DNS Lookup and Resolver Comparison

Ask for a record type and the query goes to four public resolvers at once. The answers are laid out next to each other, followed by a value-by-value table that shows which resolvers returned which record, so a disagreement is visible at a glance instead of being hidden behind one resolver's opinion. Each answer keeps its TTL, and every resolver reports whether it was able to validate the name with DNSSEC. When the resolvers disagree, the page does not guess: it lists exactly what differs and gives the two explanations that cover almost every real case, then tells you how to tell them apart.
Ready. No query has been sent yet.
Enter a name, pick a record type, then resolve.
Record types. A maps a name to an IPv4 address, AAAA to an IPv6 address. CNAME says the name is another name, and resolvers follow the chain to the end. MX lists the mail servers, each with a priority number where the lowest number is tried first. TXT holds free text and is where mail policies live: an SPF policy starts with v=spf1, a DKIM key sits under a selector name ending in ._domainkey, and a DMARC policy sits at _dmarc in front of the domain. NS lists the name servers responsible for a zone, SOA is the zone's own header record and contains the negative answer cache time. SRV locates a service at a host and port, CAA says which certificate authorities may issue certificates for the name, PTR is the reverse direction from an address back to a name, and TLSA pins a certificate for one service. DS and DNSKEY carry the keys that make DNSSEC validation possible, and HTTPS and SVCB describe how to reach a service, including the parameters for newer protocols.

Response codes. NOERROR with no records means the name exists but has nothing of the type you asked for. NXDOMAIN means the name does not exist at all, and that answer is cached for a while, so a name that was created a minute ago can still show as missing. SERVFAIL means the resolver could not finish the job, and a broken DNSSEC signature is one of the most common reasons. REFUSED means the resolver declined to answer that query.

TTL. The TTL is the number of seconds a resolver may keep the record. It is the reason two resolvers can legitimately show different answers for a while: one still holds the old copy until its timer runs out. This is also why the first thing to check after a change is whether every resolver has caught up, not whether one of them is wrong.

DNSSEC, in one paragraph. A resolver that reports the authenticated data flag says it was able to verify the answer with cryptographic signatures starting from the domain's own key. A missing flag does not prove tampering: the zone may simply not be signed, or the resolver may not validate at all. A resolver that reports a failure at the same time as the others return records is the interesting case, because a failing signature is exactly what a forged answer looks like.

Answers that look wrong but are not. Large sites, content networks and anything with location-aware DNS deliberately hand out different addresses to different resolvers, so disagreement is normal there and is not a sign of anything bad. An address like 0.0.0.0, :: or a private address in an A or AAAA answer is usually a deliberate block by whoever runs the resolver, not a hijack on the wire, but it does mean the resolver changed the answer. This page shows you the difference and the reasoning, and never tells you which one is the real answer.