The SOA Lookup tool queries the Start of Authority record for any domain name to display its primary nameserver, administrative email, serial number, and zone transfer timers. It gives you direct insight into how a domain's zone file is managed and when it was last updated.
What is it
A Start of Authority (SOA) record is a mandatory foundational DNS record that sits at the very top of every zone file. It contains essential administrative and operational parameters about the DNS zone, acting as the ultimate source of truth for that domain. Unlike standard A or CNAME records that point users to web servers, the SOA record dictates how other name servers should handle and replicate the domain's data.
Inside an SOA record, you will find several key pieces of metadata. The primary nameserver identifies the main authoritative source for the domain's DNS information. The responsible person field provides an email address for the administrator, usually formatted with a dot instead of an '@' symbol. The serial number acts as a version counter for the zone file, while the refresh, retry, expire, and minimum TTL timers dictate how secondary name servers synchronize their cached data with the primary source.
Why it matters
Monitoring your SOA record is critical for ensuring smooth DNS propagation and reliable domain availability. If your primary nameserver goes down or misbehaves, secondary name servers rely on the timers defined in the SOA record to know how long they can safely serve cached data before checking in again. Without a properly configured SOA record, global DNS resolution for your domain can fail entirely.
The serial number within the SOA record is especially important whenever you make changes to your DNS configuration, such as updating an IP address or adding a TXT record. Secondary name servers periodically check the primary server's serial number; if the number has increased, they know they need to download the updated zone file. If your serial number fails to increment, your DNS updates will not propagate across the internet.
How to use this tool
- Navigate to the SOA Lookup page on XiaTools.
- Enter your fully qualified domain name, such as
example.com, into the input box. - Press the Check button to query the live authoritative name servers for the domain.
- Review the generated SOA record fields and timers displayed on your screen.
How to read the results
When you query example.com using the tool, you will receive a breakdown of the zone's operational parameters. Here is an explanation of every value the tool shows based on a realistic output:
- Primary Nameserver (
ns1.example.com): This is the designated master name server responsible for the domain. All updates to the zone file originate here, and secondary servers sync from this host. - Responsible Person (
admin.example.com): The email address of the domain administrator, where the '@' symbol is replaced by a dot. In this example, the actual email isadmin@example.com. - Serial Number (
2023102501): The version number of the zone file. This specific format uses the dateYYYYMMDDfollowed by a daily revision number (01), which is a common industry standard. - Refresh Timer (
10800): The time in seconds (3 hours) that secondary name servers must wait before checking the primary server for zone updates. - Retry Timer (
3600): The time in seconds (1 hour) that a secondary server must wait before retrying a failed zone transfer attempt. - Expire Timer (
604800): The maximum time in seconds (7 days) that a secondary server will continue to serve its cached zone data if the primary server becomes completely unreachable. - Minimum TTL (
300): The default time-to-live duration in seconds (5 minutes) for negative caching, telling other resolvers how long to cache the fact that a specific record did not exist.
Common problems and how to fix them
Serial Number Not Incrementing
If you make changes to your DNS records but they refuse to propagate globally, the underlying cause is often a stale serial number. Secondary name servers will ignore zone updates unless the serial integer is strictly higher than their currently cached value.
To fix this, manually increment your serial number in your DNS provider's management console. If you use the standard date format, update the trailing revision digits:
; Old serial
2023102501
; New serial after making a change
2023102502
Mismatched Primary Nameserver
Sometimes the primary nameserver listed in the SOA record does not match the actual active name server configured at your domain registrar. This discrepancy can cause confusion during zone transfers and troubleshooting.
To resolve this, log into your DNS host and update the primary nameserver field in your zone file configuration to match the exact hostname of your active primary nameserver.
Unreachable Admin Email
An incorrectly formatted responsible person email address can hinder communication from other network administrators who need to report abuse or misconfigurations.
Ensure your administrative contact uses the dot notation correctly. For example, change support.example.com in the SOA record to represent support@example.com.
Best practices
Adopt a standardized numbering convention for your serial numbers, such as the YYYYMMDDnn format, to easily track when zone files were last modified. Always verify your SOA record after migrating DNS providers to ensure the primary nameserver and contact email point to the correct infrastructure. Keep your refresh and retry timers balanced to avoid flooding your primary name server with unnecessary zone transfer requests while still ensuring timely propagation of critical updates.