DNS Lookup

Look up A, MX, TXT, CAA, NS, SOA, SRV and PTR records from your browser over DNS-over-HTTPS. Pick Cloudflare or Google, see the DNSSEC flag and the raw JSON.

  • Lookups send the domain name to the DNS resolver you pick (Cloudflare or Google)
  • Free · No Sign-Up
Enter a domain or a full URL, then press Lookup or Enter. URLs, ports, trailing dots, full-width characters and international names are normalized to an ASCII hostname. Names need at least two labels; each label allows 1–63 letters, digits, hyphens or underscores and cannot start or end with a hyphen, up to 253 characters in total. An invalid name is reported with the character position or the label that breaks a rule.
ALL queries A, AAAA, CNAME, MX, TXT, NS, SOA and CAA together. Query PTR and SRV separately with the full reverse or service name; IP addresses are not converted to reverse names.
Queries go directly from your browser to the selected Cloudflare or Google resolver, which sees your IP address and the queried name. Each request times out after 5 seconds; try the other resolver if one is blocked.
Try:

DNS records, resolver status and the response JSON appear here after a lookup.

Read the full guide DNS Lookup in the Browser: A, MX, TXT, and CAA via DNS-over-HTTPS
Examples, details and FAQ Worked examples, how it compares with other tools, and answers to common questions.

Three Real Lookups

These ran on 2026-09-29; the AD flag and dnssec-failed.org results were checked again on 2026-09-30. Run them again and the TTLs will differ; the rest should match until the owners change their DNS.

Our own mail setup. zerotool.dev with type MX returns three Cloudflare Email Routing servers: 13 route1.mx.cloudflare.net., 20 route2.mx.cloudflare.net. and 63 route3.mx.cloudflare.net.. TXT returns the SPF policy v=spf1 include:_spf.mx.cloudflare.net ~all and a Google site verification token. TXT on _dmarc.zerotool.dev returns NXDOMAIN: we have not published a DMARC policy (RFC 7489 §6.1 puts it at that name). The DKIM key at cf2024-1._domainkey.zerotool.dev is 420 characters long, so it is stored as two strings, one of exactly 255 characters (RFC 1035 §3.3 limits each string to 255).

DNSSEC, signed and unsigned. example.com type A returns two addresses and the pill DNSSEC ✓. zerotool.dev returns two addresses and no DNSSEC, because the zone is not signed. The tool sends do=1 with every query. Without it, Cloudflare’s AD flag varies. On 2026-09-30 we sent each query 30 times without do=1: example.com A, AAAA and NS came back "AD": false every time, and MX came back true every time. An earlier run of 20 example.com A queries gave 10 true and 10 false. With do=1, and from Google either way, every answer had true. RFC 6840 §5.8 says a resolver should set AD only when the query sets the DO or AD bit, so send do=1 whenever you need a reliable answer. With do=1 the answer also carries RRSIG signatures; the Records view hides them and Raw and JSON show them.

A broken zone. dnssec-failed.org is the failure example in Google’s JSON API documentation. Both resolvers return SERVFAIL, and the DNSSEC pill reads DNSSEC failed. Under the records, Cloudflare’s note reads EDE(9): DNSKEY Missing no SEP matching the DS found for dnssec-failed.org.. Google sends a sentence with links to DNSViz and Verisign’s DNSSEC Debugger, plus a structured extended_dns_errors entry with code 9, which the tool shows as EDE(9): No DNSKEY matches DS RRs of dnssec-failed.org. Code 9 is “DNSKEY Missing” in RFC 8914 §4.10.

Cloudflare or Google: Why Answers Differ

Both resolvers serve the same JSON format over HTTPS (Cloudflare, Google). The JSON profile is not an RFC; the binary DNS-over-HTTPS format is RFC 8484. Comparing them with the dropdown shows three differences:

  • Location. Google sends part of your IP address to authoritative servers (EDNS Client Subnet); Cloudflare does not. A CDN can therefore give each resolver a different address, and Google’s answer depends on where the query comes from. Google’s JSON API lets you set that subnet with the edns_client_subnet parameter (this page does not send it). On 2026-09-30, www.qq.com returned 121.14.77.201 and 121.14.77.221 for 114.114.114.0/24, 43.159.109.55 for 8.8.8.0/24, and 43.168.224.173 for 139.130.4.0/24. Cloudflare ignored the same parameter and returned 43.159.109.55.
  • TXT format. Cloudflare quotes each string and separates strings with a space; Google returns one unquoted string (see the FAQ).
  • Notes. On an answered query that was not cached, Google adds Response from <IP>, naming the authoritative server it asked. When validation fails, Google sends a sentence of explanation and an extended_dns_errors field instead, and Cloudflare lists Extended DNS Errors in Comment. The tool shows all of these as resolver notes and writes Google’s errors in Cloudflare’s EDE(n): text form.

