DNS Lookup
Look up any DNS record type for a domain, or the PTR record for an IP address. Resolved live over DNS over HTTPS.
MX records show where a domain's email is delivered. TXT records hold SPF and DMARC policies (DMARC lives at _dmarc.yourdomain). Resolved over DNS over HTTPS from your browser.
What each record type does
A and AAAA records point a name at an IPv4 or IPv6 address, which is how your website is found. MX records say which servers accept email for the domain. CNAME records alias one name to another, common for services like autodiscover or a hosted website. NS records name the servers that answer for the domain, and the SOA record identifies the primary one along with the zone serial number.
TXT records carry policy and verification text. This is where SPF lives, where domain ownership proofs for Microsoft 365, Google and other services go, and where DMARC sits under the _dmarc subdomain. CAA records restrict which certificate authorities may issue certificates for the domain. PTR records do the reverse job, mapping an IP address back to a name, and are checked by receiving mail servers.
Checking your email domain in three lookups
Look up MX for your domain. For Microsoft 365 you should see a single record ending in mail.protection.outlook.com. Anything else, or an old server still listed, is either a misconfiguration or a leftover from a previous provider.
Look up TXT for your domain and find the entry that starts v=spf1. It should list only the services that genuinely send mail for you and end in -all or ~all. Then look up TXT for _dmarc.yourdomain and check the p= value. p=none only monitors. p=quarantine or p=reject actually stops spoofed mail being delivered.
DKIM lives on selector names that vary by provider. For Microsoft 365, look up CNAME for selector1._domainkey.yourdomain and selector2._domainkey.yourdomain. Both should resolve to onmicrosoft.com names.
Why results can differ from what you expect
This tool resolves over DNS over HTTPS through a public resolver, so you see what the wider internet sees rather than any cached or internal answer. A record you changed a few minutes ago may not appear until its time to live expires. Proxied records behind Cloudflare will show Cloudflareās addresses rather than the origin server, which is by design.
DNS Lookup: common questions
Why does my domain show two MX records?
Usually one is current and one is a leftover from a previous email provider. Receiving servers pick the lowest priority number, so a stale record with a lower number can silently divert mail. Remove any MX record that does not belong to your current email service.
What should a good SPF record look like?
One TXT record beginning v=spf1, listing only the services that send mail for you, for example include:spf.protection.outlook.com for Microsoft 365, and ending in -all. Having more than one SPF record, or more than ten DNS lookups inside it, causes SPF to fail.
How long do DNS changes take to show up?
Until the old recordās time to live expires, which is often between five minutes and 24 hours depending on the setting. Lowering the TTL a day before a planned change makes the switch faster.
Does this tool see my internal DNS?
No. It queries public resolvers over DNS over HTTPS from your browser, so it only sees records published to the internet. Names that exist only on your office network will not resolve here.
More free tools
Is your email domain protected?
Missing SPF, DKIM or DMARC records let attackers send email as your business. Our free Microsoft 365 monitoring checks every domain you own and tells you exactly what to fix.
