Free tool

DNS checker

Ask three public resolvers for the same record and compare their answers side by side, so you can see whether a DNS change has reached everyone.

Queried on Cloudflare (1.1.1.1), Google (8.8.8.8) and Quad9 (9.9.9.9).
Records
—

Each resolver's answer is shown side by side, with its TTL where the record type reports one.

How to read the result

The headline says whether the resolvers agree. Resolvers that timed out or returned an error are left out of that comparison, and “No records” and NXDOMAIN both count as an empty answer, so “Resolvers agree” means every resolver that gave a usable answer returned exactly the same set of records. Order does not matter.

  • AnsweredThe resolver returned records, listed under the badge. MX records show their priority first, and an SOA record shows the primary nameserver, the admin mailbox, the serial and the refresh, retry, expire and minimum TTL timers.
  • No recordsThe name exists but has no records of that type.
  • NXDOMAINThe name does not exist at all, according to that resolver.
  • Timed out or ErrorThe resolver did not answer in time, refused the query, or returned SERVFAIL. The note under the badge says which.
  • ms and TTLUnder each resolver's name: how long the lookup took and, for A and AAAA records, the TTL in seconds. A resolver reports the time left in its cache, so a TTL lower than the one you set means that copy was cached earlier and will be refreshed when it reaches zero.

Common causes and what to do next

  • Propagation after a changeOne resolver shows the new value and another the old one. Wait for the TTL shown to run out, then check again; there is nothing to fix.
  • A long TTLA TTL of hours means old answers can linger that long. Lower it ahead of planned moves and raise it again afterwards.
  • Resolver differencesGeo-DNS and DNS load balancing return different addresses by design, and a filtering resolver can block a domain the others answer for. Compare against the provider's documentation before assuming a fault.
  • NXDOMAIN everywhereThe name is misspelt, the record was never created, or the domain has lapsed or lost its nameserver delegation. Check the NS records and your registrar.
  • SERVFAILUsually a broken DNSSEC chain or unreachable nameservers. If you recently changed DNS provider, check that the DS record at your registrar matches the new provider, or remove it.

Why resolvers can disagree

Recursive resolvers cache each answer for as long as its TTL says. After you change a record, a resolver that cached the old value keeps serving it until that time runs out, so for a while different networks see different answers. Comparing several large resolvers is a quick way to see whether that window has passed.

What each record type is for

  • A and AAAAThe IPv4 and IPv6 addresses a name points to.
  • CNAMEAn alias to another name, common for CDN and SaaS custom domains.
  • MXThe mail servers for the domain, in priority order.
  • TXTFree-form text: SPF, DKIM and DMARC policies, and domain verification tokens.
  • NSThe nameservers that are authoritative for the domain.
  • SOA and CAAZone metadata (serial, refresh timers) and which certificate authorities may issue for the domain.

Frequently asked questions

How long does DNS propagation take?

As long as resolvers keep the old answer cached, which is set by the TTL of the record you changed. A record with a 300-second TTL is normally refreshed everywhere within five minutes; one with an 86,400-second TTL can take up to a day. Lowering the TTL a day before a planned change makes the switch quicker.

Why do Cloudflare, Google and Quad9 show different answers?

Each resolver caches answers separately, so after a change some still hold the old value until their cached TTL runs out. Services that use geo-DNS or load balancing at the DNS level can also return different addresses on purpose. Quad9 also blocks domains on its threat list, which can make it disagree with the others.

What is the difference between NXDOMAIN and No records?

NXDOMAIN means the name itself does not exist. No records means the name exists but has no records of the type you asked for, for example a domain with an A record but no AAAA record.

What does SERVFAIL mean?

The resolver could not get a valid answer from the domain's nameservers. It is shown here as Error with a SERVFAIL note, and usually points to a DNSSEC problem (an expired signature or a DS record that no longer matches) or nameservers that are down or misconfigured.

Need to know when a record changes?

A lookup shows today's answer. An unexpected change to an A, MX or NS record (a lapsed domain, a mistaken edit, a hijack) is an outage waiting to happen. A SutramX DNS monitor (on every plan) looks up a record on a schedule and alerts you when it changes or stops matching the values you expect. See SutramX features for the monitor types available on each plan, and the website uptime checker to test the site itself.

Catch DNS problems before your users do

SutramX checks your sites and DNS records and tells you when a record stops resolving or changes, with unlimited team seats on every plan, including Free.