Inspector of DNS & Mail Records
Look up any domain's DNS records and check whether SPF and DMARC protect its mail.
Recent lookups
Your last looked-up domains will show up here, only in this browser.
Domain Name System (DNS) & Email Architecture
Root servers hierarchy, authoritative zones, record types, and SPF/DMARC security.
The DNS namespace originates at 13 root server clusters (A-M), delegating queries to Top-Level Domains (.com, .org) and down to authoritative nameservers.
A/AAAA map domains to IPv4/IPv6 addresses. CNAME provides an alias to another domain (never on the apex root), and MX lists prioritized mail exchange hosts.
SPF declares authorized sending IPs. DKIM cryptographically signs outgoing emails, and DMARC dictates enforcement policy (p=reject / p=quarantine) on spoofed mail.
TTL specifies the caching lifespan (in seconds) on recursive resolvers before querying authoritative nameservers, dictating record propagation speed.
DNS Propagation & Email Deliverability Troubleshooting
Step-by-step fixes for stuck TTL caches, mail delivery drops, and MX routing.
Slow DNS Propagation: Resolving to Old IP Hours Later
Emails Bouncing or Landing in Spam Folders
ERR_TOO_MANY_REDIRECTS / CNAME Redirection Loops
MX Host Missing A Record / Delivery Failures
Did You Know? DNS Trivia & Facts
Historical trivia about the 13 root clusters, hosts.txt origin, and symbolics.com.
The 13 Root Server Letters That Power the World
There are only 13 root IP addresses (A through M) due to the historic 512-byte UDP packet limit. Through Anycast, they are mirrored across 1,700+ physical datacenters.
symbolics.com: The First Domain Registered in 1985
Registered on March 15, 1985 by Symbolics Inc., `symbolics.com` is the oldest registered .com domain and remains online today as an Internet museum.
When the Entire Internet Was a Single Text File (hosts.txt)
Before Paul Mockapetris created DNS in 1983, Elizabeth Feinler at SRI manually updated a master `hosts.txt` file and distributed it weekly via FTP.
The 2008 Kaminsky Bug & The Dawn of DNSSEC
Dan Kaminsky discovered a flaw enabling DNS cache poisoning in under 10 seconds. The secret patch assembly in 2008 accelerated global adoption of cryptographic DNSSEC.