Inspect every important DNS record type for a domain in one lookup — with typed tables, per-type partial results, and a JSON export you can share with your team.
Enter a domain and pick the record types to look up. Each type is queried separately, so a failure in one never hides the others.
We query public DNS for the domain you enter, using the resolver configured on our server. Your input is used only to run the lookup, results are not stored, and nothing is shared with third parties.
Type any public domain and optionally narrow the check to specific record types. All nine supported types are selected by default.
The server issues separate, typed DNS queries for A, AAAA, MX, TXT, NS, CNAME, CAA, SOA, and common email SRV names — so a timeout on one type never erases the answers from the others.
Browse typed tables with MX priorities and SOA fields, see TXT fragments and joined values, jump to dedicated authentication checkers, and download everything as JSON.
Validate your SPF record, follow includes, and count DNS lookups against the 10-query limit.
Open toolLook up a DKIM selector and inspect the published public key, its size, and its flags.
Open toolCheck your DMARC policy, reporting addresses, and alignment modes against RFC 9989.
Open toolVerify your MTA-STS policy and TLS reporting records for encrypted mail transport.
Open toolSee whether an IP address or domain appears on reviewed public DNS blocklists.
Open toolValidate MX, SPF, DKIM, and DMARC together in a one-click email DNS health check.
Open toolIt queries the public DNS for the domain you enter and shows the records that come back — address records (A and AAAA), mail exchangers (MX), text records (TXT), nameservers (NS), aliases (CNAME), certificate authority restrictions (CAA), the zone start record (SOA), and common email service records (SRV). Each type is queried separately, so one failed query never hides successful answers.
A single TXT record can be stored as several character-strings of at most 255 characters each. Resolvers return them as fragments, and this tool shows both the joined value — the form SPF and other authentication protocols actually read — and the individual fragments for diagnostics.
"No record" means the DNS server answered successfully but had no record of that type (NODATA), or the name does not exist at all (NXDOMAIN). A failed query means the server timed out, refused, or returned an error — the tool marks those as unknown and never treats them as missing records.
No. DNSSEC validation requires a resolver that performs authenticated-data checks, which this tool does not use, and no single lookup can measure global propagation. The results are a snapshot of what the resolver used by this server returns right now; recently changed records may still be cached elsewhere.
The number is the priority (preference). Sending servers try the lowest value first and fall back to higher values if that server is unreachable. Several records with the same priority share load between them.
Look for an SPF record (starting with v=spf1) at the domain apex, and remember that DMARC lives at _dmarc.yourdomain.com and DKIM at selector._domainkey.yourdomain.com, so they rarely appear in apex TXT results. When an authentication record shows up here, the tool links it to the dedicated SalesBlink checker for a full analysis.
Automate Sales Outreach & Get Booked!
Start Free Trial(14 Day Free Trial, No CC Required)