Type something to search...
How to Use nslookup to Check DNS Records?

How to Use nslookup to Check DNS Records?

If you've ever been asked by a support team to "run nslookup and send me the output," you already know how central this tool is. nslookup ships with Windows, macOS, and nearly every Linux distribution, which makes it the one DNS query tool you can count on being available on any machine you sit down at. It's not the most detailed tool around, but for checking whether a record exists, what it says, and which server is answering, it's quick and dependable.

This guide walks through everything you need for day-to-day DNS checks with nslookup: basic lookups, querying specific record types, picking which DNS server to ask, getting authoritative answers, interactive mode, reading the output on Windows versus Linux and macOS, and decoding the error messages. If you want more detail per query, the companion guide on using the dig command for DNS lookups covers the more verbose alternative.

Basic Syntax

nslookup has two modes. Non-interactive mode runs one query and exits:

nslookup [-option ...] name [server]

Interactive mode starts a prompt where you can run many queries and change settings as you go. You enter it by running nslookup with no arguments, which is covered later.

The simplest possible lookup:

nslookup example.com

On Linux or macOS, the output looks something like this:

Server:         192.168.1.1
Address:        192.168.1.1#53

Non-authoritative answer:
Name:   example.com
Address: 203.0.113.10
Name:   example.com
Address: 2001:db8::10

On Windows it looks like this:

Server:  router.home
Address:  192.168.1.1

Non-authoritative answer:
Name:    example.com
Addresses:  2001:db8::10
          203.0.113.10

Reading the Output

Every nslookup result has two parts:

  1. The server block. Server and Address show which DNS server answered. On Windows, Server is the result of a reverse lookup on that server's IP. The #53 suffix on Linux and macOS is the port.
  2. The answer block. The records returned for your query.

The line Non-authoritative answer confuses a lot of people. It doesn't mean the answer is wrong. It means the server that replied is a recursive resolver serving the record from its cache or after looking it up elsewhere, rather than one of the domain's own authoritative nameservers. Most lookups are non-authoritative. If you need to know what the source of truth says right now, query an authoritative server directly, as shown below. The distinction is explained in authoritative vs recursive DNS servers.

On Windows, you may see Server: UnKnown. That simply means the DNS server's IP has no PTR record, so nslookup couldn't turn it into a name. It's harmless.

Querying Specific Record Types

By default, nslookup asks for A and AAAA records. Use -type= (or the equivalent -query= or -q=) to ask for something else.

A and AAAA records

nslookup -type=A example.com
nslookup -type=AAAA example.com

These return only IPv4 or only IPv6 addresses respectively.

MX records (mail servers)

nslookup -type=MX example.com
Non-authoritative answer:
example.com     mail exchanger = 10 mail1.example.com.
example.com     mail exchanger = 20 mail2.example.com.

The number before each hostname is the preference; lower values are tried first. For more on how this works, see what MX records are.

TXT records (SPF, DKIM, DMARC, verification)

nslookup -type=TXT example.com

This lists every TXT record at the apex, including SPF policies and domain verification tokens. TXT records for DKIM and DMARC live at specific subdomains, so query them by full name:

nslookup -type=TXT _dmarc.example.com
nslookup -type=TXT selector1._domainkey.example.com

Replace selector1 with the DKIM selector your mail provider uses.

NS records (nameservers)

nslookup -type=NS example.com

This returns the nameservers responsible for the domain, which tells you where the zone is hosted.

CNAME records

nslookup -type=CNAME www.example.com

If www.example.com is an alias, this returns its canonical name. A plain nslookup www.example.com also follows the CNAME and shows both the alias and the final addresses.

SOA records

nslookup -type=SOA example.com

The SOA output shows the primary nameserver, the responsible-person mailbox, the zone serial number, and the timers. The serial is especially useful: comparing it across nameservers tells you whether they've all picked up the latest version of the zone.

Other types

nslookup accepts most standard types, including CAA, SRV, PTR, DS, and DNSKEY:

nslookup -type=CAA example.com
nslookup -type=SRV _sip._tcp.example.com

Avoid relying on -type=ANY. Many servers now return a minimal response or refuse ANY queries entirely, as permitted by RFC 8482, so you won't get a full list of records. Query each type you care about instead.

