Skip to content
RU
← All articles

nslookup Command: How to Use It and Read the Output

A command prompt running an nslookup query with the server's answer

nslookup is a command-line tool that sends a query to a DNS server and prints what a domain name resolves to: IP addresses, mail servers, name servers or TXT records. It ships with Windows and macOS and comes with the BIND utilities on Linux. Run nslookup example.com for addresses, or add -type=mx for other records.

What nslookup does and when to reach for it

The name stands for "name server lookup". nslookup acts as a bare DNS client: it builds a query, sends it to port 53 on a server of your choice and shows the reply with little interpretation. That is exactly why it is useful for troubleshooting — you see what DNS actually returns, not what a browser or an application decided to do with it.

Common jobs for nslookup:

  • confirming that a domain points to the new server after a hosting migration;
  • checking MX records when email stops arriving, and TXT records holding SPF, DKIM, DMARC or a site-verification token;
  • finding the authoritative name servers of a zone and asking each of them directly;
  • comparing your ISP resolver with public ones such as 8.8.8.8, 1.1.1.1 or 9.9.9.9;
  • turning an IP address back into a host name with a PTR lookup.

One detail catches many Windows users: nslookup talks to the DNS server directly and ignores both the hosts file and the DNS Client cache. A browser and ping use the system resolver, which does consult them. When nslookup and the browser disagree, the difference is a clue, not a bug. For the bigger picture of how resolution works, see what DNS is and how it works.

Basic syntax and reading the output

nslookup [-option ...] name [server]

On Windows, open Command Prompt or PowerShell; on macOS, open Terminal. A plain lookup against the resolver your system is configured to use looks like this on Windows:

C:\> nslookup example.com
Server:  UnKnown
Address:  192.168.1.1

Non-authoritative answer:
Name:    example.com
Addresses:  2001:db8::10
          203.0.113.10

The addresses above are documentation placeholders; your domain will return its own. Line by line:

  • Server / Address — the DNS server that answered. UnKnown only means that server's IP has no reverse (PTR) record, which is typical for a home router. It does not affect the result.
  • Non-authoritative answer — the reply came from a caching resolver, not from a server that hosts the zone. The data is valid but may be up to one TTL old.
  • Name — the canonical name that holds the records. If you queried an alias, the original name appears under Aliases.
  • Address / Addresses — the A (IPv4) and AAAA (IPv6) records. Several addresses usually mean load balancing or a CDN.

nslookup on Linux and macOS

macOS includes nslookup out of the box. Minimal Linux installs often answer nslookup: command not found; install the DNS utilities package:

# Debian, Ubuntu
sudo apt install dnsutils

# RHEL, AlmaLinux, Rocky, Fedora
sudo dnf install bind-utils

# Alpine
apk add bind-tools

The Linux output uses tabs and shows the port after a hash sign:

$ nslookup example.com
Server:		127.0.0.53
Address:	127.0.0.53#53

Non-authoritative answer:
Name:	example.com
Address: 203.0.113.10

On Ubuntu, 127.0.0.53 is the local systemd-resolved stub, not a real upstream. Run resolvectl status to see where it forwards queries, or simply name an external server on the command line.

Querying a specific DNS server

The optional last argument is the server to ask. Checking one name against several resolvers is the fastest way to locate a DNS problem:

nslookup example.com 8.8.8.8
nslookup example.com 1.1.1.1
nslookup example.com 9.9.9.9

If a public resolver finds the name and your ISP resolver does not, the fault is on the ISP side or in its cache. If nobody finds it, the zone itself is broken: a missing record, a lapsed registration or a delegation error.

Getting an authoritative answer

To bypass every cache, ask the zone's own name servers. First list them, then query one directly:

nslookup -type=ns example.com
nslookup example.com ns1.example-dns.net

An authoritative reply has no "Non-authoritative answer" header. If the authoritative server already returns the new IP while public resolvers still show the old one, nothing is misconfigured — caches simply have not expired yet. Waiting out the TTL is the only fix; flushing your local cache as described in how to clear the DNS cache only helps on your own machine.

Looking up MX, TXT, NS, SOA and other records

Without options nslookup asks for A and AAAA. Use -type= (aliases: -query=, -q=) for anything else:

RecordCommandTypical use
A / AAAAnslookup example.comWebsite address, post-migration check
MXnslookup -type=mx example.comWhere the domain's mail is delivered
TXTnslookup -type=txt example.comSPF, verification tokens for Google, Microsoft and others
DMARCnslookup -type=txt _dmarc.example.comDMARC policy
DKIMnslookup -type=txt selector._domainkey.example.comSigning key; the selector comes from your mail provider
NSnslookup -type=ns example.comWhich servers host the zone
SOAnslookup -type=soa example.comPrimary server, serial number, zone timers
CNAMEnslookup -type=cname www.example.comWhere an alias points
PTRnslookup 203.0.113.10Host name behind an IP, mail server reverse DNS

An MX answer on Windows reads:

example.com     MX preference = 10, mail exchanger = mx1.example.com
example.com     MX preference = 20, mail exchanger = mx2.example.com

The lower preference wins. Linux prints the same data as mail exchanger = 10 mx1.example.com. For a deeper walkthrough of mail records, read how to check a domain's MX record; the purpose of each record type is covered in DNS record types explained.

Avoid -type=any as a diagnostic shortcut. Under RFC 8482 many servers answer ANY queries with a minimal response, so a record missing from that output proves nothing. Query each type on its own.

