Lead
Domain lookup checks one domain and puts each result on its own card with its source and fetch time: the RDAP registration record, DNS records from Google Public DNS, IP addresses, IPv6 (AAAA) records, HTTP status with redirects, the page title and the response headers. When a check gets nothing, its card says "Not retrieved" and gives the reason. It is free, needs no account, and runs on our server.
Key takeaways
- Seven checks return data: registration (RDAP), DNS, IP addresses, IPv6, HTTP status and redirects, page title, and response headers.
- Each card shows where its value came from and when it was fetched, in UTC.
- DNS answers come from Google Public DNS; for about one domain in ten, Cloudflare cross-checks the addresses.
- Registration records come live from the registry over RDAP and are not saved; this tool does not provide registration data for .cn, .co, .io, .me and .br.
- In the "DNS records" card, "Resolved IP" shows the first resolved address and its ASN number.
- The domain you type reaches public DNS resolvers, the registry, the website and our hosting platform's logs.
Ask AI about this tool
ChatGPTClaudePerplexityGrokGoogle AIWhat does Domain lookup check, and who else sees the domain I type?
Opens in a new tab with only the question above and this page's link, never what you put in the tool.
Contents
How to look up a domain
Enter the domain
Type or paste a domain such as example.com. A full web address works too: the protocol, path, a leading www. and capital letters are dropped, and pasting a valid domain starts the lookup straight away.
Press Look up
The default checks start together and cannot be switched off one by one. Cards fill in as results arrive, the line above them counts succeeded, failed, skipped and running checks, and Stop ends the wait and marks unfinished checks as skipped.
Read each card
A card shows the values it received, the source and the time they were fetched. A check that got nothing says Not retrieved, gives the reason and an error code, and says whether it can be retried.
Retry or take the results
Retry on a failed card runs that one check again without its stored result, though DNS answers still inside their TTL may be reused. Copy report puts the results on your clipboard as Markdown text (when some checks were not retrieved, the button reads Copy results so far (Markdown)), Download JSON saves them as a file named after the domain, and Share link copies the link to this lookup; the link contains the domain, and whoever opens it runs the lookup again.
If a whole check fails or is skipped, the table "Not retrieved this time" under the cards lists it with its error code and whether it can be retried. A check that returned data is not listed there, even if some fields are missing from its card. If every check fails, a banner shows the code NET-DOMAIN-ALL-000 and a Retry all button, and your domain stays in the box.
What RDAP, DNS, HTTP status and ASN mean here
What is RDAP? — RDAP, the Registration Data Access Protocol, is how domain registries publish registration data over the web as structured JSON. RFC 9082 defines how to query it and RFC 9083 defines the responses. Domain lookup gets registration details through RDAP, the successor standard to WHOIS, and does not run classic WHOIS lookups. ICANN says that since 28 January 2025 RDAP is the definitive source of gTLD registration data. Domain lookup finds each ending's RDAP server in IANA's bootstrap file and asks that registry directly.
What is a DNS lookup? — A DNS lookup asks a resolver which records a name has right now. Domain lookup asks Google Public DNS for seven record types: A and AAAA (IPv4 and IPv6 addresses), CNAME (an alias that points the name at another name), NS (the name servers), MX (where mail goes), TXT (text such as SPF) and CAA (which certificate authorities may issue for the name). A resolver answers from its cache for as long as each record's TTL allows, which is why a resolver can keep returning an old answer for a while after a change.
What is an HTTP status code? — It is the three-digit number a web server sends back with every response. MDN groups them in five classes: 100–199 informational, 200–299 success, 300–399 redirection, 400–499 client error and 500–599 server error. A 3xx response sends the visitor on to another address. Domain lookup follows up to five redirects from the home page and lists every hop with its own status, then shows the final status.
What is an ASN? — An ASN (autonomous system number) is the number of the autonomous system an IP address is in. "Resolved IP" in the "DNS records" card shows the ASN of the first resolved address, in the form AS123.
