DNS Lookup

Query all DNS records for a domain

DNS Lookup
hitclub1.mobi favicon

hitclub1.mobi

DNS Query

Query Type
ALL
Query Name
Nameserver
curt.ns.cloudflare.com
Resolution
AUTHORITATIVE
Transport
TCP
Total Time
334ms

DNS Records

SOASOA Records(1)
Trace
<<>>Question: hitclub1.mobi SOA, Status: NOERROR, Flags: AA, CD; Answers: 1, Trace: 3 hops, 262ms total
01▕→
a.root-servers.net (198.41.0.4) received 469 bytes in 16ms
02▕→
a0.mobi.afilias-nst.info (199.254.55.1) received 161 bytes in 174ms
03▕→
curt.ns.cloudflare.com (108.162.193.94) received 115 bytes in 72ms✓
TYPEHOSTTTLVALUE
SOA@30mcurt.ns.cloudflare.com dns.cloudflare.com 2416083784 10000 2400 604800 1800 
NSNS Records(2)
Trace
<<>>Question: hitclub1.mobi NS, Status: NOERROR, Flags: AA, CD; Answers: 2, Trace: 3 hops, 266ms total
01▕→
a.root-servers.net (198.41.0.4) received 469 bytes in 30ms
02▕→
a0.mobi.afilias-nst.info (199.254.55.1) received 160 bytes in 176ms
03▕→
curt.ns.cloudflare.com (108.162.193.94) received 110 bytes in 60ms✓
TYPEHOSTTTLVALUE
NS@1dcurt.ns.cloudflare.com 
NS@1ddalary.ns.cloudflare.com 
AA Records(148)
Trace
<<>>Question: hitclub1.mobi A, Status: NOERROR, Flags: AA, CD; Answers: 2, Trace: 3 hops, 265ms total
01▕→
a.root-servers.net (198.41.0.4) received 469 bytes in 21ms
02▕→
a0.mobi.afilias-nst.info (199.254.55.1) received 161 bytes in 180ms
03▕→
curt.ns.cloudflare.com (108.162.193.94) received 83 bytes in 64ms✓
TYPEHOSTTTLADDRESS
A@5m104.21.4.251 
A@5m172.67.132.170 
Awww5m104.21.4.251 
Awww5m172.67.132.170 
Ans15m104.21.4.251 
Ans15m172.67.132.170 
Ans25m104.21.4.251 
Ans25m172.67.132.170 
Ans35m104.21.4.251 
Ans35m172.67.132.170 
Ans45m104.21.4.251 
Ans45m172.67.132.170 
Aadmin5m104.21.4.251 
Aadmin5m172.67.132.170 
Aalpha5m104.21.4.251 
Aalpha5m172.67.132.170 
Aapi5m104.21.4.251 
Aapi5m172.67.132.170 
Aapp5m104.21.4.251 
Aapp5m172.67.132.170 
Aapps5m104.21.4.251 
Aapps5m172.67.132.170 
Aassets5m104.21.4.251 
Aassets5m172.67.132.170 
Aauth5m104.21.4.251 
Aauth5m172.67.132.170 
Abeta5m104.21.4.251 
Abeta5m172.67.132.170 
Ablog5m104.21.4.251 
Ablog5m172.67.132.170 
Abounces5m104.21.4.251 
Abounces5m172.67.132.170 
Acart5m104.21.4.251 
Acart5m172.67.132.170 
Acdn5m104.21.4.251 
Acdn5m172.67.132.170 
Acheckout5m104.21.4.251 
Acheckout5m172.67.132.170 
Acloud5m104.21.4.251 
Acloud5m172.67.132.170 
Aconsole5m104.21.4.251 
Aconsole5m172.67.132.170 
Acontent5m104.21.4.251 
Acontent5m172.67.132.170 
Acontrol5m104.21.4.251 
Acontrol5m172.67.132.170 
Acpanel5m104.21.4.251 
Acpanel5m172.67.132.170 
Adash5m104.21.4.251 
Adash5m172.67.132.170 
Adashboard5m104.21.4.251 
Adashboard5m172.67.132.170 
Adata5m104.21.4.251 
Adata5m172.67.132.170 
Ademo5m104.21.4.251 
Ademo5m172.67.132.170 
Adev5m104.21.4.251 
Adev5m172.67.132.170 
Adns5m104.21.4.251 
Adns5m172.67.132.170 
Adocs5m104.21.4.251 
Adocs5m172.67.132.170 
Aedge5m104.21.4.251 
Aedge5m172.67.132.170 
Aemail5m104.21.4.251 
Aemail5m172.67.132.170 