How It Compares with dig and Web Lookup Sites

dig and nslookup ask the resolver your computer uses. When a VPN or proxy app answers port 53 itself, they show that app’s answer: on a test machine running a proxy in fake-IP mode, dig @1.1.1.1 dnssec-failed.org printed NOERROR with 198.18.2.147. That address comes from 198.18.0.0/15, a block reserved for benchmark tests (RFC 6890) that proxies such as mihomo use as their default fake-IP range. This page uses HTTPS to reach the resolver, so it showed the real SERVFAIL. On a server, in scripts, or when you must ask one authoritative server (dig @ns1.example.com), use dig.

Google Admin Toolbox Dig sends your query to its own backend (/apps/dig/lookup). For dnssec-failed.org its main view says “Record not found!”, and only the raw view shows rcode SERVFAIL. Its flags line for example.com reads QR RD RA, with no AD flag. DNS Checker queries “a selected list of DNS servers in multiple regions worldwide” from its servers, which is what you want for propagation checks.

This page is for the question in between: what does a major public resolver answer right now, is it DNSSEC-validated, and what exactly did it send back. To check what a web server returns once the name resolves, use the HTTP Header Analyzer; to read the certificate it serves, use the SSL Certificate Decoder.

Limits

  • Two resolvers. Only Cloudflare and Google. You cannot enter your own DoH endpoint or an authoritative server.
  • One vantage point per resolver. There is no propagation map; for that, use a multi-region checker.
  • Time limit. Each query is cancelled after 5 seconds. If a resolver is blocked on your network, the page shows a network error; switch to the other resolver.
  • Types. ALL covers eight types. PTR and SRV need their own queries, and PTR needs the in-addr.arpa name typed in. Types outside the dropdown (DS, DNSKEY, HTTPS, TLSA) cannot be queried, though RRSIG and NSEC lines appear in Raw when the resolver sends them.
  • Input. At least two labels; letters, digits, hyphens and underscores, up to 63 characters per label and 253 in total; a label cannot start or end with a hyphen. localhost or a bare com are rejected. The error names the reason: exa mple.com gives " " (U+0020) at character 4 is not allowed in a domain, and -foo.com gives Label 1 "-foo" starts with a hyphen. A host ending in a number, such as https://example.123/, is read as an IPv4 address and rejected with that reason; a port above 65535 or a dns:// prefix gets its own message too.

FAQ

Does ZeroTool see the domains I look up?

No. Your browser sends each query straight to cloudflare-dns.com or dns.google, whichever you pick, and that resolver sees your IP address and the name. There is no ZeroTool server in between. The page loads Google Analytics and AdSense like the rest of the site; the usage event it sends holds only the tool name and the action (lookup or copy_json), not the domain.

Why does a signed domain show "no DNSSEC"?

The pill shows the AD (Authenticated Data) flag of the response. It is set only when every record in the answer was validated. A CNAME that leads into an unsigned zone clears it, even when the first name is signed. If validation fails outright, the resolver returns SERVFAIL instead of an answer. When that SERVFAIL carries a DNSSEC Extended DNS Error (codes 1, 2 and 5 to 12 in RFC 8914), the pill reads "DNSSEC failed" and the resolver note under the records says why. For any other SERVFAIL the pill is hidden: the resolver sent no answer, so the flag says nothing about signing.

Why does the same TXT record look different with Google and Cloudflare?

Each string inside a TXT record holds at most 255 bytes, so long DKIM keys are stored as two or more strings. Cloudflare returns them quoted and separated by a space, as dig prints them. Google joins them into one unquoted string. Both are the same record; remove the quote-space-quote joins from the Cloudflare form to get Google's.

How do I look up DMARC, DKIM or SRV records?

Type the full owner name and pick the type. DMARC lives at _dmarc.example.com (TXT), a DKIM key at selector._domainkey.example.com (TXT), and SRV records at names such as _xmpp-server._tcp.jabber.org. Names with underscores are accepted.

How do I do a reverse (PTR) lookup?

Reverse the IPv4 address, add .in-addr.arpa, and pick PTR. For 1.1.1.1 enter 1.1.1.1.in-addr.arpa; Cloudflare answers one.one.one.one. The tool does not build the name from an IP address for you.