Advertisement

DNS Lookup & Global Propagation Checker

Query public DNS records (A, AAAA, MX, TXT, CNAME, NS, SOA, CAA, SRV, PTR, DS) and test global propagation live across 8 resolver networks.

DNS Resolution ResultsCloudflare DoH
NameTypeTTLRecord Value (Data)Copy
Enter a domain above and click "Dig Domain" to retrieve DNS records.
Advertisement
Advertisement

What is DNS and How Does This Tool Work?

The Domain Name System (DNS) serves as the decentralized phonebook of the Internet. It translates human-readable domain names (like google.com) into machine-readable IP addresses (like 142.250.190.46) so browsers can route traffic.

Our DNS Lookup & Global Propagation Checker works directly in your browser. It sends parallel requests to 8 globally distributed DNS-over-HTTPS (DoH) resolver networks (Cloudflare, Google Public DNS, Quad9, OpenDNS, AdGuard, NextDNS, DNS.WATCH, and CleanBrowsing) to query authoritative records, verify DNSSEC cryptographic signatures, and check real-time global propagation.


Supported Record Types

Record Type Description Primary Use Case
A (Address) Maps a domain name to its IPv4 address. Directing web traffic to a web server host.
AAAA (IPv6) Maps a domain name to its 128-bit IPv6 address. Directing web traffic on next-gen IPv6 networks.
CNAME (Canonical) Alias of one domain name to another domain. Mapping subdomains (like app.site.com to site.com).
MX (Mail Exchange) Specifies the mail servers receiving email. Directing incoming emails to Google Workspace, Outlook, etc.
TXT (Text) Holds raw text notes & machine-readable data. Implementing SPF, DKIM, and DMARC email verifications.
NS (Name Server) Lists authoritative name servers for a zone. Specifying which DNS host manages your domain.
SOA (Start of Authority) Contains administrative info about the DNS zone. Tracking zone serial numbers, refresh timers, and admin emails.
CAA (Certification) Defines authorized SSL certificate authorities. Restricting SSL cert issuance to prevent domain hijacking.
SRV (Service) Defines hostname and port for specific services. Configuring VoIP, Minecraft servers, and SIP communications.
PTR (Reverse IP) Maps an IP address back to a hostname. Validating mail server origins and anti-spam verification.
DS (Delegation Signer) DNSSEC key fingerprint record in parent zone. Securing DNS zone delegations against cache poisoning.

Key Diagnostic Features

  • 🌐 Global Propagation Grid (8 Locations): Automatically queries your domain across 8 global DNS locations in parallel (US, Europe, Germany, Global) to verify if new IP addresses or record changes have fully propagated.
  • 🔒 DNSSEC Cryptographic Validation: Checks if the domain has active DNSSEC signing (AD authentic data flag) to protect against DNS spoofing and cache poisoning attacks.
  • ✉️ Automated Email Security Audit: Performs instant background checks for v=spf1 and v=DMARC1 TXT policies.

Frequently Asked Questions (FAQ)

What is DNS Propagation and how long does it take?

DNS propagation is the time required for DNS changes (such as updating your website’s IP address or nameservers) to spread across all recursive DNS caches worldwide. Depending on your record’s TTL (Time to Live), full propagation usually takes between 5 minutes to 48 hours.

What does DNSSEC do?

DNSSEC (Domain Name System Security Extensions) adds cryptographic signatures to your DNS records. It ensures that the DNS responses received by browsers cannot be tampered with or intercepted by attackers on the network.

Why do some resolvers return different IP addresses?

If a domain uses a Global Content Delivery Network (CDN) like Cloudflare, AWS CloudFront, or Fastly, different DNS resolvers around the world will return the nearest regional CDN edge IP address to ensure fast loading speeds for local users.

Sponsored