Afeedback5m104.21.4.251 
Afeedback5m172.67.132.170 
Afiles5m104.21.4.251 
Afiles5m172.67.132.170 
Aforum5m104.21.4.251 
Aforum5m172.67.132.170 
Aftp5m104.21.4.251 
Aftp5m172.67.132.170 
Ahelp5m104.21.4.251 
Ahelp5m172.67.132.170 
Aimages5m104.21.4.251 
Aimages5m172.67.132.170 
Aimap5m104.21.4.251 
Aimap5m172.67.132.170 
Aimg5m104.21.4.251 
Aimg5m172.67.132.170 
Akb5m104.21.4.251 
Akb5m172.67.132.170 
Alogin5m104.21.4.251 
Alogin5m172.67.132.170 
Am5m104.21.4.251 
Am5m172.67.132.170 
Amail5m104.21.4.251 
Amail5m172.67.132.170 
Amanage5m104.21.4.251 
Amanage5m172.67.132.170 
Amedia5m104.21.4.251 
Amedia5m172.67.132.170 
Amobile5m104.21.4.251 
Amobile5m172.67.132.170 
Amx5m104.21.4.251 
Amx5m172.67.132.170 
Ans5m104.21.4.251 
Ans5m172.67.132.170 
Apanel5m104.21.4.251 
Apanel5m172.67.132.170 
Apop5m104.21.4.251 
Apop5m172.67.132.170 
Apop35m104.21.4.251 
Apop35m172.67.132.170 
Aportal5m104.21.4.251 
Aportal5m172.67.132.170 
Apreview5m104.21.4.251 
Apreview5m172.67.132.170 
Aqa5m104.21.4.251 
Aqa5m172.67.132.170 
Aremote5m104.21.4.251 
Aremote5m172.67.132.170 
Asandbox5m104.21.4.251 
Asandbox5m172.67.132.170 
Asftp5m104.21.4.251 
Asftp5m172.67.132.170 
Ashop5m104.21.4.251 
Ashop5m172.67.132.170 
Asmtp5m104.21.4.251 
Asmtp5m172.67.132.170 
Asso5m104.21.4.251 
Asso5m172.67.132.170 
Astaging5m104.21.4.251 
Astaging5m172.67.132.170 
Astatic5m104.21.4.251 
Astatic5m172.67.132.170 
Astatus5m104.21.4.251 
Astatus5m172.67.132.170 
Astore5m104.21.4.251 
Astore5m172.67.132.170 
Asupport5m104.21.4.251 
Asupport5m172.67.132.170 
Atest5m104.21.4.251 
Atest5m172.67.132.170 
Atesting5m104.21.4.251 
Atesting5m172.67.132.170 
Auat5m104.21.4.251 
Auat5m172.67.132.170 
Awebdisk5m104.21.4.251 
Awebdisk5m172.67.132.170 
Awebmail5m104.21.4.251 
Awebmail5m172.67.132.170 
Awhm5m104.21.4.251 
Awhm5m172.67.132.170 
Aws5m104.21.4.251 
Aws5m172.67.132.170 
AAAAAAAA Records(148)
Trace
<<>>Question: hitclub1.mobi AAAA, Status: NOERROR, Flags: AA, CD; Answers: 2, Trace: 3 hops, 259ms total
01▕→
a.root-servers.net (198.41.0.4) received 469 bytes in 28ms
02▕→
a0.mobi.afilias-nst.info (199.254.55.1) received 161 bytes in 167ms
03▕→
curt.ns.cloudflare.com (108.162.193.94) received 110 bytes in 64ms✓
TYPEHOSTTTLADDRESS
AAAA@5m2606:4700:3031::ac43:84aa 
AAAA@5m2606:4700:3033::6815:4fb 
AAAAwww5m2606:4700:3031::ac43:84aa 
AAAAwww5m2606:4700:3033::6815:4fb 
AAAAns15m2606:4700:3031::ac43:84aa 
AAAAns15m2606:4700:3033::6815:4fb 
AAAAns25m2606:4700:3031::ac43:84aa 
AAAAns25m2606:4700:3033::6815:4fb 
AAAAns35m2606:4700:3031::ac43:84aa 
AAAAns35m2606:4700:3033::6815:4fb 
AAAAns45m2606:4700:3031::ac43:84aa 
AAAAns45m2606:4700:3033::6815:4fb 
AAAAadmin5m2606:4700:3031::ac43:84aa 
AAAAadmin5m2606:4700:3033::6815:4fb 
AAAAalpha5m2606:4700:3031::ac43:84aa 
AAAAalpha5m2606:4700:3033::6815:4fb 
AAAAapi5m2606:4700:3031::ac43:84aa 
AAAAapi5m2606:4700:3033::6815:4fb 
AAAAapp5m2606:4700:3031::ac43:84aa 
AAAAapp5m2606:4700:3033::6815:4fb 
