XiaTools

How to Find the Mail Server IP for Any Domain

Updated 09 Oct 2026

Finding the mail server IP address for any domain is essential for email delivery troubleshooting, migration planning, and security auditing. An mx lookup queries the Domain Name System (DNS) to reveal which Mail Exchange (MX) servers are responsible for accepting email on behalf of a specific domain name.

Whether you are diagnosing why your emails are bouncing or configuring a new mail transfer agent, knowing how to trace email routing is a fundamental network engineering skill. You can quickly inspect these routing records using the XiaTools MX Lookup utility to instantly check mail servers, preference weights, and associated IP addresses without needing command-line access.

Understanding MX Records and Email Delivery

When you send an email from your client or application, your system needs to know where to deliver the message over the Simple Mail Transfer Protocol (SMTP). It does this by asking DNS for the MX records of the recipient domain. Unlike standard A records that point a domain to a web server, MX records point to the specific mail servers handling inbound mail.

Structure of an MX Record

An MX record consists of two primary components:

  1. Preference Number (Priority): A lower integer value indicates a higher priority. If multiple mail servers exist, sending servers will attempt to deliver mail to the lowest preference number first, falling back to higher numbers if the primary server is unreachable.
  2. Mail Server Hostname: The Fully Qualified Domain Name (FQDN) of the server hosting the mail exchanger (e.g., mail.example.com).

To complete the delivery, your outgoing mail server must take the hostname found in the MX record and perform a subsequent A or AAAA record lookup to resolve it into an IPv4 or IPv6 address.

How to Perform an MX Lookup Using Online Tools

Using a dedicated web-based tool is the fastest way to check mail routing without installing local utilities. Web tools query global DNS resolvers to ensure you see the current records regardless of your local caching.

  1. Navigate to the MX Lookup tool on XiaTools.
  2. Enter the target domain name in the search input field (for example, example.com).
  3. Click the lookup button to query the authoritative name servers.
  4. Review the returned table, which displays the priority, mail server hostnames, and corresponding IP addresses.

Web tools are especially useful when you need to verify global propagation after changing your DNS provider or updating your mail hosting service.

Finding Mail Server IPs Using Command-Line Tools

As a network administrator, you will often need to query DNS directly from your terminal or command prompt. Different operating systems offer various native utilities for this task.

Using dig on Linux and macOS

The dig (Domain Information Groper) utility is the gold standard for DNS queries. To find the MX records for a domain, run:

dig example.com MX

Sample output:

; <<>> DiG 9.10.6 <<>> example.com MX
;; global options: +cmd
;; ANSWER SECTION:
example.com.		300	IN	MX	10 mail.example.com.
example.com.		300	IN	MX	20 mail2.example.com.

Once you have the hostnames (mail.example.com), you can find their IP addresses by querying the A records:

dig mail.example.com A

Sample output:

;; ANSWER SECTION:
mail.example.com.	300	IN	A	192.0.2.25

Using nslookup on Windows and Linux

If dig is not available, nslookup is universally present across Windows and Unix-like environments.

  1. Open your terminal or Command Prompt.
  2. Enter interactive mode or run a direct query:
nslookup -type=MX example.com

Sample output:

Server:  dns.example.local
Address:  192.0.2.1

Non-authoritative answer:
example.com	MX preference = 10, mail exchanger = mail.example.com
example.com	MX preference = 20, mail exchanger = mail2.example.com

mail.example.com	internet address = 192.0.2.25

Using PowerShell on Windows

PowerShell provides modern cmdlets for querying DNS records directly within Windows environments:

Resolve-DnsName -Name example.com -Type MX

Sample output:

Name             Type   TTL   Section   NameHost
----             ----   ---   -------   --------
example.com      MX     300   Answer    mail.example.com

Comparing DNS Query Methods

Method Best Used For Platform Resolves IP Automatically Propagation Check
Web Tool Quick checks & sharing All (Browser) Yes Yes (Global)
dig Detailed debugging Linux, macOS No (Requires A lookup) Local / Specific DNS
nslookup Quick terminal checks Windows, Linux Varies by OS Local Cache
Resolve-DnsName Windows automation Windows PowerShell No Local Cache

Verifying SMTP Connectivity and Mail Server IPs

Once you have successfully performed an mx lookup and extracted the mail server IP address (such as 192.0.2.25), you should verify that the server is actually listening for incoming mail connections on port 25.

Testing with Telnet or Netcat

You can manually initiate an SMTP handshake to ensure the server responds:

nc -v 192.0.2.25 25

Sample successful response:

Connection to 192.0.2.25 25 port [tcp/smtp] succeeded!
220 mail.example.com ESMTP Postfix

Testing with PowerShell

To test TCP connectivity to a mail server port using PowerShell:

Test-NetConnection -ComputerName 192.0.2.25 -Port 25

Common Mistakes and How to Fix Them

When troubleshooting email routing, administrators frequently encounter a few typical pitfalls:

  • Pointing MX to an IP Address: A common configuration error is entering an IP address directly into the MX record value field instead of a hostname. MX records must always point to an FQDN, which in turn resolves to an A or AAAA record.
  • Ignoring TTL (Time to Live): If you recently changed your email provider, old MX records may be cached by local resolvers. Always check the TTL value before assuming your changes have propagated globally.
  • Blocking Outbound Port 25: Many Internet Service Providers (ISPs) and cloud hosting providers block outbound port 25 by default to prevent spam. If your connection times out during SMTP testing, verify whether your network restricts this port.
  • Confusing SPF and MX: Ensure your Sender Policy Framework (SPF) records authorize the IP addresses found during your MX lookup so that your outbound mail is not marked as spoofed.

Quick Troubleshooting Checklist

  • Identify the exact domain experiencing email delivery issues.
  • Run an MX query using a global web lookup tool or terminal command.
  • Confirm that all listed MX hostnames resolve correctly to valid IPv4 (A) or IPv6 (AAAA) addresses like 192.0.2.25 or 2001:db8::10.
  • Verify that priority numbers are set correctly (e.g., 10 for primary, 20 for secondary).
  • Test TCP connectivity on port 25 to the resolved mail server IP.
  • Check DNS propagation if record changes were recently applied.

Related articles

Free tools