TontonTools

DNS Records Checker

Check all DNS records for a domain — A, MX, TXT, CNAME, NS in one look.

100% Free No signup Privacy-friendly Domain & IP Tools
Updated Sep 2026

Share X / Twitter Facebook LinkedIn WhatsApp

How to use DNS Records Checker

  1. Enter the domain.
  2. Read the records by type — NS, A/AAAA, MX, TXT, CNAME.
  3. Match against intent: mail records → your mail provider's documented values; web records → your host/CDN.
  4. After edits, re-check — propagation lag means changes appear over minutes to hours.

What is DNS Records Checker?

A DNS records checker queries a domain's full public record set: A/AAAA (web servers), MX (mail delivery), TXT (verification and email policy — SPF, DKIM, DMARC), CNAME (aliases) and NS (which nameservers hold authority). One lookup, the whole configuration surface.

DNS is where websites, email and service verifications all meet — and where their failures start. "Email stopped arriving", "the www doesn't work", "the verification won't validate": each is a record visible (or missing) in this check.

About the DNS Records Checker

Enter a domain and read its records by type.

What each block tells you: NS — who controls the DNS (the first question in any handover or hijack investigation); A/AAAA — where the web traffic goes; MX — where mail is delivered (no MX = no inbound email; wrong MX after a migration = mail going to the old provider); TXT — the crowded workhorse: SPF (which servers may send your mail), DKIM keys, DMARC policy, plus site-verification tokens for Google, Microsoft and every SaaS you've proven ownership to; CNAME — aliases like www pointing at the apex or a hosting target.

The routine checks: after any DNS edit (did it save and propagate?), during email-deliverability work (SPF/DKIM/DMARC present and correct — the trio that keeps you out of spam), before/after migrations, and when a verification stalls (the token record is usually missing, typo'd, or on the wrong host).

Frequently Asked Questions

MX (where mail is delivered) plus the TXT trio: SPF (authorized senders), DKIM (signing key), DMARC (policy). Broken/missing entries in that set are behind most "our email goes to spam" cases.
Mostly verifications and email policy: SPF strings (v=spf1…), DKIM selectors, DMARC (v=DMARC1…), and ownership tokens (google-site-verification=… and peers). Old tokens are harmless residue; wrong SPF is not.
Authority — which DNS service answers for the domain. Every other record lives AT those nameservers, so pointing NS elsewhere (e.g. to Cloudflare) moves the whole configuration.
Caching — resolvers hold answers for the record's TTL. Expect minutes to hours (rarely 24-48h). If it never appears, the edit was made at a nameserver that isn't authoritative — check NS first.
No — CNAME must stand alone on a name, which is why the apex (domain.com) can't be a plain CNAME (it needs SOA/NS). Hosts work around it with ALIAS/flattening; the www subdomain takes CNAME freely.

Learn more

What Is DNS? How the Internet's Phone Book Works

Every time you visit a site, DNS quietly translates the name into an address. Here is how it works, the main record types, and how to inspect them.

Read the guide

We use cookies for analytics and to keep the tools free via ads. See our Privacy Policy.