AAAAapps5m2606:4700:3031::ac43:84aa 
AAAAapps5m2606:4700:3033::6815:4fb 
AAAAassets5m2606:4700:3031::ac43:84aa 
AAAAassets5m2606:4700:3033::6815:4fb 
AAAAauth5m2606:4700:3031::ac43:84aa 
AAAAauth5m2606:4700:3033::6815:4fb 
AAAAbeta5m2606:4700:3031::ac43:84aa 
AAAAbeta5m2606:4700:3033::6815:4fb 
AAAAblog5m2606:4700:3031::ac43:84aa 
AAAAblog5m2606:4700:3033::6815:4fb 
AAAAbounces5m2606:4700:3031::ac43:84aa 
AAAAbounces5m2606:4700:3033::6815:4fb 
AAAAcart5m2606:4700:3031::ac43:84aa 
AAAAcart5m2606:4700:3033::6815:4fb 
AAAAcdn5m2606:4700:3031::ac43:84aa 
AAAAcdn5m2606:4700:3033::6815:4fb 
AAAAcheckout5m2606:4700:3031::ac43:84aa 
AAAAcheckout5m2606:4700:3033::6815:4fb 
AAAAcloud5m2606:4700:3031::ac43:84aa 
AAAAcloud5m2606:4700:3033::6815:4fb 
AAAAconsole5m2606:4700:3031::ac43:84aa 
AAAAconsole5m2606:4700:3033::6815:4fb 
AAAAcontent5m2606:4700:3031::ac43:84aa 
AAAAcontent5m2606:4700:3033::6815:4fb 
AAAAcontrol5m2606:4700:3031::ac43:84aa 
AAAAcontrol5m2606:4700:3033::6815:4fb 
AAAAcpanel5m2606:4700:3031::ac43:84aa 
AAAAcpanel5m2606:4700:3033::6815:4fb 
AAAAdash5m2606:4700:3031::ac43:84aa 
AAAAdash5m2606:4700:3033::6815:4fb 
AAAAdashboard5m2606:4700:3031::ac43:84aa 
AAAAdashboard5m2606:4700:3033::6815:4fb 
AAAAdata5m2606:4700:3031::ac43:84aa 
AAAAdata5m2606:4700:3033::6815:4fb 
AAAAdemo5m2606:4700:3031::ac43:84aa 
AAAAdemo5m2606:4700:3033::6815:4fb 
AAAAdev5m2606:4700:3031::ac43:84aa 
AAAAdev5m2606:4700:3033::6815:4fb 
AAAAdns5m2606:4700:3031::ac43:84aa 
AAAAdns5m2606:4700:3033::6815:4fb 
AAAAdocs5m2606:4700:3031::ac43:84aa 
AAAAdocs5m2606:4700:3033::6815:4fb 
AAAAedge5m2606:4700:3031::ac43:84aa 
AAAAedge5m2606:4700:3033::6815:4fb 
AAAAemail5m2606:4700:3031::ac43:84aa 
AAAAemail5m2606:4700:3033::6815:4fb 
AAAAfeedback5m2606:4700:3031::ac43:84aa 
AAAAfeedback5m2606:4700:3033::6815:4fb 
AAAAfiles5m2606:4700:3031::ac43:84aa 
AAAAfiles5m2606:4700:3033::6815:4fb 
AAAAforum5m2606:4700:3031::ac43:84aa 
AAAAforum5m2606:4700:3033::6815:4fb 
AAAAftp5m2606:4700:3031::ac43:84aa 
AAAAftp5m2606:4700:3033::6815:4fb 
AAAAhelp5m2606:4700:3031::ac43:84aa 
AAAAhelp5m2606:4700:3033::6815:4fb 
AAAAimages5m2606:4700:3031::ac43:84aa 
AAAAimages5m2606:4700:3033::6815:4fb 
AAAAimap5m2606:4700:3031::ac43:84aa 
AAAAimap5m2606:4700:3033::6815:4fb 
AAAAimg5m2606:4700:3031::ac43:84aa 
AAAAimg5m2606:4700:3033::6815:4fb 
AAAAkb5m2606:4700:3031::ac43:84aa 
AAAAkb5m2606:4700:3033::6815:4fb 
AAAAlogin5m2606:4700:3031::ac43:84aa 
AAAAlogin5m2606:4700:3033::6815:4fb 
AAAAm5m2606:4700:3031::ac43:84aa 
AAAAm5m2606:4700:3033::6815:4fb 
AAAAmail5m2606:4700:3031::ac43:84aa 
AAAAmail5m2606:4700:3033::6815:4fb 
AAAAmanage5m2606:4700:3031::ac43:84aa 
AAAAmanage5m2606:4700:3033::6815:4fb 
AAAAmedia5m2606:4700:3031::ac43:84aa 
AAAAmedia5m2606:4700:3033::6815:4fb 
AAAAmobile5m2606:4700:3031::ac43:84aa 
AAAAmobile5m2606:4700:3033::6815:4fb 
AAAAmx5m2606:4700:3031::ac43:84aa 
AAAAmx5m2606:4700:3033::6815:4fb 