DNS lookup, RDAP lookup and HTTP check: main differences
| Question | DNS answers | RDAP registration record | HTTP status, title and headers |
|---|---|---|---|
| What it tells you | Which addresses, aliases, mail servers, name servers and text records the name has | Who the registrar is, key dates and status codes, as the registry publishes them | Whether the home page answers over HTTPS, where it redirects, its title and selected headers |
| Who answers here | Google Public DNS; for about one domain in ten, Cloudflare also answers the address queries for comparison | The registry for that ending, found through IANA's bootstrap file | The website itself, asked by our server |
| How old a value can be on this page | Up to 5 minutes, and no longer than the record's own TTL | Fetched live on every run; not stored | Up to 5 minutes (title up to 1 hour) |
| What it cannot tell you | What the domain's authoritative servers hold right now, or what your own resolver has cached | Anything the registry leaves out or redacts; endings without RDAP here | How the site behaves for visitors in other places or networks |
| Typical question | "Did my DNS change take effect?" | "When was this domain registered, and with whom?" | "Is the site up, and where does it send people?" |
In one line: use the "DNS records" card for where the name points, the "Domain and registration details" card for who holds it, and the "Site basics" and "Response headers (HEAD)" cards for whether the site answers.
Who holds a domain is only as visible as the registry makes it. The "Domain and registration details" card shows whatever holder and contact fields the RDAP record contains, and many registries redact them; this page has no way to contact the holder.
This page does not sell or register domains, and it does not check whether a name is available. For a name nobody has registered under an ending with an RDAP server, the "Domain and registration details" card says Not retrieved with code NET-DOMAIN-RDAP-026, the same code it shows for any registry answer it cannot use, and the "DNS records" card shows status 3. Neither proves the name is free. A registrar's search answers that, and a registrar is where a domain is bought.
Why check these together
- One run instead of four tools — Registration, DNS, address and HTTP answers sit on one page, so a mismatch such as DNS pointing to a new host while the site still redirects to an old address is visible without copying the domain between tools.
- Every value comes with its time — Right after a change, the question is usually "is this answer from before or after?". Each card's fetch time lets you tell a stored value from a fresh one instead of guessing.
- A gap is labelled, not left blank — A check that returned nothing states the reason and whether a retry can help, so an empty box is not mistaken for "this domain has no record".
Who uses Domain lookup
- Site owners who just moved hosting — Confirm that Google Public DNS returns the new A and AAAA addresses and that the home page answers with the status you expect.
- Developers chasing a redirect problem — See every hop from https://domain/ to the final page with its status code, up to five redirects.
- Email administrators — Read the MX and TXT (SPF) records before a mail migration or campaign.
- SEO and content editors — Check the title, meta description, keywords and language attribute the home page actually serves.
- Support staff hearing "your site is down" — Compare what our server gets from the site with what the customer sees.
- Security reviewers — See which of Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options and Referrer-Policy the home page sends.
- People researching a domain — Read the registry's own RDAP record for endings that publish one.
How accurate are the results?
Each value is one source's answer at one moment. The DNS check asks Google Public DNS for every record type. For about one domain in ten, picked by a fixed hash of the name so that a given domain is in or out of the sample on every run, it also asks Cloudflare for the A and AAAA records and labels the comparison same, different or unavailable; Cloudflare's answer is shown beside Google's and does not replace it. Both are public resolvers that answer from their caches. This tool does not ask the domain's authoritative name servers directly. Each resolver's answer carries its DNS status. Google's own documentation warns that "An HTTP success may still be a DNS failure", which is why the status is shown rather than hidden: status 3 is the "Name Error" of RFC 1035 §4.1.1, meaning the resolver reports that the domain does not exist.
Some values are reused for a short time. To avoid asking the same source again and again, results for DNS, IP, IPv6, HTTP status and headers are kept for up to 300 seconds, and DNS values are kept no longer than the shortest TTL in the answers received. The page title is kept for up to 3,600 seconds. The registration record is not stored. If you run the lookup again inside that window you get the stored value with its original fetch time. The Retry button on a failed card skips the stored result for that check, but the individual DNS answers underneath the DNS, IP and IPv6 checks can still be reused while inside their TTL, and the card then shows their original fetch time. These windows are the product's configured settings, not a measurement.
