Quick example
Look up the A records for example.com
An A lookup for example.com asks for its IPv4 address records. Each live answer includes the record owner, record type, IPv4 value, and TTL indicating how long a resolver may cache that answer.
Record reference
DNS record types supported by this lookup
| Type | Name | What it provides |
|---|---|---|
| A | IPv4 address | Points a name to an IPv4 address. |
| AAAA | IPv6 address | Points a name to an IPv6 address. |
| CNAME | Canonical name | Aliases one DNS name to another. |
| MX | Mail exchange | Lists servers that receive email for a domain. |
| TXT | Text | Carries verification, email-policy, and other text data. |
| NS | Name server | Lists authoritative name servers for a zone. |
| SOA | Start of authority | Describes the zone's primary authority and timers. |
| SRV | Service | Locates a service by priority, weight, port, and target. |
| CAA | Certificate authority | Controls which authorities may issue certificates. |
| PTR | Pointer | Maps a reverse-DNS name back to a host name. |
Reading the response
What DNS status, TTL, and DNSSEC mean
Response status
NOERROR means the resolver completed the query, even if that record type has no answers. NXDOMAIN means the requested DNS name does not exist.
Time to live
TTL is the number of seconds a recursive resolver may cache a record. Lower values allow faster changes but can cause more frequent DNS queries.
DNSSEC authentication
The authenticated-data flag indicates that the resolver validated a signed answer. An unsigned zone can return a successful result without this flag.
Aliases in an answer
An address lookup may include a CNAME before its final A or AAAA records. The result keeps each returned record type visible instead of hiding that chain.
Query privacy
What leaves your browser
The browser sends only the requested DNS name and record type to Pantry of Tools. The same-site Worker validates those fields and sends them to Cloudflare's DNS-over-HTTPS resolver. The endpoint does not return your IP address, browser headers, or unrelated request data, though standard Cloudflare infrastructure and resolver logs may still exist.
Common questions
DNS lookup FAQ
What does a DNS lookup show?
It asks for one record type attached to a DNS name and returns matching answer records with their owner, type, value, and TTL.
Why might DNS lookup results change?
DNS records can change, and cached answers expire according to their TTL. Different resolvers may briefly show different answers while changes propagate.
What does DNSSEC validated mean?
The resolver set the authenticated-data flag after validating the signed answer. No flag is not automatically an error because many zones are unsigned.
Is my DNS query private?
The requested name and type pass through a same-site endpoint to Cloudflare DNS. The tool returns only DNS data, but standard hosting and resolver logs may still exist.