XiaTools

How to Perform a Comprehensive DNS Lookup

Updated 09 Oct 2026

A dns lookup is the foundational process of querying the Domain Name System to translate human-readable hostnames like example.com into machine-readable IP addresses. Whether you are migrating a website, configuring mail servers, or troubleshooting connectivity failures, knowing how to query and analyze DNS records is an essential network engineering skill. By inspecting A, AAAA, MX, TXT, and CNAME records, you gain immediate visibility into how the global internet routes traffic to your infrastructure.

To quickly inspect your domain records without launching a terminal, you can use the DNS Lookup tool on XiaTools to instantly query global name servers and review your complete DNS posture.

Understanding the DNS Resolution Chain

When a client requests a domain name, a multi-step resolution process occurs behind the scenes. Understanding this hierarchy helps you pinpoint exactly where a DNS failure originates.

The Recursive Resolver

Your local operating system or your Internet Service Provider (ISP) relies on a recursive resolver (such as 8.8.8.8 or 1.1.1.1). This resolver accepts your initial request and does the heavy lifting of talking to authoritative name servers if it does not already have the record cached.

Root and TLD Name Servers

If the recursive resolver's cache is empty, it queries one of the thirteen root name servers, which directs it to the Top-Level Domain (TLD) name server for .com, .net, or other extensions. The TLD server then points the resolver to the specific authoritative name servers assigned to the domain.

Authoritative Name Servers

Authoritative name servers hold the actual DNS records created by the domain administrator. Once the resolver queries the authoritative server, it receives the definitive answer and returns it to your device.

Essential DNS Record Types

Before performing queries, you should understand the primary record types you will encounter during a DNS lookup:

  • A Record: Maps a domain name to an IPv4 address (e.g., 192.0.2.1).
  • AAAA Record: Maps a domain name to an IPv6 address (e.g., 2001:db8::1).
  • CNAME Record: Creates an alias pointing one domain name to another canonical domain name.
  • MX Record: Specifies the mail exchange servers responsible for receiving email for the domain.
  • TXT Record: Stores arbitrary text data, commonly used for domain ownership verification, SPF, DKIM, and DMARC security policies.
  • NS Record: Denotes the authoritative name servers for the zone.

How to Perform a DNS Lookup Using Command-Line Tools

Network engineers rely on command-line utilities to query DNS records directly from operating systems. Here is how to use the standard tools effectively.

Using dig (Linux and macOS)

The dig (Domain Information Groper) utility is the gold standard for DNS diagnostics because of its flexibility and detailed output.

To perform a basic lookup for A records:

dig example.com

To query a specific record type, such as MX records, and target a specific public resolver:

dig example.com MX @8.8.8.8

Sample output snippet:

;; QUESTION SECTION:
;example.com.			IN	MX

;; ANSWER SECTION:
example.com.		300	IN	MX	10 mail.example.com.

Using nslookup (Cross-Platform)

The nslookup utility is available on Windows, macOS, and Linux. It provides an interactive or single-command interface for querying DNS servers.

To look up AAAA records using nslookup:

nslookup -type=AAAA example.com

To switch to an interactive session and query a custom name server:

nslookup
> server 1.1.1.1
> set type=TXT
> example.com
> exit

Using PowerShell (Windows)

On modern Windows systems, PowerShell provides native cmdlets for DNS queries that output structured objects.

To query all records or specific types:

Resolve-DnsName -Name example.com -Type TXT

Comparing DNS Lookup Methods

Method Best Used For Platform Support Pros & Cons
Online Tools Quick audits, checking global propagation Web Browser Pros: Instant, no installation required, multi-region checks. Cons: Requires internet access.
dig Advanced debugging, scripting, raw output Linux, macOS Pros: Extremely granular control. Cons: Steep learning curve for beginners.
nslookup Basic checks across legacy systems Windows, macOS, Linux Pros: Universally available. Cons: Output format varies by OS.
PowerShell Windows administration and automation Windows Pros: Native object-oriented output. Cons: Windows-centric syntax.

Step-by-Step DNS Troubleshooting Workflow

When troubleshooting a website outage or email delivery failure, follow this systematic workflow:

  1. Check Local Resolution: Run dig example.com to see if your local machine resolves the correct IP address.
  2. Bypass Local Caching: Query public DNS resolvers directly (e.g., dig example.com @8.8.8.8) to determine if your ISP resolver is serving stale data.
  3. Inspect Authoritative Servers: Find your domain registrar or hosting provider name servers using dig example.com NS, then query those specific servers directly to ensure your zone file is correct.
  4. Verify Email Security: Check your MX records and TXT records for SPF, DKIM, and DMARC compliance to ensure mail delivery is unhindered.
  5. Check TTL (Time to Live): Review the TTL value of your records. Low TTLs (e.g., 300 seconds) are ideal during migrations, while higher TTLs (e.g., 86400 seconds) reduce query load on name servers.

Common DNS Lookup Mistakes and How to Fix Them

  • Mistake: Forgetting the trailing dot in absolute queries. When writing zone files or debugging with raw tools, omitting the root dot can lead to unexpected domain appending.
  • Mistake: Misinterpreting cached results. Failing to account for TTL caching causes engineers to think a DNS change failed when their local resolver is simply holding onto the old record.
  • Mistake: Confusing CNAME and A records at the apex. Placing a CNAME record on a root domain (e.g., example.com) violates DNS specifications and breaks other record types like MX. Always use an A record or an alias/flattening mechanism provided by your DNS host for root domains.
  • Mistake: Overlooking EDNS settings. Modern DNS queries often require Extension Mechanisms for DNS (EDNS) to handle large UDP packets containing DNSSEC or extensive TXT records. Ensure your firewall does not block UDP port 53.

Quick DNS Health Check Checklist

  • Verify A and AAAA records point to your current server IPs.
  • Confirm MX records point to active mail server hostnames, not IP addresses.
  • Check that TXT records validate domain ownership and include proper SPF syntax.
  • Ensure TTLs are adjusted appropriately before making infrastructure changes.
  • Test resolution across multiple independent public resolvers.

Frequently asked questions

What is the difference between a recursive and authoritative DNS server?

A recursive server acts as an intermediary that accepts client requests and searches the internet for answers, caching them for future use. An authoritative server is the definitive source that stores the actual DNS records for a specific domain name and provides final answers to recursive servers.

Why does a DNS lookup return different IP addresses from different locations?

This usually happens when a domain uses GeoDNS or Anycast routing to direct users to the nearest data center for optimal performance. Additionally, local caching delays can cause different recursive resolvers to see old records until the TTL expires.

How long does it take for DNS changes to propagate globally?

DNS propagation depends primarily on the Time to Live (TTL) value set on the modified records and the caching behavior of global recursive resolvers. While some resolvers update within minutes, complete global propagation can take anywhere from a few hours up to 48 hours.

Can I perform a DNS lookup for internal private IP addresses?

Standard public DNS lookups cannot resolve private IP addresses unless you query your organization's internal private name servers or Active Directory domain controllers. Public resolvers like 8.8.8.8 only have visibility into public-facing internet zones.

What does a SERVFAIL error mean during a DNS lookup?

A SERVFAIL error indicates that the recursive resolver encountered a failure when trying to contact the authoritative name server. This is often caused by misconfigured name servers, expired DNSSEC signatures, or severe network connectivity issues between the resolver and the authoritatives.

Related articles

Free tools