DNS lookup
Enter a domain, a web address, an email address or an IP address to see what DNS says about it.
The name you look up is sent from your browser to Cloudflare and, if needed, Google. Quaestio does not see the query and stores nothing.
How it works
DNS, the Domain Name System, translates names such as quaestio.app into what computers need: IP addresses, which servers accept email and much more. Each piece of information is a record with a type. A gives an IPv4 address, AAAA an IPv6 address, CNAME says the name is an alias for another name, MX points to mail servers, NS to the domain’s name servers and SOA holds details of the zone itself.
The queries go from your browser to Cloudflare’s public resolver 1.1.1.1 using DNS over HTTPS (RFC 8484), and to Google’s 8.8.8.8 if Cloudflare does not answer. The answer is therefore what a public resolver sees right now. If a record has just changed, your provider or your computer may still have the old one stored until its TTL runs out.
TTL, time to live, is how long a resolver may keep the answer. When the answer comes from the resolver’s cache, the time shown is what remains, not the value the domain’s name server gave. The response code NOERROR means the query succeeded, even if there are no records of that type, NXDOMAIN that the name does not exist at all, and SERVFAIL that the resolver could not get a valid answer, for example because of a broken DNSSEC signature or name servers that do not respond.
DNSSEC signs records so that a resolver can check they have not been forged along the way. Validated means the resolver set the AD flag in its answer, having checked the whole chain of signatures. Not validated usually just means the domain does not use DNSSEC. The path between your browser and the resolver is protected by HTTPS.
TXT records are used for email, among other things. SPF (v=spf1) lists the servers allowed to send email for the domain; ending in -all means other senders should fail, and ~all that they should be treated as suspicious. DMARC lives under _dmarc and tells receivers what to do with email that fails the checks: p=none only report, p=quarantine treat as suspicious, for example by sending to spam, and p=reject refuse it. DKIM keys live under selector._domainkey and can only be looked up with the selector’s name, which appears in the DKIM-Signature header of a received message.
CAA says which certificate authorities may issue certificates for the domain, SRV where a service is found with its port and priority, and the HTTPS record tells browsers which protocols the server supports, such as HTTP/3. An IP address is looked up in reverse with PTR under in-addr.arpa or ip6.arpa, which gives the name the network’s owner has set, if any. Domain names with letters such as é or ü are queried in punycode: münchen.de becomes xn--mnchen-3ya.de.