AAAAns5m2606:4700:3031::ac43:84aa 
AAAAns5m2606:4700:3033::6815:4fb 
AAAApanel5m2606:4700:3031::ac43:84aa 
AAAApanel5m2606:4700:3033::6815:4fb 
AAAApop5m2606:4700:3031::ac43:84aa 
AAAApop5m2606:4700:3033::6815:4fb 
AAAApop35m2606:4700:3031::ac43:84aa 
AAAApop35m2606:4700:3033::6815:4fb 
AAAAportal5m2606:4700:3031::ac43:84aa 
AAAAportal5m2606:4700:3033::6815:4fb 
AAAApreview5m2606:4700:3031::ac43:84aa 
AAAApreview5m2606:4700:3033::6815:4fb 
AAAAqa5m2606:4700:3031::ac43:84aa 
AAAAqa5m2606:4700:3033::6815:4fb 
AAAAremote5m2606:4700:3031::ac43:84aa 
AAAAremote5m2606:4700:3033::6815:4fb 
AAAAsandbox5m2606:4700:3031::ac43:84aa 
AAAAsandbox5m2606:4700:3033::6815:4fb 
AAAAsftp5m2606:4700:3031::ac43:84aa 
AAAAsftp5m2606:4700:3033::6815:4fb 
AAAAshop5m2606:4700:3031::ac43:84aa 
AAAAshop5m2606:4700:3033::6815:4fb 
AAAAsmtp5m2606:4700:3031::ac43:84aa 
AAAAsmtp5m2606:4700:3033::6815:4fb 
AAAAsso5m2606:4700:3031::ac43:84aa 
AAAAsso5m2606:4700:3033::6815:4fb 
AAAAstaging5m2606:4700:3031::ac43:84aa 
AAAAstaging5m2606:4700:3033::6815:4fb 
AAAAstatic5m2606:4700:3031::ac43:84aa 
AAAAstatic5m2606:4700:3033::6815:4fb 
AAAAstatus5m2606:4700:3031::ac43:84aa 
AAAAstatus5m2606:4700:3033::6815:4fb 
AAAAstore5m2606:4700:3031::ac43:84aa 
AAAAstore5m2606:4700:3033::6815:4fb 
AAAAsupport5m2606:4700:3031::ac43:84aa 
AAAAsupport5m2606:4700:3033::6815:4fb 
AAAAtest5m2606:4700:3031::ac43:84aa 
AAAAtest5m2606:4700:3033::6815:4fb 
AAAAtesting5m2606:4700:3031::ac43:84aa 
AAAAtesting5m2606:4700:3033::6815:4fb 
AAAAuat5m2606:4700:3031::ac43:84aa 
AAAAuat5m2606:4700:3033::6815:4fb 
AAAAwebdisk5m2606:4700:3031::ac43:84aa 
AAAAwebdisk5m2606:4700:3033::6815:4fb 
AAAAwebmail5m2606:4700:3031::ac43:84aa 
AAAAwebmail5m2606:4700:3033::6815:4fb 
AAAAwhm5m2606:4700:3031::ac43:84aa 
AAAAwhm5m2606:4700:3033::6815:4fb 
AAAAws5m2606:4700:3031::ac43:84aa 
AAAAws5m2606:4700:3033::6815:4fb 
CNAMECNAME Records(0)
Trace
<<>>Question: hitclub1.mobi CNAME, Status: NOERROR, Flags: AA, CD; Answers: 0, Trace: 3 hops, 269ms total
01▕→
a.root-servers.net (198.41.0.4) received 469 bytes in 21ms
02▕→
a0.mobi.afilias-nst.info (199.254.55.1) received 161 bytes in 173ms
03▕→
curt.ns.cloudflare.com (108.162.193.94) received 116 bytes in 75ms✓
NO RECORDS FOUND
MXMX Records(0)
Trace
<<>>Question: hitclub1.mobi MX, Status: NOERROR, Flags: AA, CD; Answers: 0, Trace: 3 hops, 264ms total
01▕→
a.root-servers.net (198.41.0.4) received 469 bytes in 13ms
02▕→
a0.mobi.afilias-nst.info (199.254.55.1) received 160 bytes in 183ms
03▕→
curt.ns.cloudflare.com (108.162.193.94) received 115 bytes in 68ms✓
NO RECORDS FOUND
TXTTXT Records(0)
Trace
<<>>Question: hitclub1.mobi TXT, Status: NOERROR, Flags: AA, CD; Answers: 0, Trace: 3 hops, 265ms total
01▕→
a.root-servers.net (198.41.0.4) received 469 bytes in 15ms
02▕→
a0.mobi.afilias-nst.info (199.254.55.1) received 160 bytes in 177ms
03▕→
curt.ns.cloudflare.com (108.162.193.94) received 114 bytes in 73ms✓
NO RECORDS FOUND

