FAQ
What does BetterDNS.info check?
It checks IP addresses, nameservers, DNSSEC status, MX, SPF, DKIM, DMARC, registrar details, and WHOIS information for a domain.
Why is BetterDNS.info faster than using several separate tools?
BetterDNS.info is built around parallel lookups, so the main domain checks are performed together instead of one by one. That reduces manual steps and makes troubleshooting more efficient.
Who should use BetterDNS.info?
It is aimed at developers, sysadmins, network engineers, security researchers, and anyone who needs quick DNS and WHOIS visibility.
Is BetterDNS.info free?
Yes, BetterDNS.info is totally free to use.
Can I use it in the browser without installing anything?
Yes, it works in any browser and requires no install.
Does BetterDNS.info show IP geolocation?
Yes. When geolocation data is available for returned IP addresses, BetterDNS.info may show the associated city and country. This can help you understand where a server, mail host, or other resolved endpoint appears to be located. Geolocation data is not guaranteed for every IP address, so location details may appear only when a reliable match is available.
How often is geolocation data updated?
The geolocation data we use is updated weekly.
What is DNSSEC?
DNSSEC (Domain Name System Security Extensions) is a protocol that adds a digital signature layer to DNS records, allowing resolvers to verify that the DNS response came from the authoritative server and hasn't been tampered with. It helps prevent DNS spoofing and cache poisoning attacks, and is a critical security measure for high-value domains.
Should I enable DNSSEC for my domain?
Enabling DNSSEC is a good security practice if your domain is sensitive or high-value. It helps protect against DNS spoofing attacks and ensures that recursive resolvers can verify the authenticity of your DNS records. However, DNSSEC requires careful setup and monitoring — misconfiguration can cause DNS failures. Most domain registrars now support DNSSEC, and many make it easy to enable. If you handle sensitive information or operate critical services, DNSSEC is worth implementing.
Do I need a DKIM selector?
Only if you want to inspect a DKIM record, because DKIM records are usually stored under a selector-specific subdomain. The domain lookup still works without it for the other records.
What is a DKIM record, anyway?
DKIM (DomainKeys Identified Mail) is a protocol that uses cryptographic signatures to verify that emails sent from your domain are authentic and haven't been modified in transit. DKIM records are stored as DNS TXT records and contain a public key that mail receivers use to verify the signature on emails that claim to be from your domain.
Is DKIM necessary for my domain?
If you send email from your domain, implementing DKIM is highly recommended. DKIM is a core part of email authentication (alongside SPF and DMARC) and helps prevent your domain from being impersonated for phishing or spam. Major email providers expect DKIM signatures on incoming mail, and lack of proper DKIM setup can result in your emails being flagged as spam or rejected outright. If your domain sends any email at all, DKIM is worth setting up.
How do I find my DKIM selector?
DKIM selectors are set by whoever configured DKIM signing for your domain — usually your email provider or hosting platform. Common selectors include names like default, mail, google, selector1, or s1. You can check your email provider's documentation, inspect the raw headers of a sent email (look for the DKIM-Signature header and find the s= tag), or try common selector names directly in BetterDNS.info.
What is an SPF record?
SPF (Sender Policy Framework) is a DNS TXT record that specifies which mail servers are authorized to send email on behalf of your domain. It helps receiving mail servers detect spoofed sender addresses and is a key part of email authentication alongside DKIM and DMARC.
Is SPF necessary for my domain?
If your domain sends email, implementing SPF is highly recommended. SPF is a core part of email authentication and is expected by major email providers. Without SPF, your emails are more likely to be marked as spam or rejected. Most email hosting providers support SPF setup, and it is relatively straightforward to implement. If you send any email from your domain, SPF is worth setting up.
What does DMARC stand for?
DMARC stands for Domain-based Message Authentication, Reporting, and Conformance. It is a DNS TXT record that builds on SPF and DKIM to tell receiving mail servers what to do when a message fails authentication — for example, quarantine it or reject it outright. It also enables reporting so domain owners can monitor how their domain is being used in email.
Is DMARC necessary for my domain?
If your domain sends email, implementing DMARC is highly recommended. DMARC is the final piece of email authentication and works with SPF and DKIM to provide policy enforcement and reporting on email authentication failures. It helps protect your domain from being used in phishing attacks and gives you visibility into who is sending email on behalf of your domain. Major email providers support DMARC, and setting it up provides significant security and visibility benefits.
Why might WHOIS data be redacted?
WHOIS data may be redacted for several reasons. Under GDPR and similar privacy regulations, registrars are required to hide personal data such as the registrant's name, address, and email for domains registered by individuals in privacy-protected jurisdictions. Many domain owners also use a privacy protection or proxy service that replaces their contact details with those of the service provider. As a result, WHOIS records increasingly show limited or generic information rather than the actual registrant's details.
Try the Lookup Tool →