Ask for a record type and the query goes to four public resolvers at once. The answers are laid out next to
each other, followed by a value-by-value table that shows which resolvers returned which record, so a
disagreement is visible at a glance instead of being hidden behind one resolver's opinion. Each answer keeps its
TTL, and every resolver reports whether it was able to validate the name with DNSSEC. When the resolvers disagree,
the page does not guess: it lists exactly what differs and gives the two explanations that cover almost every
real case, then tells you how to tell them apart.
Name to resolve
Comparison
Ready. No query has been sent yet.
Enter a name, pick a record type, then resolve.
Record types, response codes and the answers that look wrong but are not
Record types.A maps a name to an IPv4 address, AAAA to an IPv6 address.
CNAME says the name is another name, and resolvers follow the chain to the end.
MX lists the mail servers, each with a priority number where the lowest number is tried first.
TXT holds free text and is where mail policies live: an SPF policy starts with
v=spf1, a DKIM key sits under a selector name ending in ._domainkey, and a
DMARC policy sits at _dmarc in front of the domain. NS lists the name servers
responsible for a zone, SOA is the zone's own header record and contains the negative answer
cache time. SRV locates a service at a host and port, CAA says which certificate
authorities may issue certificates for the name, PTR is the reverse direction from an address
back to a name, and TLSA pins a certificate for one service. DS and
DNSKEY carry the keys that make DNSSEC validation possible, and HTTPS and
SVCB describe how to reach a service, including the parameters for newer protocols.
Response codes.NOERROR with no records means the name exists but has nothing
of the type you asked for. NXDOMAIN means the name does not exist at all, and that answer is
cached for a while, so a name that was created a minute ago can still show as missing.
SERVFAIL means the resolver could not finish the job, and a broken DNSSEC signature is one of the
most common reasons. REFUSED means the resolver declined to answer that query.
TTL. The TTL is the number of seconds a resolver may keep the record. It is the reason two
resolvers can legitimately show different answers for a while: one still holds the old copy until its timer
runs out. This is also why the first thing to check after a change is whether every resolver has caught up, not
whether one of them is wrong.
DNSSEC, in one paragraph. A resolver that reports the authenticated data flag says it was able
to verify the answer with cryptographic signatures starting from the domain's own key. A missing flag does not
prove tampering: the zone may simply not be signed, or the resolver may not validate at all. A resolver that
reports a failure at the same time as the others return records is the interesting case, because a failing
signature is exactly what a forged answer looks like.
Answers that look wrong but are not. Large sites, content networks and anything with
location-aware DNS deliberately hand out different addresses to different resolvers, so disagreement is normal
there and is not a sign of anything bad. An address like 0.0.0.0, :: or a private
address in an A or AAAA answer is usually a deliberate block by whoever runs the resolver, not a hijack on the
wire, but it does mean the resolver changed the answer. This page shows you the difference and the reasoning,
and never tells you which one is the real answer.
🔷 Network & Security Tools
Network, DNS and web reference utilities running entirely in your browser.