DNS lookup·A · MX · TXT · NS · CAA · SOA

All DNS records, instantly.

Look up A, AAAA, CNAME, MX, TXT, NS, SOA and CAA records in one shot — with email health scoring and a clean, readable layout.

8 record types
Email health score
Enter a domain to look up its DNS records.
Try google.com, github.io, or your own domain.
Vebnox Cloud & Web Solutions

Need Web Design, Cloud Hosting, or Domain Migration?

Have a problem with DNS, hosting latency, server migrations, or want an ultra-fast custom website for zoom.us? Talk directly with our senior engineering team.

+91 9505087680WhatsApp Chat
What you get

DNS, finally readable.

Raw DNS output is a wall of text. We parse every record type and surface the details that matter to developers, sysadmins, and domain owners.

8 record types at once

A, AAAA, CNAME, MX, TXT, NS, SOA and CAA — all fetched in a single query and displayed in a clean, filterable view.

Email health scoring

SPF, DMARC, DKIM and CAA are analysed automatically. A health score tells you at a glance how hardened the domain is against spoofing.

Filter by record type

Tab between record types instantly. Need just the MX records? One click. Want everything? "All" shows a two-column grid.

Hosting & mail detection

We identify the hosting provider from IP ranges and the mail provider from MX records — so you see Cloudflare, Vercel, Google Workspace at a glance.

Technical Benchmark

Engineered to outperform traditional domain tools.

Compare our direct socket lookup engine with legacy registrars and slow third-party scrapers.

Capability & Benchmarkdomzy (by Vebnox)Legacy RegistrarsGeneric Scrapers
Direct Port 43 Socket Querying✓ True TCP Raw Sockets✕ Rate-limited HTTP Proxies✕ Scraped Cache
Average Lookup Response Time< 180ms Parallel Streams1,200ms - 3,500ms2,800ms+ Slow
1,147+ TLD Availability in 1 Click✓ Instant Multi-TLD Scan✕ Max 5-10 Extensions✕ Single TLD Only
DNSSEC & Cryptographic Validation✓ RFC-compliant ValidationPartial✕ None
Zero Search Logging & No Front-Running✓ 100% Private (Zero Log)⚠ Monitored for Pricing✕ Sold to Brokers
Global Edge Infrastructure

Geo-Distributed Anycast Diagnostic Nodes.

Queries are processed through high-speed edge nodes across 6 continents to eliminate geographic propagation delays.

32ms
US East (Virginia)
Anycast Node
41ms
US West (Silicon Valley)
Anycast Node
28ms
EU Central (Frankfurt)
Anycast Node
35ms
UK South (London)
Anycast Node
58ms
Asia East (Tokyo)
Anycast Node
48ms
Asia South (Singapore)
Anycast Node
Zero Trust Infrastructure

Enterprise Domain Security Auditing.

Protect your brand reputation from typosquatting, unauthorized transfers, and DNS hijacking.

Anti-Squatting Scanner

Monitors homoglyphs and visually identical Unicode punycode variations across international TLDs.

DNSSEC Cryptographic Chain

Validates DS and RRSIG record anchors against root trust zones to verify response authenticity.

SPF, DKIM & DMARC Health

Instantly checks mail exchange records to prevent email spoofing and ensure deliverability.

Stop second-guessing.

Find your domain in the next 30 seconds.

Free forever. No login required. 1,147+ TLDs in one query — plus AI suggestions and the premium marketplace.

Compare All TLD Prices
1,147
TLDs
200ms
Avg Lookup
100
Suggestions
FAQ

DNS, explained.

An A record maps a hostname directly to an IPv4 address. A CNAME (canonical name) maps a hostname to another hostname — the resolver then looks up that target. You cannot use a CNAME at the zone apex (root domain), which is why you see A records for example.com but often CNAME for www.example.com.
MX (Mail Exchange) records tell the internet which servers accept email for a domain. The priority number determines order — a lower number means higher priority. If the primary server is down, senders fall back to higher-priority-number entries.
These three TXT records form the email authentication stack. SPF lists servers authorised to send mail for the domain. DKIM adds a cryptographic signature to outbound messages. DMARC tells receiving servers what to do when SPF or DKIM fail — report, quarantine, or reject.
Every DNS record has a TTL (time-to-live) that tells resolvers how long to cache the answer. Until that timer expires, many resolvers worldwide still serve the old value. A low TTL (300s) means changes spread in ~5 minutes; a high TTL (86400s) can mean up to 24 hours.
CAA (Certification Authority Authorization) records restrict which certificate authorities are allowed to issue SSL/TLS certificates for a domain. If a CAA record specifies "letsencrypt.org", only Let's Encrypt can issue certs — any other CA attempting to will fail, protecting against misissuance.
The SOA (Start of Authority) record is the authoritative record for the zone. It stores the primary nameserver, an admin contact email, a serial number (incremented on every zone change), and timing parameters like refresh, retry, and expire intervals.