Enter a domain or IP address, pick a resolver and record type, then press Look up.
Related tools
- DNS PropagationCompare live DNS answers from Cloudflare, Google, and dns.sb side by side.
- DMARC Report ViewerDrop a DMARC aggregate report and see who is sending as your domain.
- Email Header AnalyzerSPF, DKIM and DMARC verdicts plus a hop-by-hop delay waterfall from raw email headers.
- Subnet CalculatorCIDR math, address ranges, splitting, and supernetting for IPv4 and IPv6.
- HTTP Header InspectorSee exactly which HTTP request headers your browser sends, with a plain English explanation for User-Agent, Sec-CH-UA, and more.
- WebRTC DebuggerParse ICE candidates from SDP or JSON, classify each address, and interpret STUN and TURN reachability results.
What it does
Queries a single DNS record over DNS-over-HTTPS at a resolver you pick: Cloudflare, Google, or dns.sb. It covers A, AAAA, CNAME, MX, TXT, NS, SOA, SRV, CAA, and PTR, and it reads the DNS status code so an NXDOMAIN or SERVFAIL shows up as plain English instead of a bare number. Paste an IPv4 or IPv6 address instead of a domain and it automatically builds the in-addr.arpa or ip6.arpa reverse name and runs a PTR lookup, whatever record type is selected.
How to use it
Type a domain name or IP address, pick a resolver and a record type, and the page fires the DoH request from your browser and shows the request URL it uses. You can also paste a JSON DoH response you already captured, such as one saved from another tool or from curl, and it renders each answer with its name, type, TTL, and data, plus the status code explained.
Why this one
Most online DNS lookup tools proxy the query through their own server first, so they see every domain you check and often wrap the answer in ads or a signup wall. This one builds the request and lets your browser send it straight to the resolver you chose, so there is no middleman logging your lookups, no account, and no daily limit beyond what the public resolver itself applies. It is honest about the tradeoff: the resolver you pick does see the domain or address you look up, because that is what a DNS query is.
FAQ
- Who sees my lookups?
- Whichever resolver you pick, Cloudflare, Google, or dns.sb, and nobody else. The query goes from your browser straight to that resolver over DNS-over-HTTPS, the same way it would if you had set it as your system resolver. Nothing is sent to this site's server, and no lookup history is stored.
- How does the reverse lookup work?
- Paste an IPv4 address like 192.0.2.1 or an IPv6 address like 2001:db8::1 and the tool detects it, builds the standard reverse name (1.2.0.192.in-addr.arpa for IPv4, the expanded nibble form under ip6.arpa for IPv6), and queries PTR at that name regardless of which record type is selected, noting that it did so.
- What do NXDOMAIN and SERVFAIL mean?
- NOERROR means the query succeeded. NXDOMAIN means the domain does not exist at all. SERVFAIL means the resolver itself failed to answer, often because of a broken or unsigned DNSSEC chain. REFUSED means the resolver declined to answer the query. The tool spells these out next to the code so you don't have to look them up.
Keyboard shortcuts: press ? anywhere on this page to see them.