The HTTP view is our server's view. Domain lookup requests https://domain/ only, identifies itself as 17TooL-ExternalProbe/1.0 and gives each check 5 seconds. It follows at most five redirects; a sixth stops the request. A response larger than 1 MiB is abandoned once it passes that size: the HTTP status, title and header checks then all report Not retrieved with a code ending in -007. Sites behind bot protection may answer our request differently from a browser. When we fetched 62 search-result pages with a plain non-browser client on 2026-09-22 for our own research, 13 of them answered with a challenge or a refusal (HTTP 403 or 429). A 403 here is therefore not proof that visitors are blocked.
The registration record is shown as the registry sends it. Which fields it contains is up to the registry; Domain lookup does not fill in hidden fields or guess them from elsewhere. The "Response time" figure in the "Site basics" card counts from the start of that check, including any wait for its turn in the queue, so it is not a speed measurement of the site.
Privacy and security
Domain lookup runs on our server, not in your browser, so the domain you type has to leave your device. Here is who receives it. For the DNS, IP and IPv6 checks the domain goes to Google Public DNS (dns.google). For about one domain in ten, the A and AAAA queries also go to Cloudflare's resolver (cloudflare-dns.com); Cloudflare states that it deletes its public resolver logs within 25 hours, but it may keep an aggregate list of the domain names queried, with counts, indefinitely. The address check our server makes before connecting to the website or the registry goes to Google Public DNS as well. For the registration record the domain goes to the registry of that ending, for example Verisign for .com. For the HTTP status, title and headers our server requests the site's home page itself, labelled 17TooL-ExternalProbe/1.0. Downloading IANA's bootstrap file does not include your domain.
Your lookups are never published. Registration data is not stored. Lookup results are not stored with your identity. The temporary link made while a lookup runs expires 24 hours after the lookup starts. Public DNS and web data for the same domain are cached on our server for up to 1 hour (DNS data for up to 5 minutes, and no longer than the record's own TTL), without recording who looked it up, so the results you see may come from the cache. Separately, a pre-warm list holds only the domain name itself; it does not record who looked it up and stores no results. The platform that hosts this site (Cloudflare) keeps sampled operational logs.
Share link only copies the link to this lookup to your clipboard. Our server keeps no copy of the results for sharing. The link contains the domain you looked up, and anyone who opens it runs a new lookup of that domain.
Our hosting platform is Cloudflare Workers, and it keeps logs of requests to our server; in our production settings it samples about one request in ten. So we cannot claim that nobody can tell who looked up a domain. For the same reason, avoid checking hostnames that contain personal information, such as a person's name or an internal project name: they go to the parties listed above.
When it helps
- Setting up CAA — Read the CAA records to see which certificate authorities the domain allows to issue for it.
- Before a renewal or transfer — Read the expiry date and status codes in the registry's record, where the ending publishes them.
- After changing name servers at the registrar — Compare the name servers in the registration record with the NS answer from Google Public DNS.
- Verifying a domain for a third-party service — Confirm the verification TXT record appears in the public DNS answer.
- After pointing a subdomain at a hosted service — Enter the subdomain, such as shop.example.com, and check that its CNAME answer names the host you set.
- Planning IPv6 support — See whether the domain publishes AAAA records at all.
