DNS Lookup
Query A, AAAA, MX, TXT, NS, CNAME, SOA and CAA records for any domain.
Checking for an existing session…
Enter a domain and pick a record type.
How it works
A DNS record is the answer a resolver gives for a name — where mail for a domain routes to, which server answers for it, what a TXT record claims about it. This queries Cloudflare's own DNS-over-HTTPS resolver from Quietlytic's backend and returns exactly what it says, one record type at a time.
Why this tool needs a bot check
Every other tool in this section runs entirely in your browser — nothing you type ever reaches Quietlytic. This one queries a resolver on your behalf, which is cheap per lookup but easy to script at volume. A single Turnstile solve unlocks lookups for 30 minutes in this tab, and each network tool allows a fixed number of lookups per hour from one IP address (20 for DNS), so a real investigation involving several lookups is not interrupted every time.
A private-range answer is flagged, not hidden
A public domain that resolves to an RFC 1918 address, loopback, or another non-routable range is either a misconfiguration or a DNS rebinding attempt. Either way it is worth noticing at a glance rather than reading as an ordinary public answer — so an A or AAAA record pointing into a private range is marked as such.
Example
Query MX for a domain to see where its mail routes before assuming a spoofed sender is legitimate.
Query TXT for the domain to read SPF and domain-verification records, for
_dmarc.example.com to read the DMARC policy, or for selector._domainkey.example.com to
read a DKIM key — directly, without trusting a third party's summary of them. A URL or email address pasted in is
trimmed to its domain.
Frequently asked questions
Why does this need a bot check when most tools here do not?
Because this is the first tool in the section that makes an outbound request on your behalf rather than computing something locally in your browser. A DNS resolver query is cheap for one lookup, but trivial to abuse at volume — without a gate, this endpoint would double as a free DNS-enumeration service for anyone scripting requests at it. One Turnstile solve unlocks 30 minutes of lookups in that tab; an hourly per-IP limit does the rest, so a real investigation involving several lookups in a row is not interrupted every time.
Why is a private IP address flagged instead of just shown?
A public domain that resolves to 10.x, 127.x or another non-routable range is either a misconfiguration or a DNS rebinding attempt, and either way it is worth knowing at a glance rather than reading the answer as if it were a normal public address. The flag uses the same IANA special-purpose-registry classification the CIDR and IP tools in this section use.
Why only one record type per query instead of "all records"?
A single DNS-over-HTTPS query is scoped to one type by the protocol itself — an "all records" answer would mean firing several queries per lookup, which multiplies the abuse surface this tool is already rate-limited to control. Pick the type you need; MX and TXT cover the two most common investigative questions (mail routing, SPF/DKIM/DMARC policy).
Related tools
WHOIS Lookup
Registrar, registration and expiry dates, status codes and name servers for any domain.
Sends dataSSL Certificate Lookup
Every certificate publicly logged for a domain, decoded — via Certificate Transparency, not a live handshake.
Sends dataMX Lookup
See where a domain’s mail is delivered, in priority order, with its SPF and DMARC status beside it.
Sends dataPrivate & Public IP Classifier
Tell whether an address is routable, private, loopback or otherwise reserved.
LocalPort Checker
Check whether one well-known port on a host answers — open, closed, or timed out.
Sends dataCIDR Calculator
Network, broadcast, mask and usable range for any block — and split it into subnets.
Local