Skip to Main Content
Back to ResourcesEmail News

DNS TXT Record Lookup: dig, nslookup & Online Tools

Johanie DupontBy Johanie DupontAugust 9, 2023Updated September 16, 20269 min read

In brief

Look up DNS TXT records with dig, nslookup, PowerShell, or our free online checker. Find and interpret SPF, DKIM, DMARC, BIMI, and verification records.

A DNS TXT record lookup returns the text records published at one exact DNS name, which is how you read SPF, DKIM, and DMARC values for a domain. The fastest options are:

  • Browser: enter the hostname in the free TXT record lookup (embedded below). It returns only the TXT records and labels each one as SPF, DMARC, DKIM, BIMI or a verification token.
  • macOS or Linux: run dig TXT example.com.
  • Windows: run nslookup -type=TXT example.com or Resolve-DnsName -Name example.com -Type TXT in PowerShell.
For email authentication, the hostname matters as much as the record type. SPF is usually published at the sending domain, DMARC at _dmarc.example.com, DKIM at selector._domainkey.example.com, and BIMI at default._bimi.example.com.

Run a DNS TXT lookup online

The embedded Palisade TXT record lookup above reads public DNS without a terminal. Enter the full hostname you need to inspect, such as _dmarc.example.com, and run the lookup. Each string comes back labelled by the protocol or service that reads it, and one-click links look up the related hosts (_dmarc, default._bimi, _mta-sts) for the same domain. For every other record type, the DNS lookup tool queries A, AAAA, CNAME, MX, NS, TXT, SOA, CAA and SRV together.

A lookup reads public DNS. It does not change the domain, prove that a production message was signed correctly, or show a private mailbox provider decision.

DNS TXT lookup commands you can copy

macOS and Linux with dig

Query TXT records at the root domain:

Terminalbash
dig TXT example.com

Return a shorter answer without the surrounding DNS response:

Terminalbash
dig +short TXT example.com

Query the most common email-security TXT records:

Terminalbash
dig +short TXT _dmarc.example.com
dig +short TXT selector1._domainkey.example.com
dig +short TXT default._bimi.example.com
dig +short TXT _smtp._tls.example.com

Replace selector1 with the selector that names the sending service's signing key. A generic DKIM lookup cannot discover every selector; the selector normally comes from the provider's setup instructions or a real message header.

To compare a specific resolver with your default resolver, add its IP address:

Terminalbash
dig +short TXT _dmarc.example.com @1.1.1.1
dig +short TXT _dmarc.example.com @8.8.8.8

Windows with nslookup

Run a one-line TXT query in Command Prompt or PowerShell:

Technical exampletext
nslookup -type=TXT example.com

Query a DMARC hostname through Cloudflare's public resolver:

Technical exampletext
nslookup -type=TXT _dmarc.example.com 1.1.1.1

You can also open the interactive nslookup prompt:

Technical exampletext
nslookup
set type=TXT
_dmarc.example.com

Type exit when you are finished.

Windows with PowerShell

PowerShell returns structured DNS output that is easier to filter or reuse in a script:

POWERSHELLpowershell
Resolve-DnsName -Name example.com -Type TXT

For DMARC:

POWERSHELLpowershell
Resolve-DnsName -Name _dmarc.example.com -Type TXT

If your system resolver appears stale, specify another DNS server:

POWERSHELLpowershell
Resolve-DnsName -Name _dmarc.example.com -Type TXT -Server 1.1.1.1

Which hostname should you query?

RecordTypical hostnameValue usually starts with
SPFexample.comv=spf1
DKIMselector._domainkey.example.comv=DKIM1 or a public key
DMARC_dmarc.example.comv=DMARC1
BIMIdefault._bimi.example.comv=BIMI1
TLS reporting_smtp._tls.example.comv=TLSRPTv1
Service verificationProvider-specificA token supplied by the provider

The root domain is not a universal shortcut. Querying example.com can reveal SPF and verification tokens, but it will not normally return DMARC, DKIM, or BIMI because those records use dedicated hostnames.

How to read the result

Read an nslookup TXT record answer

For nslookup -type=TXT _dmarc.example.com, an answer can look like this simplified example. These are illustrative values, not a live result for example.com:

Technical exampletext
Non-authoritative answer:
_dmarc.example.com   text =
        "v=DMARC1; p=none; rua=mailto:reports@example.com"

The name before text = is the queried hostname; the quoted text is its TXT value. “Non-authoritative” means the answer came from a recursive resolver rather than directly from the domain's authoritative nameserver. It does not by itself mean the record is wrong or unverified. Use the nslookup command reference to select a specific DNS server when comparing answers.

Read a dig TXT record answer

Run dig TXT _dmarc.example.com without +short when you need the response status and TTL. This illustrative excerpt shows one successful answer:

Technical exampletext
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 12345
;; ANSWER SECTION:
_dmarc.example.com.  300  IN  TXT  "v=DMARC1; p=none"

Read the answer row as hostname → TTL in seconds → DNS class → record type → value. Here, 300 is the returned cache lifetime and TXT is the type. NOERROR means the DNS query completed without a protocol error; it does not validate the DMARC policy or prove that an email passes authentication. The BIND dig reference documents the full response and the terse +short option.

