To check a domain’s DNS records, query the specific record type you need with a browser lookup tool or the dig command. For example, run dig example.com MX to see the mail servers currently returned by your chosen resolver. A result is a time-specific view from that resolver—not a guaranteed export of every record configured at the DNS provider.
This guide explains the record types, browser and terminal methods, resolver differences, TTL-related delays, and safe troubleshooting steps.
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
DNS and BIND (5th Edition) | $38.88 | Buy on Amazon |
| 2 |
|
DNS & BIND Cookbook | $17.30 | Buy on Amazon |
| 3 |
|
DNS and BIND | $17.96 | Buy on Amazon |
| 4 |
|
DNS and BIND on IPv6: DNS for the Next-Generation Internet | $25.79 | Buy on Amazon |
| 5 |
|
DNS and BIND, Fourth Edition | $36.44 | Buy on Amazon |
What a DNS lookup actually shows
A DNS lookup asks for a domain name and record type, then displays the answer supplied by the resolver you queried. Each answer normally includes a record type, name, content or value, and TTL (time to live). TTL tells recursive resolvers how long they may cache the answer before asking again.
Because the response depends on the resolver, its cache, and the moment of the query, one lookup should not be treated as a complete zone export. A browser tool may show several common types, while a targeted query makes your question explicit.
#1 Best Overall
Choose the record type that matches your question
| Type | What it tells you | Typical question |
|---|---|---|
| A | IPv4 address for a name | Which IPv4 server does this hostname use? |
| AAAA | IPv6 address for a name | Is IPv6 configured? |
| CNAME | Alias to another canonical name | Where does this subdomain ultimately point? |
| MX | Mail-exchange destinations | Where should mail for this domain be delivered? |
| NS | Name servers authoritative for the domain | Which DNS servers publish the zone? |
| TXT | Arbitrary text, commonly verification and email-authentication data | Is a verification, SPF, DKIM, or DMARC value published? |
| SOA | Zone authority information | Which server is listed as primary authority and what serial is published? |
| SRV | Service target and port | Where is a named service hosted? |
Google Cloud’s record reference notes that the SPF record type is deprecated. Modern SPF policy is published as TXT data beginning with v=spf1, not as a separate SPF-type record.
Check records in a browser
- Open dns.google or another reputable DNS lookup interface.
- Enter the domain, such as
example.com. Use the hostname withouthttps://when the interface asks for a domain. - Select the record type—A, AAAA, MX, NS, TXT, CNAME, SOA, or SRV.
- Run the query and record the returned value, resolver context, and TTL.
- Repeat with another resolver if you are investigating a recent change or an apparent outage.
Browser tools are convenient for a quick inspection, but their result still represents the resolver and time shown by that service.
Use dig from a terminal
dig is useful when you need repeatable, type-specific queries or want to name the resolver explicitly. These commands work on most Linux and macOS systems; Windows users can install a DNS utility or use a browser interface.
Common queries
dig example.com A
dig example.com AAAA
dig example.com CNAME
dig example.com MX
dig example.com NS
dig example.com TXT
dig example.com SOA
dig example.com SRV
The default output includes the status, question, answer, authority and additional sections. The answer section contains the records returned for your query; the TTL appears beside each answer.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Ask a particular recursive resolver
dig @8.8.8.8 example.com A
dig @1.1.1.1 example.com MX
These examples compare answers from two recursive resolvers. Replace the resolver addresses with the service you are investigating.
Rank #2
Query the authoritative name server
First find the domain’s name servers:
dig example.com NS
Then query one returned server directly:
dig @ns1.example-dns.com example.com A
dig @ns1.example-dns.com example.com TXT
The name server hostname is only an example; use an actual NS value returned for the domain. Comparing an authoritative answer with a recursive answer helps separate published zone data from cached data.
Show only concise answers
dig +short example.com A
dig +short example.com MX
dig +short example.com TXT
Concise mode is convenient for scripts, but retain a full query when you need status, TTL, authority, or resolver details.
How to read the result
A and AAAA
An A record maps a name to an IPv4 address; AAAA maps it to IPv6. A hostname can have several of either type, so do not assume the first address is the only destination.
Free tools Windows power users keep installed
One-click scans. No signup required.
CNAME
A CNAME points a name to another name. The target can then resolve through its own A or AAAA records. Follow the chain when diagnosing a hosting or CDN configuration.
