DNS Lookup Tool

Check all DNS records for any domain instantly — A, AAAA, MX, TXT, CNAME, NS and SOA. Results are fetched directly from authoritative nameservers in real time. Free, no sign-up required.

Enter any domain or hostname to retrieve all its DNS records instantly.
Results for  amazon.com 70 records found
98.82.161.185 IPv4 98.87.170.71 IPv4 98.87.170.74 IPv4
A Record 3 MX Record 1 NS Record 4 TXT Record 61 SOA Record 1
A Record IPv4 address 3
98.87.170.74
TTL 158s
98.82.161.185
TTL 158s
98.87.170.71
TTL 158s
MX Record Mail server 1
amazon-smtp.amazon.com (priority 5)
TTL 900s
NS Record Nameserver 4
ns-521.awsdns-01.net
TTL 6,889s
ns-1707.awsdns-21.co.uk
TTL 6,889s
ns-1447.awsdns-52.org
TTL 6,889s
ns-264.awsdns-33.com
TTL 6,889s
TXT Record Text / SPF / DKIM 61
pendo-domain-verification=ecbe1a51-954d-4202-ab86-d15e04b96769
TTL 86s
ZOOM_verify_ARI4AiKALCcjulAUZNwR8S
TTL 86s
sending_domain608861=d33a88e8540c33a1217138cf8a25879734bd35673bb7cfbd639f95c550b33ec4
TTL 86s
sending_domain608861=81b0d52095dae60d604e7cbea5e58e1d842f7d950d6673a43feae339b664ca31
TTL 86s
vizcom-domain-verification-Otrns5=NtkDXOBddZZnm9ETuwyrltTdl
TTL 86s
stripe-verification=76924B623B7105057C67D4F5EAE19F65EE8BD92635581BCACA2CCACA4D38FE1B
TTL 86s
canva-site-verification=Hksh9WEUPWP13_SEU1mPMA
TTL 86s
stripe-verification=a5c01aa4d732f4b93154d67983d77982ef1a2db73fecfd4bcd64e224d3ab4075
TTL 86s
uber-domain-verification=7a35217f-6956-41a0-be5c-a28ea2646964
TTL 86s
uber-domain-verification=0ddb4c64-175c-4e7a-8a7a-f552034222e8
TTL 86s
docker-verification=1779f74e-699a-4d8b-acdc-ce242d73559f
TTL 86s
stripe-verification=26EFABF97D624D7F4F3C062366A04C4B1399841F23F275DD81E58D00A981979C
TTL 86s
autodesk-domain-verification=dmryiygGOGBJFJFVo5Bl
TTL 86s
v=spf1 include:spf1.amazon.com include:spf2.amazon.com include:amazonses.com -all
TTL 86s
apple-domain-verification=4wbNaeWvAH0pU1yi
TTL 86s
sending_domain197572=555e96ed2e576ced81c89f7001740cb72f9c66aeb136d0d05734aad625766bc1
TTL 86s
TS1760027
TTL 86s
canva-site-verification=WhUvTbfe6tUQWmIXnQifGA
TTL 86s
google-site-verification=14WGW2MdNMxchG8PlinF7LgqqE0OwwHqOq0HKhb7rDQ
TTL 86s
dell-technologies-domain-verification=amazon.com_2dc4b285-482d-4948-bf92-16e698f2cab9_1738858526
TTL 86s
apple-domain-verification=dVkKZnu17XS0EN2X
TTL 86s
google-site-verification=NV91qEfNgqDZOPzwlhXE-KtDUfCBSNgAsdxaFebyh80
TTL 86s
pstk-verification-a938892542ffacd51af9339e4755dc1a
TTL 86s
neat-pulse-domain-verification-QgvLWLN=f37f2998-0bb3-493b-a3aa-c4ff8f3dce08
TTL 86s
sending_domain1003771=199bc63a54ace5d8d5c5d08286af86d7049b4afacb5ef7decd6b22cf9e8d5efb
TTL 86s
uber-domain-verification=01e9f567-7b84-45dd-9326-53992a028b40
TTL 86s
stripe-verification=35A865E5A20C09CD0288F87ACA29DE73FF8A704D21F7310A5AAFF4CB63062E81
TTL 86s
ZZQHY11TNIE58IL4LBKKT51FQ59LYM243WZU3MJM5OLQMLVBN0TR564SD8SXZU2G
TTL 86s
uber-domain-verification=5f5cc242-4dbe-4871-b726-bbbe085ff053
TTL 86s
box-domain-verification=ffea95cd0e0d61c302198367155b07e74fd534fa1d867662dc9bf9969b6f535d
TTL 86s
MS=4B600B22799EB2CAC0D8FF0A3A3CAECA5EE2BF3A
TTL 86s
cisco-ci-domain-verification=1b256bd11daa486ba2fa405d2d5de70f75feb6757dd8993ca8de685a7dfea1df