Choosing Which DNS Server to Ask

Add a server as the last argument to send the query there instead of your default resolver:

nslookup example.com 1.1.1.1
nslookup -type=MX example.com 8.8.8.8

This is useful for comparing your local resolver against public ones. If 1.1.1.1 returns a new IP and your default resolver returns the old one, your resolver is still caching the old record.

Getting an authoritative answer

To see exactly what the domain's own nameservers publish, first find them, then query one directly:

nslookup -type=NS example.com
nslookup example.com ns1.example-dns.net

When you query an authoritative nameserver for its own zone, the "Non-authoritative answer" line disappears. This is the most reliable way to confirm a change you just made at your DNS host, because it skips every cache in between. It's also the first step when checking whether DNS changes have propagated.

Useful Options

OptionWhat it does
-type=X / -query=XQuery record type X
-timeout=NWait N seconds for a reply
-retry=NRetry N times before giving up
-port=NSend queries to a non-standard port
-debugShow full response details, including TTLs and sections
-norecurseAsk the server not to recurse
-vcUse TCP instead of UDP

Seeing TTLs with debug mode

Plain nslookup output hides TTLs. Add -debug to see them:

nslookup -debug -type=A example.com

The debug output prints the header (including the response code), the question, and each answer with its ttl value. On a recursive resolver, that TTL is the remaining cache time, counting down with each query; on an authoritative server, it's the configured TTL. This is handy when you're waiting for an old record to expire. See what a TTL is in DNS for how to plan around it.

Interactive Mode

Interactive mode is useful when you're running several queries against the same server or changing options between queries. Start it with no arguments:

$ nslookup
> server 1.1.1.1
Default server: 1.1.1.1
Address: 1.1.1.1#53
> set type=MX
> example.com
Server:         1.1.1.1
Address:        1.1.1.1#53

Non-authoritative answer:
example.com     mail exchanger = 10 mail1.example.com.
> set type=TXT
> _dmarc.example.com
...
> exit

The most useful interactive commands:

  • server <ip-or-name> switches the server for subsequent queries.
  • set type=<type> (or set q=<type>) changes the record type.
  • set debug and set nodebug toggle detailed output.
  • set timeout=<seconds> adjusts the wait time.
  • set vc switches to TCP, useful for large responses.
  • exit quits.

Older guides also mention ls -d example.com for listing an entire zone. That command (available only in the Windows version) attempts a zone transfer, which almost every public nameserver refuses. Expect a failure rather than a list.

Error Messages and What They Mean

Most of what nslookup reports on failure maps to standard DNS response codes, which are explained in detail in what NXDOMAIN, SERVFAIL, and REFUSED mean.

MessagePlatformMeaning
** server can't find example.com: NXDOMAINLinux / macOSThe name does not exist
*** ... can't find example.com: Non-existent domainWindowsSame as above
** server can't find example.com: SERVFAILLinux / macOSThe resolver couldn't get a valid answer
*** ... can't find example.com: Server failedWindowsSame as above
** server can't find example.com: REFUSEDLinux / macOSThe server declined to answer
*** No ... records available for example.comWindowsThe name exists but has no records of that type
*** Can't find example.com: No answerLinux / macOSThe name exists but has no records of that type
;; connection timed out; no servers could be reachedLinux / macOSNo reply from the server at all
DNS request timed outWindowsSame as above

Two patterns deserve a closer look:

  1. "No answer" is not NXDOMAIN. It means the name exists but has no records of the type you asked for, for example querying MX on a hostname with only an A record. Check that you asked for the right type.
  2. Windows timeouts before an answer. Windows nslookup sometimes prints DNS request timed out once or twice and then shows a normal answer. That usually comes from its attempt to reverse-resolve the server's own address, or from trying an IPv6 resolver first, and can be ignored if the final answer is correct.

