Skip to content
EnterraHost
Products
Tools
Hosting Email Support Client Area Find a domain
Easy utilities

DNS lookup

Ask four public resolvers in each of five regions what a domain resolves to, and read every answer side by side. Propagation is the question a single lookup cannot answer.

Public domains and addresses only. Each region queries four resolvers, so a lookup over all five is twenty answers to compare.

Reading the result

A lookup asks a cache, not the zone.

A resolver answers from what it already holds. It asks your authoritative nameservers only when the record it holds has expired, so the answer you get from one region says as much about that resolver's cache as it does about your zone.

That is why the tool asks twenty resolvers rather than one. The authoritative servers are the source of truth, and every public resolver between them and your visitor is a copy that may be a few minutes or a few hours out of date. Comparing the copies is the only way to see how far a change has spread.

TTL is a ceiling

A resolver may keep an answer for less than its TTL and rarely keeps it for longer. The lowest TTL in the result is therefore the number that bounds how long a stale answer can survive anywhere we can see.

Distance does not decide it

A resolver in Sydney is not more likely to hold the old record than one in Frankfurt. What decides it is when that resolver last asked, which is why the regions disagree in patches rather than in order.

Record types

Eight types, eight questions.

The type you choose decides what a resolver looks for. Asking for the wrong one returns an empty answer that reads like a broken domain rather than a mismatched question.

The record types this tool can look up, and what each one answers
TypeThe question it answers
AThe IPv4 address a name points to
AAAAThe IPv6 address a name points to
MXWhich server accepts mail for the domain, and in what order
TXTText attached to a name, which is what SPF, DMARC and most domain verification use
NSWhich nameservers are authoritative for the zone
CNAMEWhich other name this one is an alias for
SOAZone details, including the serial a secondary server uses to decide it is out of date
PTRWhich hostname an IP address points back to

Mail records are the ones worth running twice. An MX change that has reached Google's resolver and not Quad9's means some mail is being delivered to the old host, and no amount of refreshing a browser will show you that.

Questions

What the lookup can and cannot tell you.

Why do two resolvers give different answers for the same domain?
Because they cache. A resolver holds an answer until its TTL runs out rather than asking the authoritative server every time, so a resolver that has just answered a request holds the old value while one that has not asks afresh. Straight after a change it is normal for part of the internet to have the new record and the rest to still serve the old one.
How long does a DNS change take to appear everywhere?
The TTL you set is the ceiling, not the schedule. Caching resolvers may keep a record for less than its TTL, so most of the world usually picks a change up sooner than the number suggests. The lowest TTL in the result is the one that bounds how long a stale answer can survive.
What does the consensus check actually measure?
Whether every resolver that answered returned the same set of records. It does not measure whether those records are the ones you wanted, because no lookup tool can know your intent. When the sets differ, the per region view names the resolver that is out of step.
Why does a lookup return no answers for a hostname that works?
Usually because the record type is wrong for the name. A nameserver has NS records and rarely an A record, a mail host answers on MX, and a TXT record used for verification belongs to the exact name you were given rather than to the bare domain. Asking the wrong type returns an empty answer that looks like a failure and is not one.
Can this tool look up records for a private name?
No, and the refusal is deliberate. A name that only resolves inside your own network is answered by a resolver we cannot reach, and the public resolvers would return nothing. Private and reserved addresses are refused for the same reason, so the tool cannot be turned into a way of probing a network from the outside.

Next

Once the record is right everywhere.

A record that has propagated is the start of the question rather than the end of it. The next step is usually to check what the server at the other end actually answers.