MX
MX records identify mail destinations and include preference values. Lower preference numbers are preferred when multiple destinations are available. An MX lookup does not prove that a mailbox exists or that a provider will accept a message.
Rank #3
NS and SOA
NS records identify the servers authoritative for the zone. SOA carries authority information, including a serial value and timing fields used by DNS systems.
TXT
TXT values are strings. They commonly hold domain-verification tokens and email-authentication policies. Long values may be displayed as multiple quoted strings; interpret them according to the protocol that uses them.
SRV
SRV records specify a service, protocol, priority, weight, port, and target. Query the exact service name required by the application, not only the base domain.
Diagnose a mismatch after changing DNS
- Write down the domain, exact record type, returned value, resolver, and TTL.
- Run the same type-specific query against a second recursive resolver.
- Query an authoritative name server listed by the domain’s NS records.
- Compare the authoritative value with each cached response.
- Wait for the relevant cached answers to expire according to their TTL, then test again.
A recent edit can coexist with an older answer while recursive caches retain it. A low TTL does not force every resolver to refresh immediately, and a high TTL can make a previous value persist longer. Do not declare a record absent from one cached response alone.
Common problems and fixes
“No answer” for a name
Confirm that you queried the intended hostname and type. A domain can have MX or TXT records without having an A record at the apex, and a name may legitimately lack AAAA or SRV data.
Rank #4
NXDOMAIN
NXDOMAIN means the queried name does not exist according to that resolver. Check spelling, the parent domain, and an authoritative server before concluding that the name was never created.
Old value after an edit
Compare recursive and authoritative answers and inspect TTL. If the authoritative server has the new value, cached resolvers are the likely explanation.
Different answers from different tools
Check whether the tools queried different record types, recursive resolvers, geographic endpoints, or authoritative servers. Record the resolver and timestamp for every comparison.
Unexpected CNAME or missing address
Follow the CNAME target and query its A and AAAA records. Also verify that the alias is allowed at the name where you placed it; some DNS configurations cannot combine a CNAME with other data at the same name.
Mail still fails after changing MX
Verify MX values and preferences, then inspect TXT-based email-authentication records separately. DNS visibility does not itself prove that the destination accepts mail, that TLS works, or that the application is configured correctly.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsBest Value
Lookup versus DNS management
A lookup only observes what a resolver returns. It does not add, delete, or edit records. To change DNS, sign in to the DNS management service responsible for the zone—the provider where the domain’s authoritative DNS is hosted or delegated. After saving a change, use the comparison procedure above to verify publication and cache behavior.
Performance, reliability, and evidence to keep
- Use a type-specific query rather than relying on a tool’s “all records” view when troubleshooting.
- Keep the resolver name, timestamp, record type, answer, and TTL in your incident notes.
- Use an authoritative query to check published zone data and recursive queries to understand what users may currently receive.
- Repeat important checks from more than one network or resolver when a change affects production.
- Never treat a successful DNS answer as proof that the web server, mail service, or application behind it is healthy.
Or skip the browser setup
If your workflow also needs a clean visual capture of a DNS dashboard or documentation page, ScreenshotNeo can return a screenshot or PDF with one request. It is separate from DNS lookup: it captures a URL rather than querying DNS records.
Use the API documentation at https://screenshotneo.com/docs/. For example:
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://dns.google -o shot.webp
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://dns.google"}, timeout=90)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://dns.google' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
Before capture, ScreenshotNeo accepts cookie or consent banners and removes more than 60 known consent platforms, newsletter popups, and chat widgets; each step can be disabled. Bot checks or CAPTCHAs, blank pages, timeouts, failed loads, and cache hits are not billed, and response headers identify the page verdict and billing status. Its MCP server provides take_screenshot, get_page_info, and capture_pdf tools for Claude, Cursor, and other MCP clients. The Free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000. Create a free ScreenshotNeo account.
Recommended Free Tools
FAQ
Can a DNS lookup reveal every record a provider has configured?
No. It reports answers for the queried name and type from the resolver used. Provider-side settings that are not published, or records for other names and types, will not appear.
Should I query the root domain or a subdomain?
Query the exact name used by the service. example.com, www.example.com, and mail.example.com can have different records.
Does changing TTL instantly update the internet?
No. A TTL governs how long a cached response may be reused; caches that already hold an earlier answer can continue serving it until their cache lifetime ends.
Can DNS lookup tools edit records?
No. Editing requires access to the DNS management service hosting or delegating the zone.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




