DNS Inspector
Look up a domain's records, with the TTLs that decide how long an answer lingers and whether the resolver validated the signatures.
Network request required This tool has to ask a DNS resolver, so the domain name you type is sent to it. Nothing else is: no cookies, no identifier, and nothing about you. Your browser makes the request directly — Toolsfully has no server involved and never sees the query. The resolver is yours to choose below, and each publishes its own privacy policy.
Reading the answers
TTL is how long a resolver may keep the answer. It is the number that decides how long a change takes to be seen everywhere — and the clock starts when each resolver cached its copy, not when you made the change. Lower it a day before a migration and raise it afterwards.
NXDOMAIN and an empty answer are different. NXDOMAIN means the name does not exist at all. An empty NOERROR means the name exists but has no record of that type, which is what you see asking for AAAA on a domain with only IPv4.
DNSSEC validated means the resolver checked the signature chain and it held. Its absence usually means the domain is not signed rather than that anything failed — most domains still are not.
CAA says which certificate authorities may issue for the domain. It is checked at issuance, so it constrains future certificates rather than existing ones.
What this shows and what it does not
One resolver's view, right now. A different resolver may hold an older cached answer, which is exactly what makes propagation confusing. Nothing here queries the authoritative servers directly, so what you see is what that resolver would tell anyone asking.
What "validated" actually claims
When an answer comes back with the AD bit set, it means the resolver that answered you checked the DNSSEC signature chain and it held up. That is a real assurance about the path between the resolver and the authoritative servers, and it is worth having.
It says nothing about the last hop — the one between that resolver and you. Ordinary DNS on port 53 is unauthenticated and unencrypted, so anything between you and your resolver could in principle alter the answer, AD bit included. The flag is a statement the resolver makes about its own work, not proof of what reached your machine. Closing that gap is what DNS over TLS and DNS over HTTPS are for, and it is a separate mechanism from DNSSEC rather than a replacement for it.
One resolver's view is not the whole picture
This tool asks a public resolver over HTTPS and shows you what came back. That is the honest description of what any DNS lookup gives you, and it has consequences worth keeping in mind when an answer looks wrong.
Different resolvers can legitimately hold different answers for the same name. A record whose TTL has not yet expired somewhere will keep returning the old value after you have changed it — the change is not travelling anywhere, it is simply that each cache expires on its own schedule. Authoritative servers can also answer differently depending on who is asking, whether by geography or by returning one set of records inside a network and another outside it. So a mismatch between what you see here and what a colleague sees is not necessarily a fault; check the TTL first, and compare against the authoritative server directly when it matters.
Related tools
Email DNS Analyzer for SPF, DKIM and DMARC in detail. Subnet Calculator for the addresses it returns.