JSON API Response

{
tool: "dns"
query: "hitclub1.mobi"
queryType: "ALL"
server: "108.162.193.94"
serverHost: "curt.ns.cloudflare.com"
serverType: "authoritative"
transport: "tcp"
recursive: false
dnssec: false
subdomains: true
requestId: "5de8964a-3148-4876-8154-3e2f322a5585"
timestamp: "2026-10-08T06:02:47.727Z"
elapsed: 315
results: [
[]
[]
[]
]
}
Need DNS data?
Get started with our API.
DNS API
  • Query: hitclub1.mobi
  • Request ID: 5de8964a
  • Timestamp: 2026-10-08 06:02 UTC
  • Elapsed: 315ms / Retries: 0
  • Cached: true

How does it work?

This tool performs recursive resolution through the full DNS hierarchy, from root servers to authoritative nameservers, bypassing any caching layers. It fetches all major record types (A, CNAME, MX, TXT, etc.), along with a query trace showing per-hop latency, for a complete and live view of DNS.

When should you run a DNS Lookup?

It could be the move when diagnosing website connectivity problems or making any DNS changes – waiting for propagation is never a good strategy. Use it to cut through ISP caches, office VPNs, and those "is it down or just me" guesses. Whether you're planning a big migration, verifying domain ownership, or setting up authenticated email, this tool gives you the answers straight from the authoritative source.

Frequently Asked Questions

How is this different from dig or nslookup?

Unlike command-line tools dig and nslookup which only return one record type at a time, this tool queries for all common DNS record types in parallel and performs full recursive resolution from the root servers down to the domain's authoritative nameservers, complete with a diagnostic trace showing per-hop latency. It's like running a whole suite of dig +trace commands for every record type, but with a user-friendly web interface that doesn't require memorizing command-line syntax.

What DNS records are supported?

The DNS Lookup tool supports a comprehensive set of record types, including a special ALL query that fetches the most common and critical record types in a single request.

Here are all the officially supported DNS record types:

