Skip to content

DNS Lookup

Look up DNS records by type, including reverse (PTR) lookups for IP addresses.

Runs on the XGM server. Nothing is stored.

A domain, a hostname, or an IP address for a reverse (PTR) lookup. Press Enter to run. Try , , .

About this tool

DNS Lookup asks the public DNS for one record type, or for the common ones at once (A, AAAA, CNAME, MX, NS, TXT), and shows every answer with its TTL in dig format. Enter an IP address instead of a name and it becomes a reverse (PTR) lookup. The same question also goes to seven public resolvers, so you can see whether a change has propagated and whether DNSSEC validation succeeded. It does not change records, read zone transfers or see anything your name servers do not publish.

The name you enter is sent to the XGM API and resolved from the XGM server (2 seconds per query, 4 seconds in total); with an IP address the query becomes a PTR lookup in the in-addr.arpa or ip6.arpa zone. The same question then goes to seven public resolvers - Cloudflare 1.1.1.1, Google 8.8.8.8, Quad9 9.9.9.9, OpenDNS, AdGuard, Level3 and Yandex - so those operators see the name you looked up, and their AD flag is what the DNSSEC column reports. Only public DNS data is read: no zone transfer, no change to any record, and the name you checked is not stored with the result.

How to use it

  1. Open the DNS Lookup tool.
  2. Enter the public domain, hostname or IP address you want to check.
  3. Run the check; XGM queries it from its server and lists the findings.
  4. Copy the output only after checking it looks correct.
  5. Use related XGM tools if you need a broader diagnostic view.

FAQ

What is the difference between an empty answer and a name that does not exist?

NXDOMAIN means no name server knows the name at all, usually a typo or a zone that is not delegated. NODATA - shown here as “No records” - means the name exists but has no record of that type, which is normal for, say, an AAAA query on an IPv4-only host.

Why do the resolvers disagree with each other?

Each resolver serves the answer it cached until the TTL expires, so right after a change some still return the old value. The propagation table shows the TTL each resolver reports; wait for the largest one and check again before assuming something is broken.

What does the DNSSEC column tell me?

Cloudflare, Google and Quad9 validate DNSSEC and set the AD flag when the signatures check out, which is what “validated” means here. “Failed” means those resolvers returned SERVFAIL while a non-validating server answered, the classic signature of a broken signature or an unpublished DS record (RFC 4035).

Why does a reverse lookup return nothing for my server?

PTR records live in the in-addr.arpa or ip6.arpa zone, which belongs to whoever owns the IP address, not to you. Only the network operator or hosting provider can publish or change them, so the request usually goes through their control panel or support.

Can I see who is queried and copy the equivalent command?

Yes. Every result includes the matching dig command, including +dnssec, so you can reproduce it on your own machine, and the propagation table names each resolver with its IP address and answer time.

Read the full DNS Lookup guide

Further reading