
How to Use nslookup to Check DNS Records?
If you've ever been asked by a support team to "run nslookup and send me the output," you already know how central this tool is. nslookup ships with Windows, macOS, and nearly every Linux distribution, which makes it the one DNS query tool you can count on being available on any machine you sit down at. It's not the most detailed tool around, but for checking whether a record exists, what it says, and which server is answering, it's quick and dependable.
This guide walks through everything you need for day-to-day DNS checks with nslookup: basic lookups, querying specific record types, picking which DNS server to ask, getting authoritative answers, interactive mode, reading the output on Windows versus Linux and macOS, and decoding the error messages. If you want more detail per query, the companion guide on using the dig command for DNS lookups covers the more verbose alternative.
Basic Syntax
nslookup has two modes. Non-interactive mode runs one query and exits:
nslookup [-option ...] name [server]
Interactive mode starts a prompt where you can run many queries and change settings as you go. You enter it by running nslookup with no arguments, which is covered later.
The simplest possible lookup:
nslookup example.com
On Linux or macOS, the output looks something like this:
Server: 192.168.1.1
Address: 192.168.1.1#53
Non-authoritative answer:
Name: example.com
Address: 203.0.113.10
Name: example.com
Address: 2001:db8::10
On Windows it looks like this:
Server: router.home
Address: 192.168.1.1
Non-authoritative answer:
Name: example.com
Addresses: 2001:db8::10
203.0.113.10
Reading the Output
Every nslookup result has two parts:
- The server block.
ServerandAddressshow which DNS server answered. On Windows,Serveris the result of a reverse lookup on that server's IP. The#53suffix on Linux and macOS is the port. - The answer block. The records returned for your query.
The line Non-authoritative answer confuses a lot of people. It doesn't mean the answer is wrong. It means the server that replied is a recursive resolver serving the record from its cache or after looking it up elsewhere, rather than one of the domain's own authoritative nameservers. Most lookups are non-authoritative. If you need to know what the source of truth says right now, query an authoritative server directly, as shown below. The distinction is explained in authoritative vs recursive DNS servers.
On Windows, you may see Server: UnKnown. That simply means the DNS server's IP has no PTR record, so nslookup couldn't turn it into a name. It's harmless.
Querying Specific Record Types
By default, nslookup asks for A and AAAA records. Use -type= (or the equivalent -query= or -q=) to ask for something else.
A and AAAA records
nslookup -type=A example.com
nslookup -type=AAAA example.com
These return only IPv4 or only IPv6 addresses respectively.
MX records (mail servers)
nslookup -type=MX example.com
Non-authoritative answer:
example.com mail exchanger = 10 mail1.example.com.
example.com mail exchanger = 20 mail2.example.com.
The number before each hostname is the preference; lower values are tried first. For more on how this works, see what MX records are.
TXT records (SPF, DKIM, DMARC, verification)
nslookup -type=TXT example.com
This lists every TXT record at the apex, including SPF policies and domain verification tokens. TXT records for DKIM and DMARC live at specific subdomains, so query them by full name:
nslookup -type=TXT _dmarc.example.com
nslookup -type=TXT selector1._domainkey.example.com
Replace selector1 with the DKIM selector your mail provider uses.
NS records (nameservers)
nslookup -type=NS example.com
This returns the nameservers responsible for the domain, which tells you where the zone is hosted.
CNAME records
nslookup -type=CNAME www.example.com
If www.example.com is an alias, this returns its canonical name. A plain nslookup www.example.com also follows the CNAME and shows both the alias and the final addresses.
SOA records
nslookup -type=SOA example.com
The SOA output shows the primary nameserver, the responsible-person mailbox, the zone serial number, and the timers. The serial is especially useful: comparing it across nameservers tells you whether they've all picked up the latest version of the zone.
Other types
nslookup accepts most standard types, including CAA, SRV, PTR, DS, and DNSKEY:
nslookup -type=CAA example.com
nslookup -type=SRV _sip._tcp.example.com
Avoid relying on -type=ANY. Many servers now return a minimal response or refuse ANY queries entirely, as permitted by RFC 8482, so you won't get a full list of records. Query each type you care about instead.
Choosing Which DNS Server to Ask
Add a server as the last argument to send the query there instead of your default resolver:
nslookup example.com 1.1.1.1
nslookup -type=MX example.com 8.8.8.8
This is useful for comparing your local resolver against public ones. If 1.1.1.1 returns a new IP and your default resolver returns the old one, your resolver is still caching the old record.
Getting an authoritative answer
To see exactly what the domain's own nameservers publish, first find them, then query one directly:
nslookup -type=NS example.com
nslookup example.com ns1.example-dns.net
When you query an authoritative nameserver for its own zone, the "Non-authoritative answer" line disappears. This is the most reliable way to confirm a change you just made at your DNS host, because it skips every cache in between. It's also the first step when checking whether DNS changes have propagated.
Useful Options
| Option | What it does |
|---|---|
-type=X / -query=X | Query record type X |
-timeout=N | Wait N seconds for a reply |
-retry=N | Retry N times before giving up |
-port=N | Send queries to a non-standard port |
-debug | Show full response details, including TTLs and sections |
-norecurse | Ask the server not to recurse |
-vc | Use TCP instead of UDP |
Seeing TTLs with debug mode
Plain nslookup output hides TTLs. Add -debug to see them:
nslookup -debug -type=A example.com
The debug output prints the header (including the response code), the question, and each answer with its ttl value. On a recursive resolver, that TTL is the remaining cache time, counting down with each query; on an authoritative server, it's the configured TTL. This is handy when you're waiting for an old record to expire. See what a TTL is in DNS for how to plan around it.