TTL 86s
stripe-verification=a27edc0da55836ea6bb7eac592bf2ca8e246eb652608d54493119df7df005afc
TTL 86s
stripe-verification=65883709F0B36AB2B73FFC870338AE9F817315DDBB1CAB28910F074F4A8DE1EC
TTL 86s
pardot326621=b26a7b44d7c73d119ef9dfd1a24d93c77d583ac50ba4ecedd899a9134734403b
TTL 86s
liveramp-site-verification=jZJKgMEQ_1mdjMhKj02iqNACZ-NJHRWhCEQdQ_OuCMo
TTL 86s
sending_domain229492=341509a116ea4311fcb2e489303bf09a139b10ce9b90e5029d2677055cb4dc89
TTL 86s
google-site-verification=D0RwRb_QApkpApKTFaFlRwbm_yrkey0uokKw0wQUIdk
TTL 86s
stripe-verification=B0AD8DC1918B8A717E5B6A29C2E04594A9872AB05F8DA24CB762BBA0A0487BC6
TTL 86s
stripe-verification=6a5d107aa37465eac2101bb1c725b02072689a4fa7bd38b455970baac4979a17
TTL 86s
ZOOM_verify_6OUC1znUonKMCoyMMGyFfX
TTL 86s
stripe-verification=79C640ED20153B836A623F16A3DCF65E2072948FB80C42D19300514DADF94EC5
TTL 86s
google-site-verification=G_-mXb0ZYjjGkQVGjpOOB2deSOaVdxVj4i4vozJTREs
TTL 86s
facebook-domain-verification=d9u57u52gylohx845ogo1axzpywpmq
TTL 86s
sending_domain949422=43d714838567583460e7720e6049505edb8e25c1ef4321419d41bc5255db7ba5
TTL 86s
wrike-verification=MzI3NzM2ODo2NDk5MjE4NjQ2MWJmOTEwMGMxM2MzNzJmNWJlY2U5ZDU4MmVlNzQ2NWU4MTY5OWJjMjlmYjQ4Mjc5M2JiMzky
TTL 86s
spf2.0/pra include:spf1.amazon.com include:spf2.amazon.com include:amazonses.com -all
TTL 86s
sending_domain229492=7cde83fbc5246557c64d9d9ba79f0d11f7ba9eb6127f60451a9aa6f8dead4381
TTL 86s
00DcX000002xu6h=1TBcX00000000Xt
TTL 86s
uber-domain-verification=72ffdffb-d431-452c-932e-cd1030d1eb46
TTL 86s
sending_domain1003771=f1303d8ee3b86e39db2703b11feb83e1e8b712a9ffc64c3d56505192e5b3bf4f
TTL 86s
stripe-verification=8E217BE0FF12B50596BD78EEA3F81E62C6C7A2AC78FBD46DAD95B7D21BA2F8BF
TTL 86s
stripe-verification=1D421397AAEC571CCBD9F25DDC90F00EDEBC3E74F4047270EC9A13B784579E34
TTL 86s
stripe-verification=C7ABA7B41F5AC26E3C397015A34CD46ACD2130DC8DAAFA7F59AAEFEDBC3FA517
TTL 86s
apple-domain-verification=_j3fIZD8uuYetbG64YKTEpz-8mwyvYrLRqM5CoVZVTk
TTL 86s
sending_domain1014172=003846595520e80ec84e8cc47c07e3a71afb855fc743bb92cdec93f88c7a4029
TTL 86s
atlassian-domain-verification=ZT4AapXgobCpXIWoNcd7gtMjZyOUdr4EDFMnFUWrqqqgdaQVbDvoGpRaIwj/tgPH
TTL 86s
sending_domain949422=99a7b44052aefc4dec2abf56189160824664d2fdac00ca962f4455be62b51d56
TTL 86s
brevo-code:9be7f7c39958d253a31de6593fa831bc
TTL 86s
lucidlink-verification=QG752KJ3CMZAZTZ3ERMX1AXMCG
TTL 86s
stripe-verification=45f746e3b195198f419af3f685fdf217532ce552b4b47070b3caefe325559a67
TTL 86s
SOA Record Start of authority 1
mname: dns-external-route53.us-east-1.amazonaws.com | rname: root.amazon.com | serial: 201
TTL 7,200s
Not stored or logged
Real-time lookup
No sign-up needed

What This Tool Does

This tool queries the authoritative nameservers for any domain you enter and returns every publicly available DNS record type in real time — A, AAAA, MX, CNAME, NS, TXT and SOA. Results are never cached on Convixy's side: every lookup reflects the live state of the domain's DNS configuration at the moment you run it. IP addresses resolved from A and AAAA records appear as clickable pills that link directly to the IP Lookup tool for instant geolocation and network details.