Technical specifications
| Item | Value |
|---|---|
| Input | One domain per run, e.g. example.com; a full URL is reduced to its host name |
| Not accepted | IP addresses, names without a dot, localhost and .local names |
| Checks per run | Registration (RDAP), DNS, IP addresses, IPv6, HTTP status and redirects, title, headers; all run together |
| DNS sources | Google Public DNS (dns.google) for A, AAAA, CNAME, NS, MX, TXT and CAA; for about one domain in ten, Cloudflare (cloudflare-dns.com) is also asked for A and AAAA as a cross-check |
| Registration source | The registry's RDAP server, found in IANA's bootstrap file; this tool does not provide registration data for .cn, .co, .io, .me and .br |
| IP details | "Resolved IP" in the "DNS records" card: the first resolved address and its ASN number; the A and AAAA records are listed in the same card |
| HTTP request | A request for https://domain/ from our server, user agent 17TooL-ExternalProbe/1.0, following up to 5 redirects; a response over 1 MiB is abandoned and yields no values |
| Headers shown | content-type, content-length, server, cache-control, strict-transport-security, content-security-policy, x-frame-options, x-content-type-options, referrer-policy; cookies are not collected |
| Time limit | 5 seconds per check |
| Reuse window | DNS, IP, IPv6, HTTP, headers: up to 300 s; title: up to 3,600 s; registration: not stored |
| Results you can take | Copy report (Markdown to clipboard), Download JSON, Share link (copies the link to this lookup) |
| Price and account | Free; no account; domains are not sold here |
| Processing location | Our server; your browser only sends the domain and shows the results |
What this tool does not provide
Some checks can return no data; the card says so, with the reason, rather than leaving the space empty.
| Part | What the card shows | Why |
|---|---|---|
| Registration for .cn, .co, .io, .me | Not retrieved, NET-DOMAIN-RDAP-015 | This tool does not provide registration data for these endings |
| Registration for .br | Skipped, NET-DOMAIN-RDAP-014, with a link to registro.br | registro.br's terms restrict redistribution, so the page links to registro.br instead |
| Registration for endings with no RDAP server in IANA's file | Not retrieved, NET-DOMAIN-RDAP-015 | There is no RDAP server to ask, and this tool does not use another source |
Domain lookup does not ask the domain's authoritative name servers directly, does not test direct IPv6 connections, and does not look up reverse DNS for IP addresses; these parts do not appear in the results.
Registration records are also kept out of storage by design. The copy of a lookup job kept on our server carries NET-DOMAIN-RDAP-012 ("not saved, please look it up again") in place of the registration record; the record itself exists only in the results your page received.
Other failures happen at lookup time and are marked as retryable when a retry can help: a check that ran out of its 5 seconds (code ending -023), a data source that is rate-limiting us (-025), or a data source that returned nothing usable (-026). A request stopped by our outbound safety check (-024), for example after more than five redirects, or a response over the 1 MiB limit (-007) is marked as not retryable.
Is the site down, or is it just me?
Domain lookup shows what our server saw, from one place, at the time printed on each card. That is enough to answer "did the site answer anybody?", and not enough to prove it is down for everyone. Read the cards in this order.
- "HTTP status" in the "Site basics" card shows a code with a recent fetch time. The site answered our server at that moment. A 2xx or a redirect ending in 2xx means it was serving pages; if you still cannot open it, the difference is likely on your side, such as your resolver, your network or a firewall. Compare the addresses in the "DNS records" card with what a command such as nslookup returns on your own machine.
- "HTTP status" shows a 5xx code. The server is reachable but failing to serve the page. That is a server-side problem, and waiting or contacting the site owner is the realistic option.
- "HTTP status" shows a 4xx code. The server answered but refused the request. A 403 can be bot protection reacting to our server rather than a block on visitors, as explained under accuracy.
- "Site basics" says Not retrieved for "HTTP status and redirect chain". Read the "DNS records" card first. If it reports status 3, the domain does not exist in DNS. If there is no public address at all, or the home page redirected more than five times, the "Site basics" card reports that the outbound safety check stopped the request. If addresses are listed but the HTTP check timed out, the site did not answer our server over HTTPS within 5 seconds.
- Check the fetch time. A card can show a stored value. If the problem started or was fixed within the last few minutes, the card may still show the earlier state.
What this cannot tell you: whether the site works from other countries or networks, because this tool checks from one place only, and whether a plain-HTTP-only site is up, because our check requests HTTPS.