Interactive Mode
Interactive mode is useful when you're running several queries against the same server or changing options between queries. Start it with no arguments:
$ nslookup
> server 1.1.1.1
Default server: 1.1.1.1
Address: 1.1.1.1#53
> set type=MX
> example.com
Server: 1.1.1.1
Address: 1.1.1.1#53
Non-authoritative answer:
example.com mail exchanger = 10 mail1.example.com.
> set type=TXT
> _dmarc.example.com
...
> exit
The most useful interactive commands:
server <ip-or-name>switches the server for subsequent queries.set type=<type>(orset q=<type>) changes the record type.set debugandset nodebugtoggle detailed output.set timeout=<seconds>adjusts the wait time.set vcswitches to TCP, useful for large responses.exitquits.
Older guides also mention ls -d example.com for listing an entire zone. That command (available only in the Windows version) attempts a zone transfer, which almost every public nameserver refuses. Expect a failure rather than a list.
Error Messages and What They Mean
Most of what nslookup reports on failure maps to standard DNS response codes, which are explained in detail in what NXDOMAIN, SERVFAIL, and REFUSED mean.
| Message | Platform | Meaning |
|---|---|---|
** server can't find example.com: NXDOMAIN | Linux / macOS | The name does not exist |
*** ... can't find example.com: Non-existent domain | Windows | Same as above |
** server can't find example.com: SERVFAIL | Linux / macOS | The resolver couldn't get a valid answer |
*** ... can't find example.com: Server failed | Windows | Same as above |
** server can't find example.com: REFUSED | Linux / macOS | The server declined to answer |
*** No ... records available for example.com | Windows | The name exists but has no records of that type |
*** Can't find example.com: No answer | Linux / macOS | The name exists but has no records of that type |
;; connection timed out; no servers could be reached | Linux / macOS | No reply from the server at all |
DNS request timed out | Windows | Same as above |
Two patterns deserve a closer look:
- "No answer" is not NXDOMAIN. It means the name exists but has no records of the type you asked for, for example querying MX on a hostname with only an A record. Check that you asked for the right type.
- Windows timeouts before an answer. Windows nslookup sometimes prints
DNS request timed outonce or twice and then shows a normal answer. That usually comes from its attempt to reverse-resolve the server's own address, or from trying an IPv6 resolver first, and can be ignored if the final answer is correct.
Scripting with nslookup
nslookup output isn't designed for parsing, but it works for quick checks. This loop checks the MX records for a list of domains:
for d in example.com example.net example.org; do
echo "== $d"
nslookup -type=MX "$d" 1.1.1.1 | awk '/mail exchanger/ {print $NF, "(pref", $(NF-1) ")"}'
done
The awk filter prints each mail server hostname with its preference value. For anything more robust, prefer dig +short on Linux and macOS, or PowerShell's Resolve-DnsName on Windows, which returns structured objects:
Resolve-DnsName -Name example.com -Type MX -Server 1.1.1.1 |
Select-Object NameExchange, Preference
This returns the same MX data as typed properties that you can sort, filter, or export with Export-Csv.
nslookup vs dig vs Resolve-DnsName
| Tool | Available on | Strengths |
|---|---|---|
nslookup | Windows, macOS, Linux | Everywhere by default, simple output, interactive mode |
dig | macOS, Linux (Windows via BIND or WSL) | Full response detail, flags, +trace, DNSSEC, scripting |
Resolve-DnsName | Windows PowerShell | Structured objects, honors the hosts file unless -DnsOnly |
A practical rule: use nslookup when you want a quick answer on any machine, and reach for dig when you need TTLs, flags, sections, or a full resolution trace. Neither one reads the hosts file, so if results look right in nslookup but wrong in the browser, check that too.
nslookup FAQ
It means the reply came from a recursive resolver rather than one of the domain's own authoritative nameservers. The data is usually correct, but it may be a cached copy. Query an authoritative nameserver directly to see the current published value.
Run nslookup -type=MX example.com. The output lists each mail server with its preference value; lower numbers have higher priority.
Add the server as the last argument, for example nslookup example.com 8.8.8.8. In interactive mode, use the server command to switch servers for all following queries.
The DNS server's IP address has no PTR record, so nslookup can't display a name for it. It doesn't affect the lookup results.
No. nslookup sends DNS queries directly to a DNS server and ignores the hosts file. Use ping, getent hosts on Linux, or Resolve-DnsName on Windows to see results that include hosts file entries.
Add the -debug option, for example nslookup -debug example.com. The detailed output shows the TTL for each record in the answer.
Many DNS servers now return minimal responses to ANY queries, as allowed by RFC 8482, to reduce abuse. Query each record type individually instead.
It was once marked deprecated in BIND but was later restored and is still maintained and widely used. For detailed troubleshooting, dig is generally preferred, but nslookup remains a perfectly valid tool.
Conclusion
nslookup earns its place through ubiquity. With a handful of commands, nslookup name, -type= for specific records, a trailing server argument to choose who answers, and -debug for TTLs, you can check almost any DNS question on any operating system without installing anything. Interactive mode makes longer sessions faster, and the error messages map neatly to standard DNS response codes once you know what to look for.
The key habits are simple: always note which server answered, remember that "non-authoritative" means cached rather than wrong, and query an authoritative nameserver directly whenever you need to verify a recent change. When you need more depth than nslookup offers, that's the signal to switch to dig.
For full command references, see these sources:
- Microsoft Learn: nslookup command reference — the official documentation for the Windows version of nslookup.
- BIND 9 Documentation: BIND 9 Administrator Reference Manual — includes the manual pages for nslookup, dig, and host as shipped with BIND.
- Microsoft Learn: Resolve-DnsName — the PowerShell alternative with structured output.
- RFC 8482: Providing Minimal-Sized Responses to DNS Queries That Have QTYPE=ANY — explains why ANY queries no longer return every record.