Address Records (A & AAAA)

IPv4 and IPv6 addresses the domain resolves to, with TTL shown for every record.

Mail Records (MX)

All mail servers configured for the domain, with priority values that determine delivery order.

Text Records (TXT)

SPF, DKIM, DMARC and domain verification tokens used for email authentication and service ownership proof.

Authority Records (NS & SOA)

The nameservers responsible for the zone and the SOA metadata governing caching and zone transfers.

Understanding DNS Record Types

DNS is a hierarchical distributed database, and each record type has a precise, distinct function. Knowing what each one controls lets you diagnose problems faster and make changes with confidence.

A and AAAA records are the most fundamental — they map your hostname to an IP address so browsers know where to connect. MX records control where email for your domain is delivered; multiple MX entries with different priority values provide redundancy so a backup server handles mail if the primary is unreachable. CNAME records create hostname aliases, letting www.example.com point to a CDN or SaaS hostname without manually tracking IP addresses. NS records delegate authority for the zone to specific nameservers — changing these transfers DNS control from one provider to another. TXT records hold free-form text used for SPF email sender authorisation, DKIM public keys, DMARC policies, and domain ownership verification by third-party services. The SOA record is the administrative record for the entire zone, containing the primary nameserver, a contact address, a serial number that increments on every change, and timing parameters that govern how secondary nameservers synchronise.

Practical DNS Diagnostics

Frequently Asked Questions

What is DNS and how does a lookup actually work?

DNS (Domain Name System) is the distributed global directory that translates domain names into the IP addresses computers use to communicate. When you type a domain into a browser, your device sends a query to a recursive resolver. If the resolver has the answer cached it replies immediately; if not, it works up through the DNS hierarchy — querying root servers, then TLD servers (e.g. .com), then the domain's authoritative nameservers — to get the definitive answer.

This tool queries the authoritative nameservers directly, bypassing any intermediate cache, so results always reflect the current published state of the domain's DNS configuration regardless of whether any particular resolver has caught up with recent changes. Every lookup is a fresh query with no caching on Convixy's side.

What do the different DNS record types mean?

A records map a hostname to an IPv4 address — the most fundamental record type. AAAA records do the same for IPv6. MX records specify which mail servers accept email for the domain, with priority numbers that determine delivery order. CNAME records create an alias from one hostname to another — useful for pointing subdomains to CDNs or hosted services without tracking IPs manually.

NS records identify the authoritative nameservers for the domain — changing these transfers DNS authority from one provider to another and is the most impactful DNS change you can make. TXT records hold free-form text used for SPF, DKIM, DMARC and domain ownership verification. The SOA record is the administrative record for the entire DNS zone, containing the primary nameserver, an encoded contact address, a serial number, and timing parameters for zone synchronisation.

What is TTL and how does it affect DNS changes?

TTL (Time To Live) is the number of seconds that resolvers and browsers are permitted to cache a DNS record before re-querying the authoritative server for a fresh answer. A record with a TTL of 86400 can be cached for 24 hours; one with a TTL of 300 expires after 5 minutes. The TTL value is shown for every record in the results above.

Before any server migration or DNS cut-over, lower the TTL on the affected records to 300 seconds at least 24–48 hours in advance. This ensures that once you make the change, the old cached records expire and resolvers worldwide pick up the new address within minutes rather than hours. After the change is confirmed working and stable, raise the TTL back to a higher value (typically 3600 or 86400) to restore caching performance and reduce DNS query load.

What is DNS propagation and how long does it take?

Propagation is the time it takes for a DNS record change to spread through the global network of recursive resolvers and caches. When you update a record, the authoritative nameserver immediately serves the new value — but resolvers around the world continue serving the old cached record until its TTL expires. The commonly cited "up to 48 hours" represents the worst case when records have very high TTLs or when resolvers do not correctly honour TTL values.

In practice, most changes propagate within minutes to a few hours when TTLs have been lowered in advance. Since this tool queries authoritative nameservers directly, it shows the new record immediately after you save it — well before most resolvers have updated their caches. If you see the new record here but your browser still loads the old site, flushing your local DNS cache is the fastest fix: ipconfig /flushdns on Windows or sudo dscacheutil -flushcache on macOS.