Domain lookup compared with other domain lookup tools
On 2026-09-22, between 02:10 and 03:36 (UTC+7), we ran the same test on six English-language domain tools: Google Chrome 153 on Windows 11, not signed in to any site, one lookup of example.com and one of a domain that does not exist, with a screenshot, raw data or network log behind every cell. Domain lookup was not part of that test, so its column describes how the tool is designed and says "Not yet measured" where only a test could tell.
| Dimension | 17TooL Domain lookup (as designed) | dnschecker.org, 2026-09-22 | whatsmydns.net, 2026-09-22 | MxToolbox SuperTool, 2026-09-22 | HackerTarget DNS Lookup, 2026-09-22 | DomainTools Whois, 2026-09-22 | nslookup.io, 2026-09-22 |
|---|---|---|---|---|---|---|---|
| Result without signing in or passing a check | Yes; the lookup route has no sign-in | No: the Cloudflare human check showed "verification failed" and no records appeared | Yes | Yes | Yes | No: stopped by a captcha ("Please help us validate that you are indeed human") | Yes |
| What one lookup returns by default | Registration (RDAP), DNS, IP addresses, IPv6, HTTP status and redirects, title and headers | Not tested (stopped by the check) | A records from many locations, 18 visible on the first screen | An MX lookup plus DNS checks | A, AAAA, MX, NS, TXT, SOA | Not tested (stopped by the captcha) | A, AAAA, CNAME, TXT with SPF parsed, NS, MX |
| Several domains in one run | Yes, with Batch lookup: up to 100,000 domains per batch | No | No | No, not on this page | No | No | No |
| Price shown on the site | Free | No price page found | No price page found; a Donate link | "FREE $0/month", $129/month, $399/month | $10, $25 or $50 a month billed yearly; enterprise from $100 a month | The pricing link opened a page whose text showed no price | No price page found |
| Time until the results stopped changing (example.com) | Not yet measured; each check has a 5 s limit | Not measured (no result) | 2.6 s or less | 4.6 s | About 2.6 s | Not measured (no result) | About 2.6 s |
| A domain that does not exist | "Domain and registration details": Not retrieved, NET-DOMAIN-RDAP-026; "DNS records": status 3 | Not tested | A red ✖ per location, no text reason | "DNS Record not found" | "error input invalid - enter IP or Hostname" for a validly formed name | Not tested | "No A records found." and "No AAAA records found." |
| Fetch time on results | Yes, on each card, in UTC | None on results; help text mentions caching | None on results; help text mentions caching | "Reported by … on 9/21/2026 at …" | None | Not tested | Remaining TTL per record ("Revalidate in") |
| Source named on results | Yes, on each card | A selector reading "DNS Server: Google" | Resolver city and operator on each row | "Reported by elliott.ns.cloudflare.com" | None; footer "Powered by Open Source Software" | Not tested | "The Cloudflare DNS server responded with these DNS records"; Cloudflare, Google DNS and Local DNS columns |
| Browser sent the looked-up domain to third parties | Not yet measured on our page; our server sends it to the parties listed under privacy | Yes: 10 ad and analytics hosts, including ad.doubleclick.net and z.clarity.ms | No | No | No | Yes: ssl.google-analytics.com, px.ads.linkedin.com | Yes: u.clarity.ms, b.clarity.ms, www.google-analytics.com |
| Third-party sites / ad or tracking hosts contacted | Not yet measured | 190 / 91 | 7 / 4 | 10 / 5 | 5 / 2 | 10 / 7 | 13 / 8 |
| Export | Copy report, Download JSON, Share link | None seen | None seen | None seen | None seen | Not tested | None seen; "Save / Track This Domain" |
| Fits a 375 px phone screen | Not yet measured | No: 982 px wide | Yes | Nearly: 400 px wide | Yes | Yes | Yes |
| Interface languages | Interface text in 7 languages | 1 | 1 | 1 | 1 | 1 | 1 |
The same run covered 13 Chinese-language tools: jucha, chinaz, boce, 5118, aizhan, cjzzc, iis7, juziseo, khcha, link113, longming, xiongmaotool and xz. Across all 19, four gave no result because of a check or sign-in: jucha (a slider check, then sign-in for bulk), longming (a sign-in page), DomainTools (a captcha) and dnschecker.org (a failed human check). xiongmaotool's tool pointed to link113 instead, juziseo returned to its home page twice without a result, and iis7's bulk run stayed at 0 for 180 seconds. Of the three bulk boxes that accepted the test list, link113 and iis7 looked up bücher.de as cher.de, xz dropped it, and all three dropped the line "hello world" without a message.
