Loading

Running checks, please wait...

QuantaRock Systems Visit Shop

DNS Checker

Looks up a domain's address records, mail exchangers and DNSSEC status over DNS-over-HTTPS, showing what public resolvers currently return for it.

The records this checks

A records map a name to an IPv4 address and AAAA records map it to IPv6. A domain can have several of each, which is how round-robin load balancing and most CDNs work -- seeing more than one address is normal, not a fault.

MX records name the servers that accept mail for the domain, each with a preference number where lower means higher priority. DNSKEY records indicate whether DNSSEC is configured.

What DNSSEC actually provides

DNSSEC signs DNS responses cryptographically so a resolver can verify that an answer came from the real zone and was not altered in transit. Without it, DNS answers are unauthenticated and can be forged by anyone positioned to intercept the query.

It does not encrypt anything. Observers still see which domains you look up; DNSSEC only guarantees the answer is genuine. It is also not universally deployed, and its absence is common rather than alarming -- but for a domain handling payments or authentication it is worth having.

Why answers here may differ from your machine

This tool queries public resolvers over DNS-over-HTTPS rather than whatever resolver your computer uses. Results can legitimately differ.

Split-horizon DNS returns different answers inside a corporate network than outside it. Geo-aware providers answer based on where the query appears to come from. And caching means a recently changed record may have expired from one resolver but not another -- the DNS Propagation Checker is built specifically for that case.

Common problems this surfaces

No address records at all usually means a typo in the domain, an expired registration, or a zone that was never published. If nameservers are set but no records exist beneath them, the zone was probably created and never populated.

Records that resolve to an address you no longer control are a genuine risk. Dangling DNS entries pointing at released cloud IPs can be claimed by whoever gets that address next, which is a well-established subdomain takeover route.

Frequently asked questions

How long do DNS changes take to appear?

As long as the record's TTL, which is set by whoever manages the zone and commonly ranges from five minutes to 24 hours. Resolvers may keep a cached answer for that period regardless of what the zone now says.

Why does this need a domain rather than an IP?

These records are published under domain names. For an address, the equivalent lookup is reverse DNS (PTR), which the Full Report includes when given an IP.

Is more than one A record a problem?

No, it is normal. Multiple addresses distribute traffic across servers, and clients pick among them. Most large sites return several.

What does the DNSSEC AD flag mean?

AD stands for authenticated data. It means the resolver validated the signature chain successfully, so the answer is verified rather than merely present.

Your feedback matters

Help businesses choose infrastructure with confidence.

Share your QuantaRock experience on Trustpilot.

Review us on Trustpilot