DNS Lookup
A DNS lookup checks the records that connect a domain name to its server, and shows whether the domain resolves at all. Enter a domain to see its A, AAAA, CNAME, MX, NS, TXT, SOA and CAA records, plus a plain-language verdict on why it shows DNS_PROBE_FINISHED_NXDOMAIN: a problem with the domain, or one on your own device.
1 Enter a domain
Lookups go from Frost Rank's server to Cloudflare's public DNS (Google's as a fallback), so you see what the internet sees, not your device's cache. Nothing you check is stored.
2 DNS result
Diagnose common DNS errors
Before a browser can load a site, it asks DNS for the domain's IP address. When that fails, Chrome shows "This site can't be reached" with an error code underneath. Every DNS error comes down to one question this tool answers first: does the domain resolve? It asks public DNS, which gets its answer from the domain's own (authoritative) nameservers, so your device's cache and settings play no part.
- Domain does not resolve: the domain isn't registered, has expired, has no nameservers, or the name you typed (often a subdomain or the www version) has no record. Everyone sees the error, and only the domain's owner can fix it.
- Domain resolves: DNS is fine everywhere else, so your DNS cache, DNS server, VPN, browser or hosts file gave your device a wrong answer. Only you see the error, and the device fixes below clear it.
DNS_PROBE_FINISHED_NXDOMAIN
NXDOMAIN ("non-existent domain") is the DNS answer that says a name doesn't exist, and DNS_PROBE_FINISHED_NXDOMAIN is how Chrome and Edge report it. Firefox says "Hmm. We're having trouble finding that site." Look the domain up above:
- If it says Domain does not resolve, check the spelling first. Then, if the domain is new or its nameservers just changed, give DNS propagation time (up to 24-48 hours) and check again. If it still fails, check at the registrar that the domain is active and that its nameservers are set to your DNS host's. The domain fixes below cover each cause.
- If it says Domain resolves, the domain is fine. Work through the device fixes, starting with clearing your DNS cache.
For example, looking up a subdomain that was never created, nope.frostrank.com, gives this (copied with the "Copy results" button):
DNS lookup for nope.frostrank.com Status: NXDOMAIN frostrank.com exists, but nope.frostrank.com has no DNS records (NXDOMAIN) The main domain is fine, but this name was never set up. Add an A record (or a CNAME) for it at the DNS provider for frostrank.com.
The main domain answers normally, so the fix is a missing DNS record, not anything on the visitor's computer.
ERR_NAME_NOT_RESOLVED
ERR_NAME_NOT_RESOLVED means the browser couldn't turn the domain into an IP address. It's the same family as DNS_PROBE_FINISHED_NXDOMAIN; Chrome shows it when it couldn't confirm the exact reason, often on Android or when the DNS server didn't answer at all. Diagnose it the same way: if the lookup above says the domain resolves, the cause is your device or network, so start with the device fixes, especially changing your DNS server. If it doesn't resolve, the domain needs fixing.
"This site can't be reached"
This is Chrome's heading for any connection failure, so read the error code underneath it. A DNS code (DNS_PROBE_FINISHED_NXDOMAIN, ERR_NAME_NOT_RESOLVED, DNS_PROBE_FINISHED_BAD_CONFIG) means a DNS problem, which this tool diagnoses. A connection code such as ERR_CONNECTION_REFUSED or ERR_CONNECTION_TIMED_OUT means DNS worked and found the server, but the server didn't respond; check it with the HTTP Header Checker instead. To see who hosts the address a domain points to, use the IP Address Lookup.
How to fix DNS_PROBE_FINISHED_NXDOMAIN on your device
Use these when the lookup above says the domain resolves. Try them in order and reload the site after each one:
- Check the address for typos, including the www part. Retype it rather than reusing an old bookmark.
- Clear Chrome's DNS cache: open
chrome://net-internals/#dnsand click "Clear host cache". - Flush your device's DNS cache: on Windows run
ipconfig /flushdnsin Command Prompt; on a Mac runsudo dscacheutil -flushcache; sudo killall -HUP mDNSResponderin Terminal; on a phone, turn airplane mode on and off. - Switch off any VPN, proxy or ad-blocking DNS app, since these use their own DNS servers.