Note: peer facts come from that one test and are shown as recorded. Times are when page text stopped changing, sampled once a second, so values near 2.5 s only mean the page settled quickly. Ad and tracking hosts were matched by host name against a list and may be over- or under-counted; dnschecker.org's failed check may be related to the automated browser and was not bypassed.
Frequently asked questions
Is Domain lookup free, and do I need an account?
Yes, it is free and there is no account or sign-in. You type a domain and press Look up; the default checks run without any registration step.
What is the difference between DNS records and registration details?
DNS records show where a name points now: addresses, mail servers, name servers. Registration details are the registry's record of the domain: registrar, dates and status. This page shows DNS answers and the registration details from RDAP.
Can I find out who owns a domain or contact the owner?
Only as far as the registry publishes it. The "Domain and registration details" card shows the RDAP record as sent, including any holder or contact fields, and many registries redact them. This page cannot message the holder.
Can I check whether a domain is available, or buy it here?
No. This page does not sell domains. For an unregistered name, the "Domain and registration details" card says Not retrieved (NET-DOMAIN-RDAP-026) and the "DNS records" card shows status 3; neither proves availability. A registrar's search confirms it.
Why are some registration details missing or hidden?
The registry decides what its RDAP record contains, and many leave fields out or redact them. Domain lookup shows the record as sent and does not fill gaps from other sources.
Can I check many domains at once?
Yes. Press Batch lookup on this page to open the batch page (the same address with ?page=batch), then paste the domains one per line; commas and spaces also work. Each domain is checked on its own, and one batch takes up to 100,000 domains. The single lookup checks one domain per run.
Does it monitor a domain or warn me before it expires?
No. There is no monitoring, no expiry alert and no public API. Each result is a single check at the time shown on the card.
Why is a website down for me but not for others?
If "HTTP status" in the "Site basics" card shows a code with a recent time, the site answered our server, so the problem is likely your resolver, network or firewall. Compare the addresses in the "DNS records" card with your own.
How fresh are the results?
Registration is fetched live each run. DNS, IP, IPv6, HTTP status and headers can be up to 5 minutes old, the title up to 1 hour. Each card prints its fetch time.
Is the domain I look up saved?
Your lookups are never published. Each check sends only the domain you entered. Registration data is not stored, and lookup results are not stored with your identity. The temporary link made while a lookup runs expires 24 hours after the lookup starts. Public DNS and web data for the same domain are cached on our server for up to 1 hour (DNS data for up to 5 minutes, and no longer than the record's own TTL), without recording who looked it up, so the results you see may come from the cache. Separately, a pre-warm list holds only the domain name itself; it does not record who looked it up and stores no results. The platform that hosts this site (Cloudflare) keeps sampled operational logs.
Can I look up any domain?
Most public domain names with at least one dot, such as example.com. IP addresses, localhost and .local names are refused. A name without a public address gets DNS answers but no HTTP result.
What does "Can't be retried" mean on a failed card?
That failure will not change on a retry, for example because our outbound safety check stopped it. Retryable failures such as timeouts show a Retry button instead.
Sources and references
- ICANN, Registration Data Access Protocol (RDAP) · accessed 2026-09
- ICANN, ICANN Update: Launching RDAP; Sunsetting WHOIS (27 January 2025) · accessed 2026-09
- RFC 9082, Registration Data Access Protocol (RDAP) Query Format · accessed 2026-09
- RFC 9083, JSON Responses for the Registration Data Access Protocol (RDAP) · accessed 2026-09
- RFC 1035, Domain Names: Implementation and Specification, §4.1.1 · accessed 2026-09
- Google Public DNS, DNS-over-HTTPS (DoH) · accessed 2026-09
- Cloudflare, 1.1.1.1 Public DNS Resolver privacy · accessed 2026-09
- MDN Web Docs, HTTP response status codes · accessed 2026-09
- Cloudflare, Workers Logs · accessed 2026-09