies can linger for the duration of its TTL. Wait 5–30 minutes and try again. If it still doesn't appear, double-check that you added it to the correct DNS provider (nameservers must point there) and that the record name and value have no typos.
Yes — multiple A records enable basic load balancing and redundancy. The DNS resolver will typically return them in a rotating order (round-robin). If one server goes down, users still reach the others. Many large sites use this technique in combination with anycast routing for global reliability.
TTL stands for Time To Live. It's measured in seconds and tells resolvers how long they can cache the record before asking again. Lower TTLs mean faster propagation of changes but more DNS queries. Higher TTLs reduce server load but slow down updates. Most sites use 300–3600 seconds (5 minutes to 1 hour).
Yes — DNS records are inherently public. Anyone can query them with a single command. This is by design; the internet needs to know where to route traffic. That said, don't put secrets in TXT records — they're visible to everyone. Use TXT only for verification strings and public email policies.
An authoritative nameserver holds the actual DNS records for a zone — it's the source of truth. A recursive resolver is what your computer queries; it walks the DNS tree and caches results for you. This tool queries authoritative servers directly, so what you see is what the internet is being told.
SecWeb Icon

Add SecWeb to your Home Screen

Get quick access to your security scans directly from your device.

Tap the Share icon below, then select "Add to Home Screen".