DNS record lookup

DNS Lookup

Query common DNS record types and inspect each answer's value and time to live. Requests use a small same-site endpoint backed by Cloudflare DNS over HTTPS.

Live DNS query

Enter a DNS name

Choose one record type to query through Cloudflare's resolver.

Enter a name, not a full URL. Example: example.com

The requested name and type are sent to Cloudflare DNS. No account is required.

DNS response

Ready for lookup

Answer records will appear with their current TTL values.

NOT QUERIEDDNSSEC status pending

Enter a name and select Look up records.

Name + typeresolver answerTTL in seconds

Quick example

Look up the A records for example.com

An A lookup for example.com asks for its IPv4 address records. Each live answer includes the record owner, record type, IPv4 value, and TTL indicating how long a resolver may cache that answer.

Record reference

DNS record types supported by this lookup

TypeNameWhat it provides
AIPv4 addressPoints a name to an IPv4 address.
AAAAIPv6 addressPoints a name to an IPv6 address.
CNAMECanonical nameAliases one DNS name to another.
MXMail exchangeLists servers that receive email for a domain.
TXTTextCarries verification, email-policy, and other text data.
NSName serverLists authoritative name servers for a zone.
SOAStart of authorityDescribes the zone's primary authority and timers.
SRVServiceLocates a service by priority, weight, port, and target.
CAACertificate authorityControls which authorities may issue certificates.
PTRPointerMaps a reverse-DNS name back to a host name.

Reading the response

What DNS status, TTL, and DNSSEC mean

Response status

NOERROR means the resolver completed the query, even if that record type has no answers. NXDOMAIN means the requested DNS name does not exist.

Time to live

TTL is the number of seconds a recursive resolver may cache a record. Lower values allow faster changes but can cause more frequent DNS queries.

DNSSEC authentication

The authenticated-data flag indicates that the resolver validated a signed answer. An unsigned zone can return a successful result without this flag.

Aliases in an answer

An address lookup may include a CNAME before its final A or AAAA records. The result keeps each returned record type visible instead of hiding that chain.

Query privacy

What leaves your browser

The browser sends only the requested DNS name and record type to Pantry of Tools. The same-site Worker validates those fields and sends them to Cloudflare's DNS-over-HTTPS resolver. The endpoint does not return your IP address, browser headers, or unrelated request data, though standard Cloudflare infrastructure and resolver logs may still exist.

Common questions

DNS lookup FAQ

What does a DNS lookup show?

It asks for one record type attached to a DNS name and returns matching answer records with their owner, type, value, and TTL.

Why might DNS lookup results change?

DNS records can change, and cached answers expire according to their TTL. Different resolvers may briefly show different answers while changes propagate.

What does DNSSEC validated mean?

The resolver set the authenticated-data flag after validating the signed answer. No flag is not automatically an error because many zones are unsigned.

Is my DNS query private?

The requested name and type pass through a same-site endpoint to Cloudflare DNS. The tool returns only DNS data, but standard hosting and resolver logs may still exist.