Reverse lookup: from IP to name

Pass an IP address instead of a name and nslookup performs a PTR query automatically:

C:\> nslookup 8.8.8.8
Server:  UnKnown
Address:  192.168.1.1

Name:    dns.google
Address:  8.8.8.8

The result is whatever the owner of the address block published in the reverse zone — one name, not a list of every site on that server. Mail servers need a correct PTR; without one, outgoing mail is frequently rejected or filtered.

Interactive mode

Run nslookup with no arguments to get a > prompt. Settings persist between queries, which saves typing when you check several records:

> server 1.1.1.1
> set type=txt
> example.com
> _dmarc.example.com
> set type=mx
> example.com
> set debug
> example.com
> exit
  • server address — switch the DNS server for subsequent queries;
  • set type= — record type (a, aaaa, mx, txt, ns, soa, cname, ptr);
  • set debug — print the full response, header flags and the TTL of every record;
  • set timeout=10, set retry=3 — wait time in seconds and number of retries;
  • set vc — use TCP instead of UDP;
  • exit — leave the prompt.

The same switches work on one line, for example nslookup -debug -type=mx example.com 8.8.8.8. The Windows-only ls command attempts a zone transfer (AXFR); any properly configured server refuses it, because an open transfer leaks every host name in the zone.

Common nslookup errors

Non-existent domain (NXDOMAIN)

Windows prints *** UnKnown can't find example.invalid: Non-existent domain; Linux prints ** server can't find example.invalid: NXDOMAIN. The server is certain the name does not exist. Look for a typo, an unregistered or expired domain, or a subdomain that was never created. Repeat the query against a public resolver and an authoritative server before blaming anything else.

DNS request timed out

DNS request timed out. timeout was 2 seconds. means no reply arrived in time; on Linux the equivalent is ;; connection timed out; no servers could be reached. Check that the server is reachable, that a firewall or security suite is not blocking outbound UDP port 53, and try another resolver. A timeout from one server only points at that server.

SERVFAIL

server can't find example.com: SERVFAIL means the resolver could not get a usable answer from the authoritative servers. Unreachable or mis-delegated name servers and broken DNSSEC signatures are the usual causes; if every resolver returns SERVFAIL, contact whoever hosts the domain's DNS.

No records of the requested type

No internal type for both IPv4 and IPv6 Addresses (A+AAAA) records available tells you the name exists but has no address records — for instance, a domain used only for email.

Unexpected suffixes in queries

On domain-joined Windows machines, nslookup may append the DNS search suffix, so debug output shows queries such as example.com.corp.local. Add a trailing dot — nslookup example.com. — to mark the name as fully qualified.

nslookup vs dig vs Resolve-DnsName

Tasknslookupdig (Linux, macOS)Resolve-DnsName (PowerShell)
Addressesnslookup example.comdig example.com +shortResolve-DnsName example.com
MX via 8.8.8.8nslookup -type=mx example.com 8.8.8.8dig @8.8.8.8 example.com MXResolve-DnsName example.com -Type MX -Server 8.8.8.8
Reverse lookupnslookup 8.8.8.8dig -x 8.8.8.8Resolve-DnsName 8.8.8.8
TTL shownonly with -debugalwaysalways (TTL column)
Trace delegation from rootnodig +trace example.comno
Uses hosts file and cachenonoyes; -DnsOnly turns it off

A reasonable split: nslookup for a quick check on any machine, dig when you need response flags, TTLs and delegation tracing, Resolve-DnsName inside PowerShell scripts where results are objects you can filter. Full option lists are in the Microsoft nslookup reference and the Resolve-DnsName documentation; the DNS message format itself is defined in RFC 1035.

nslookup, ping and traceroute together

These three commands answer different questions. nslookup: what does the name resolve to? ping: does that host respond, and how fast? traceroute (tracert on Windows): which routers do packets cross, and where do they stop? Work in that order — confirm the name resolves to the right address, ping that address, then trace the route if it does not answer. Reading traceroute output explains the last step.

How to check DNS online

A terminal shows only what your own network sees. To check a domain from outside, from a phone, or across several regions at once:

  • DNS Lookup — an nslookup online equivalent returning A, AAAA, MX, NS, TXT, CNAME and SOA in one request;
  • DNS propagation checker — compares answers from public resolvers worldwide and shows where an old address still lingers;
  • Ping — reachability of the host once you know its address.

Frequently asked questions

Is "Non-authoritative answer" an error?

No. It only says the reply came from a caching resolver rather than the zone's own name server. Query an NS server of the domain directly to get an authoritative answer.

Why does nslookup show a different IP than my browser uses?

On Windows, nslookup skips the hosts file and the DNS Client cache. Check the hosts file, run ipconfig /flushdns, and see whether the browser uses its own DNS over HTTPS setting.

How do I see the TTL of a record?

Add -debug: nslookup -debug example.com. Each record in the ANSWERS section shows its remaining TTL in seconds. dig shows TTL by default.

How do I test whether a DNS server works?

Query it explicitly: nslookup example.com 192.168.1.1. A fast reply that matches a public resolver means the server is healthy; a timeout or empty reply means it is not.

Can I run nslookup on a phone?

Android and iOS have no built-in command. An online DNS lookup gives the same result as nslookup against a public resolver.

Check your website right now

Check your site's DNS →
More articles: DNS
DNS
Best Public DNS Servers 2026: Fastest, Safest, IPv4 & IPv6
21.07.2026 · 1 702 views
DNS
How to Flush DNS Cache: Windows, Mac, Linux, Browsers
15.04.2026 · 1 132 views
DNS
MX Records for Email: Step-by-Step Setup Guide
15.04.2026 · 1 064 views
DNS
DNS Not Resolving: 8 Causes and How to Fix
15.04.2026 · 948 views