When should I use a CNAME instead of an A record?

Use an A record when you know the exact IP address of your server and it is stable — typically for your root domain (example.com) or any hostname pointing at a fixed IP. Use a CNAME when you want to alias a subdomain to another hostname, such as pointing www.example.com to a CDN or cloud platform that manages its own IP addresses. This way, if the service's IP changes, your DNS automatically follows without any manual update.

The key constraint: you cannot place a CNAME at the zone apex alongside other records — DNS rules prohibit it. Most DNS providers offer a proprietary ALIAS or ANAME record type to work around this for root domain scenarios. If you are migrating from one CDN to another, a CNAME at the subdomain level makes the transition seamless since you only update the target hostname rather than tracking IP changes.

Why are MX records important and how do I read the priority values?

MX (Mail Exchanger) records tell sending mail servers where to deliver email addressed to your domain. When multiple MX records exist, the priority number (sometimes called preference) determines which server is attempted first — lower numbers mean higher priority. If the primary server is unavailable, the sender falls back to the next lowest priority entry automatically, providing delivery redundancy without any action needed from the recipient.

Google Workspace uses aspmx.l.google.com with priority 1 as its primary entry and several backup servers at higher numbers. Microsoft 365 uses a single [tenant].mail.protection.outlook.com entry. If email delivery is failing, checking MX records here is the correct first diagnostic step — a missing, incorrect or expired MX record is one of the most common causes of complete email delivery failure for a domain.

What are TXT records used for beyond plain text?

TXT records carry free-form text data and are used for several critical operational purposes. SPF (Sender Policy Framework) declares which IP addresses and services are authorised to send email on behalf of your domain — a missing or incorrect SPF record is a leading cause of legitimate mail being marked as spam or rejected outright. DKIM (DomainKeys Identified Mail) publishes a public key used to verify cryptographic signatures on outbound email, proving the message was not altered in transit.

DMARC (Domain-based Message Authentication, Reporting and Conformance) sets the policy for handling email that fails SPF or DKIM checks — monitor only, quarantine to spam, or reject entirely — and can request aggregate reports of authentication failures from receiving mail servers. Domain ownership verification by services like Google Search Console, Cloudflare, GitHub and others also uses TXT records, typically requiring you to add a specific token value that the service checks to confirm you control the domain.

What is an SOA record and do I ever need to edit it?

The SOA (Start of Authority) record is the administrative record for a DNS zone. It contains the primary nameserver (mname), an encoded administrative contact address (rname, where the first dot replaces the @ in the email address), a serial number that must increment on every zone change, and four timing parameters: refresh interval (how often secondary nameservers check for updates), retry interval (how long to wait before retrying a failed refresh), expire time (how long a secondary can serve data without a successful refresh), and negative caching TTL.

In almost every case your DNS provider creates and manages the SOA record automatically — you never need to interact with it directly when using hosted DNS services like Cloudflare, Route 53 or Namecheap. You only need to edit the SOA manually if you operate your own authoritative nameserver software such as BIND or PowerDNS. The serial number is particularly important when running your own server: failing to increment it on zone changes means secondary nameservers will not fetch the updated records.

What is the difference between forward and reverse DNS?

A forward DNS lookup — which is what this tool performs — resolves a domain name into IP addresses and associated records. It answers the question "what IP does this domain point to?" A reverse DNS lookup goes in the opposite direction: it takes an IP address and returns the hostname assigned to it via a PTR record, answering "what hostname does this IP belong to?"

Reverse DNS is controlled by the organisation that owns the IP block — typically the ISP or hosting provider — rather than the domain owner. Mail servers use PTR records to verify sending IP identities as part of spam filtering, and sysadmins use them to identify unknown hosts in network traffic logs. Use Convixy's dedicated Reverse DNS tool to look up the PTR record for any IP address, or the IP Lookup tool to get full geolocation and network details for any resolved IP.

Are my DNS queries stored or logged?

No. Every lookup runs fresh when you submit the form. The domain you enter and the results returned are not written to any database, not associated with any user profile, and not shared with third parties. No account is required to use the tool, so there is nothing to log a query against. Results are fetched live from authoritative nameservers on every request with no caching on Convixy's servers.

Standard web server access logs record the URL of each request — which includes the domain you searched as a URL query parameter — for security and uptime monitoring purposes, but these logs are periodically rotated and are not used for user tracking, analytics profiling or advertising. You can look up any publicly accessible domain or hostname without creating an account or providing any personal information.