- Change your DNS server to a public one such as Cloudflare's
1.1.1.1or Google's8.8.8.8, in your network settings or router. - Check your hosts file for an entry for the domain:
C:\Windows\System32\drivers\etc\hostson Windows,/etc/hostson a Mac. - Restart your router, which clears its own DNS cache.
Fixes when the domain is the problem
- Typo: check the spelling and the ending (.com, .co, .net) before anything else.
- Still propagating: a newly registered domain or a nameserver change can take up to 24-48 hours to reach every resolver. Check again later; a changed record usually updates once its TTL (shown next to each record above) runs out.
- Not registered or expired: check the domain's status with your registrar and renew it.
- No nameservers: at the registrar, set the nameservers your DNS host gave you, like Cloudflare's or your web host's.
- Missing subdomain or www: add an A record (or a CNAME) for that name at your DNS provider. A common miss is the www version, so add
wwwas a CNAME to the main domain. - CNAME pointing nowhere: the alias targets a deleted site or service. Update or remove it.
- SERVFAIL: the nameservers don't answer correctly, often after moving DNS hosts with DNSSEC still switched on. Remove or update the DS record at the registrar.
DNS record types this tool checks
| Record | What it does |
|---|---|
| A | The IPv4 address a browser connects to. A website needs an A or AAAA record. |
| AAAA | The IPv6 address, the newer version of an A record. |
| CNAME | An alias pointing this name to another domain, which then supplies the address. |
| MX | The mail servers that receive email for the domain, in priority order (lower first). |
| NS | The nameservers in charge of the domain's DNS, set at the registrar. |
| TXT | Free-text records for verification and email security, like SPF and site verification codes. |
| SOA | The zone's start of authority: the primary nameserver, admin contact and serial number. |
| CAA | Which certificate authorities may issue SSL/TLS certificates for the domain. |
How to use this tool
-
1
Enter the domain
Type or paste the domain that shows the error, like example.com. A full URL or www. address works too.
-
2
Run the lookup
Click "Look up DNS". The tool asks public DNS for every record type at once.
-
3
Read the verdict
The verdict says whether the domain resolves, and if not, why: not registered, a missing subdomain, a CNAME pointing nowhere, no IP address, or broken nameservers.
-
4
Follow the fix
The steps under the verdict match the cause: fixes for your device when the domain works, or the DNS change the domain owner needs to make.
-
5
Check the records
Review the A, AAAA, CNAME, MX, NS, TXT, SOA and CAA records with their TTLs, and copy them to share with your host or registrar.
Frequently asked questions
It's the error Chrome shows when a DNS lookup comes back NXDOMAIN ("non-existent domain"): the DNS server your device asked says the name doesn't exist, so the browser has no IP address to connect to. Either the domain really doesn't exist in DNS (unregistered, expired, or no records for that name), or something on your device or network gave a wrong answer.
Run the domain through this DNS Lookup. It asks public DNS, not your device. If the domain resolves here, the website is fine and the problem is on your side: a stale DNS cache, your DNS server, a VPN or the hosts file. If it comes back NXDOMAIN here too, the domain itself is the problem and only its owner can fix it.
On Windows, open Command Prompt and run ipconfig /flushdns. On a Mac, run sudo dscacheutil -flushcache; sudo killall -HUP mDNSResponder in Terminal. In Chrome, also open chrome://net-internals/#dns and click "Clear host cache". On a phone, turning airplane mode on and off clears it.
The two devices are asking different DNS servers or have different cached answers. Your computer may have an old cached NXDOMAIN, a VPN or a custom DNS server, or an entry in its hosts file. Flush its DNS cache, switch off any VPN, or set its DNS server to 1.1.1.1 or 8.8.8.8.
A new or changed record usually works within minutes, but resolvers that cached the old answer keep it until its TTL (time to live) runs out. This tool shows each record's TTL. A newly registered domain or a nameserver change can take up to 24-48 hours to reach every resolver.
Yes, it's free with no signup. Each lookup is sent from Frost Rank's server to Cloudflare's public DNS (Google's if Cloudflare doesn't answer). The domains you check aren't stored or logged.
Reads the real DNS response code and authority section, the same check used when debugging a domain migration, so it can tell an unregistered domain from a missing subdomain or a stale device cache instead of just saying "not found".
Was this tool helpful?
Rate it and leave a comment — takes 10 seconds, and genuinely helps decide what to fix or build next.