  • SOA - Contains administrative information about a DNS zone
  • NS - Specifies which name servers are authoritative for a domain
  • A - Maps domain names to IPv4 addresses
  • AAAA - Maps domain names to IPv6 addresses
  • CNAME - Creates an alias that points one domain name to another
  • DNAME - Redirects an entire subdomain tree to another domain
  • MX - Directs email to mail servers with priority settings
  • TXT - Stores text information for verification, SPF, DKIM, and other purposes
  • CAA - Controls which certificate authorities can issue SSL certificates
  • TLSA - Associates SSL certificates with domain names (DANE)
  • DS - Delegation signer that enables DNSSEC for subdomains
  • DNSKEY - Public key used for DNSSEC validation
  • RRSIG - Digital signature that validates other DNS records (DNSSEC)
  • NSEC - Proves that certain DNS records do not exist (DNSSEC)
  • NSEC3 - Enhanced NSEC with hashed domain names for privacy (DNSSEC)
  • NSEC3PARAM - Parameters for NSEC3 hashing algorithm (DNSSEC)
  • CDS - Child DS record for secure domain transfers
  • CDNSKEY - Child DNSKEY record for secure domain delegation
  • KEY - Legacy security key record (replaced by DNSKEY)
  • SIG - Legacy digital signature record (replaced by RRSIG)
  • SRV - Specifies the location of services like email or chat servers
  • HTTPS - HTTPS service binding for secure web services
  • SVCB - General-purpose service binding record
  • CERT - Stores digital certificates and cryptographic keys
  • HINFO - Host information including CPU and operating system details
  • TSIG - Authenticates DNS messages between servers
  • OPENPGPKEY - OpenPGP public key for email encryption
  • RP - Responsible person contact information for a domain
  • SSHFP - SSH host key fingerprints for secure connections
  • URI - Maps domain names to Uniform Resource Identifiers
  • NAPTR - Maps domain names to services like phone numbers or URIs
  • LOC - Geographical location information for a domain
  • PTR - Maps IP addresses back to domain names for reverse DNS
How does DNS propagation work? What even is a TTL?

DNS Propagation is a misleading term – nothing actually "propagates" across the internet. Instead, thousands of recursive resolvers worldwide independently cache your DNS records, each for as long as your TTL (Time To Live) allows. When you update a record, authoritative nameservers show the change immediately, but cached copies must expire before resolvers fetch the new data. A high TTL (e.g. 24 hours) means some resolvers will continue to serve old data for that long, creating the illusion of slow propagation. Most updates today settle within minutes to a few hours; the infamous "48-hour propagation" was a relic from the days when everyone used 48 hour TTLs by default.

TTL (Time To Live) is the number of seconds a DNS answer may be cached by resolvers before they must re‑query the authoritative server. Each DNS record carries its own TTL, and caches honor the value they previously received until it expires. The TTL value you set represents a trade-off between performance and agility:

  • Higher TTLs (e.g. 24 hours) reduce the query load on your authoritative nameservers and speed up lookups for repeat visitors through local caching, but they also extend the "propagation" time for changes, delaying the visibility of DNS updates.
  • Lower TTLs (e.g. 5 minutes) allow for faster updates, but increase the number of queries your nameservers must handle.

When planning DNS changes, lower TTLs ahead of time, make the change, then raise them again. If updates seem stuck, check the prior TTL, flush DNS caches, and compare authoritative answers to public resolvers. Some resolvers enforce minimums, so ultra‑low TTLs (like 30s) may be rounded up.

Authoritative vs. Recursive DNS servers – what's the difference?
  • Authoritative servers are the definitive source of truth for a DNS zone. They host the actual records (the master copies) and always return the current configuration. When a domain owner updates their DNS records, the changes are made on the authoritative servers and take effect there immediately.
  • Recursive resolvers (run by your ISP, workplace, or a public DNS provider) fetch DNS answers by following the DNS hierarchy – starting at the root servers, then TLD servers, and finally the authoritative servers. They cache the results for the period defined by each record's TTL. This caching speeds up lookups but can cause outdated answers to linger until the TTL expires, creating the illusion of slow "propagation."

For troubleshooting, remember: recursive servers may serve stale data, but authoritative servers always return the current configuration. Our DNS Lookup tool queries authoritative servers directly by default, bypassing caching layers.

What does DNSSEC do?

DNSSEC (DNS Security Extensions) adds cryptographic signatures to DNS records, preventing tampering and forgery. When DNS was first created, it had no built-in security, making it vulnerable to cache poisoning and man-in-the-middle attacks. DNSSEC addresses this by creating a chain of trust from the root servers down to individual domains, digitally signing each layer of the hierarchy so DNS responses can be verified as authentic.

Our DNS Lookup tool displays all DNSSEC-related records (DS, DNSKEY, RRSIG, NSEC/NSEC3) alongside the regular answers so you can see whether signing is in place, but it doesn't perform full cryptographic validation. For complete end-to-end verification of the chain of trust, use the dedicated DNSSEC Tool.

Why is it always DNS?

Because DNS is a fragile house of cards, a spindly web held together by RFCs, glue records, and tribal knowledge. It's invisible when working and catastrophic when broken. When your website is down or your email bounces, start with DNS. It's probably DNS. It's always DNS.

Domain Intelligence APIs

Get started with our easy-to-use API docs.