Scripting with nslookup

nslookup output isn't designed for parsing, but it works for quick checks. This loop checks the MX records for a list of domains:

for d in example.com example.net example.org; do
  echo "== $d"
  nslookup -type=MX "$d" 1.1.1.1 | awk '/mail exchanger/ {print $NF, "(pref", $(NF-1) ")"}'
done

The awk filter prints each mail server hostname with its preference value. For anything more robust, prefer dig +short on Linux and macOS, or PowerShell's Resolve-DnsName on Windows, which returns structured objects:

Resolve-DnsName -Name example.com -Type MX -Server 1.1.1.1 |
  Select-Object NameExchange, Preference

This returns the same MX data as typed properties that you can sort, filter, or export with Export-Csv.

nslookup vs dig vs Resolve-DnsName

ToolAvailable onStrengths
nslookupWindows, macOS, LinuxEverywhere by default, simple output, interactive mode
digmacOS, Linux (Windows via BIND or WSL)Full response detail, flags, +trace, DNSSEC, scripting
Resolve-DnsNameWindows PowerShellStructured objects, honors the hosts file unless -DnsOnly

A practical rule: use nslookup when you want a quick answer on any machine, and reach for dig when you need TTLs, flags, sections, or a full resolution trace. Neither one reads the hosts file, so if results look right in nslookup but wrong in the browser, check that too.


nslookup FAQ

It means the reply came from a recursive resolver rather than one of the domain's own authoritative nameservers. The data is usually correct, but it may be a cached copy. Query an authoritative nameserver directly to see the current published value.

Run nslookup -type=MX example.com. The output lists each mail server with its preference value; lower numbers have higher priority.

Add the server as the last argument, for example nslookup example.com 8.8.8.8. In interactive mode, use the server command to switch servers for all following queries.

The DNS server's IP address has no PTR record, so nslookup can't display a name for it. It doesn't affect the lookup results.

No. nslookup sends DNS queries directly to a DNS server and ignores the hosts file. Use ping, getent hosts on Linux, or Resolve-DnsName on Windows to see results that include hosts file entries.

Add the -debug option, for example nslookup -debug example.com. The detailed output shows the TTL for each record in the answer.

Many DNS servers now return minimal responses to ANY queries, as allowed by RFC 8482, to reduce abuse. Query each record type individually instead.

It was once marked deprecated in BIND but was later restored and is still maintained and widely used. For detailed troubleshooting, dig is generally preferred, but nslookup remains a perfectly valid tool.

Conclusion

nslookup earns its place through ubiquity. With a handful of commands, nslookup name, -type= for specific records, a trailing server argument to choose who answers, and -debug for TTLs, you can check almost any DNS question on any operating system without installing anything. Interactive mode makes longer sessions faster, and the error messages map neatly to standard DNS response codes once you know what to look for.

The key habits are simple: always note which server answered, remember that "non-authoritative" means cached rather than wrong, and query an authoritative nameserver directly whenever you need to verify a recent change. When you need more depth than nslookup offers, that's the signal to switch to dig.

For full command references, see these sources:

  1. Microsoft Learn: nslookup command reference — the official documentation for the Windows version of nslookup.
  2. BIND 9 Documentation: BIND 9 Administrator Reference Manual — includes the manual pages for nslookup, dig, and host as shipped with BIND.
  3. Microsoft Learn: Resolve-DnsName — the PowerShell alternative with structured output.
  4. RFC 8482: Providing Minimal-Sized Responses to DNS Queries That Have QTYPE=ANY — explains why ANY queries no longer return every record.
Tags :
Share :

Related Posts

What Is the Difference Between Authoritative and Recursive DNS Servers?

What Is the Difference Between Authoritative and Recursive DNS Servers?

When someone says "the DNS server," they could mean two completely different machines doing two completely different jobs. One kind of server holds t

Continue Reading
Can DNS settings affect website speed?

Can DNS settings affect website speed?

Yes, DNS settings can significantly affect the speed at which a website loads for its users. DNS, or Domain Name System, is often likened to the inte

Continue Reading
Can You Use a CNAME Record on the Root Domain?

Can You Use a CNAME Record on the Root Domain?

It is one of the most common DNS questions there is. Your hosting platform says "add a CNAME pointing to myapp.example-cdn.net," it works perfectly

Continue Reading