DNS Lookup: Check DNS Records and the SSL Certificate
DNS Lookup: Check the DNS Records and the SSL Certificate of a Domain
Enter a domain name and get its DNS records in one list: A, AAAA, CNAME, MX, NS, TXT, SOA and CAA. If the host answers on the HTTPS port, the page also shows the details of its SSL certificate. The tool is free, needs no registration and shows the answer of a real DNS resolver at once. You can paste a whole link: the host name is taken from it.
What the records mean
- A and AAAA. The IPv4 and IPv6 addresses of the host. This is the answer to the question "which IP address does this domain have".
- CNAME. An alias: the host name points to another name.
- MX. The mail servers of the domain with their priority. Mail goes first to the server with the lowest number. If a mail service reports a failed MX lookup, check this list first.
- NS. The name servers that answer for the domain.
- TXT. Free text; mostly SPF, DKIM, DMARC and the verification codes of services.
- SOA. The start of authority: the primary name server, the e-mail of the administrator, the serial number of the zone and the refresh, retry, expire and minimum TTL timers.
- CAA. Which certificate authorities may issue certificates for the domain.
The SSL certificate block
The tool connects to port 443 of the host and reads the certificate: the date from which and until which it is valid, the organization and the common name of the issuer, the country of the issuer and the type of the signature. The status shows whether today is inside the validity period. It does not check the chain of trust or that the name in the certificate fits the host, so use it to see when a certificate expires, not as a full security audit. The block is not shown if the host does not answer on port 443 or points to a private address.
DNS lookup failure, failed or error: what it means
A message like "DNS lookup failed" means that the program asked a DNS server for the address of a name and did not get a usable answer. The reasons are usually these:
- the name is mistyped, or the domain is not registered or has expired;
- the name servers of the domain do not answer or are set up wrongly (the resolver then reports SERVFAIL);
- the DNS server of your provider, router or company is down or blocked by a firewall;
- a VPN, a security program or a filter changes or blocks DNS queries on your device.
Enter the domain here. If the records are shown, the domain itself is fine and the problem is on your side: your DNS server, your network or the programs on your device. If nothing is found, the problem is in the domain or in its name servers.
CF DNS lookup failure in Cloudflare WARP
The error CF_DNS_LOOKUP_FAILURE in the Cloudflare WARP client means, according to the documentation of Cloudflare, that the client could not resolve host names through its local DNS proxy. The client does not connect, pages do not open, and the commands nslookup and dig fail on the device. Cloudflare advises to:
- check that the network you are in has DNS connectivity;
- check that DNS works when WARP is turned off;
- make sure that no other program takes control of DNS from WARP, and that no program decrypts (TLS inspection) the traffic to the WARP addresses;
- check that the device gets a valid IP address;
- restart the device or run the network diagnostics of the system.
This tool asks DNS from the server of dieg.dev, not from your device, so it cannot test WARP itself. It helps to exclude the other cause: if the site that you cannot open has records here, its DNS is working. dieg.dev is not connected with Cloudflare.
DNS error "type mx lookup" and SERVFAIL
Mail programs and services sometimes write that the DNS type mx lookup of a domain "responded with code SERVFAIL". SERVFAIL is a general answer "something went wrong": the resolver could not get a valid answer from the name servers of the domain. The reasons are a wrong delegation, name servers that do not answer, errors in the zone and broken DNSSEC signatures. Look at the NS and MX records here: they must exist and the name servers must answer.
DNS lookup from the command line
Windows (the command line or PowerShell):
nslookup example.com
nslookup -type=mx example.com
nslookup example.com 8.8.8.8
The third line asks the public DNS of Google (8.8.8.8) instead of your own server; the public DNS of Cloudflare has the address 1.1.1.1. If the answers differ, the problem is in your DNS server.
Linux and macOS:
dig example.com MX
host -t mx example.com
dig @8.8.8.8 example.com
Reverse DNS lookup
To find the host name of an IP address (the PTR record) use the IP lookup: it shows the host name and the location of the address.
Related tools
To read the registration data of a domain use the Whois lookup, to check the status code and the redirects of a page the HTTP status code and redirect checker, and to measure how fast the server answers the TTFB checker.
Similar tools
Free IP lookup: find the country, city, coordinates and timezone of an IP address and its host name with a reverse IP (reverse DNS) lookup. IPv4 and IPv6.
Free whois lookup: registrar, creation and expiry dates, status, DNSSEC and nameservers of a domain, or the network of an IP address. Uses RDAP and WHOIS.
Check from the United States (New York) whether a website is online: HTTP status code and response time in milliseconds. A free US ping test for any URL.
Popular tools
Check who hosts a website: the IP address, the hosting company (ASN), the country and the city of the server. Free hosting checker for any domain.
Free IP lookup: find the country, city, coordinates and timezone of an IP address and its host name with a reverse IP (reverse DNS) lookup. IPv4 and IPv6.
Free DNS lookup online: check A, AAAA, CNAME, MX, NS, TXT, SOA and CAA records of any domain, plus its SSL certificate. Find out why a DNS lookup fails.
Check from the United States (New York) whether a website is online: HTTP status code and response time in milliseconds. A free US ping test for any URL.