Quoted strings may be one logical record

DNS software can split a long TXT value into several quoted character strings. Tools may display an SPF or DKIM record as two adjacent quoted sections even though DNS returns one logical TXT record. Join the strings in order before interpreting the value.

An empty answer is different from an error

  • NOERROR with no TXT answer: the lookup can succeed without finding that record type at the queried name. Inspect the full response and any CNAME chain before concluding a TXT record is absent.
  • NXDOMAIN: the queried hostname does not exist.
  • SERVFAIL: the resolver could not complete the lookup, often because of a DNS or DNSSEC problem.
  • Timeout: the resolver or network did not answer in time.
A blank dig +short result alone does not distinguish these cases. Rerun dig TXT _dmarc.example.com without +short, replacing _dmarc.example.com with your exact hostname. Read the status before assuming a record is missing.

TTL explains part of propagation

The time to live (TTL) tells recursive resolvers how long they may cache an answer. After you change a TXT record, one resolver can show the new value while another still serves the cached value. Compare more than one public resolver and the authoritative nameserver before declaring propagation complete.

Missing records can also be cached: RFC 2308 defines negative caching for NXDOMAIN and no-data answers. Adding a previously absent record does not immediately clear those cached answers.

Use the DNS propagation guide for a step-by-step comparison.

How to interpret email-authentication TXT records

SPF

An SPF record starts with v=spf1 and lists mechanisms that authorize sending infrastructure. A domain must not publish multiple SPF records at the same hostname; use the SPF checker to inspect syntax and the DNS-lookup chain.

DKIM

A DKIM record is tied to a selector. The query name looks like selector._domainkey.example.com. DNS can show the published public key, but only a real signed message proves which selector and signing domain the production stream used. The DKIM checker is useful once you know the selector.

DMARC

A DMARC record starts with v=DMARC1 and is published at _dmarc.example.com. Read the p= policy, reporting addresses, and alignment tags. The DMARC checker validates the public record and explains each state.

BIMI

A BIMI record starts with v=BIMI1 and is normally published at default._bimi.example.com. It points to the logo and, when used, certificate evidence. Use the BIMI checker to validate the public record, but remember that each mailbox provider applies its own display criteria.

Troubleshoot a TXT record that is missing or stale

Work through these checks in order:

  1. Confirm the full hostname. _dmarc, _domainkey, and _bimi are not interchangeable.
  2. Check the provider's host-field convention. Some DNS panels want only _dmarc; others want _dmarc.example.com. Entering the full domain when the panel appends it automatically can create _dmarc.example.com.example.com.
  3. Check authoritative DNS. Make sure you edited the DNS zone used by the domain's current nameservers, not an old registrar panel.
  4. Compare resolvers. Query your default resolver, 1.1.1.1, and 8.8.8.8.
  5. Wait out the previous TTL. Lowering the TTL after a change does not erase answers already cached under the old TTL.
  6. Look for duplicates. Multiple SPF or DMARC records at the same hostname can invalidate evaluation even though the lookup returns text.
  7. Preserve exact punctuation. Missing semicolons, smart quotes, copied line breaks, or an incorrect hostname can make a record unusable.

Evidence

Sources and further reading

Check the full public email-security posture

Use the Email Security Score when you want one public-domain assessment across DMARC, SPF, DKIM, BIMI, MX, MTA-STS, and TLS-RPT. It is a point-in-time DNS assessment, not continuous monitoring or proof of inbox placement.

Questions readers ask

Frequently asked questions

How do I look up a TXT record for a domain?

Run dig TXT example.com on macOS or Linux, nslookup -type=TXT example.com on Windows, or use the browser-based TXT record lookup. Replace the root domain with the full protocol hostname when checking DMARC, DKIM, BIMI, or TLS-RPT.

Can I find every TXT record used by a domain?

A TXT query returns the TXT records at the exact hostname you enter. It does not enumerate TXT records on other names such as _dmarc.example.com, DKIM selector names, BIMI names, or provider-created subdomains. Query each known hostname separately.

Why does my TXT record show multiple quoted sections?

DNS permits one TXT record to contain multiple character strings. Many tools display those strings separately. Join them in order before reading a long SPF or DKIM value.

Why can one DNS checker see my new record while another cannot?

DNS checkers can show different TXT values because their recursive resolvers cache answers according to TTL and may refresh at different times. Compare public resolvers and the authoritative nameserver, then wait until the previous cached answer expires.

Can a TXT lookup confirm that email authentication passes?

A TXT lookup can confirm what public DNS currently publishes. It cannot prove that a particular message used the expected Return-Path, DKIM selector, signing domain, or aligned identity. Use a real message header or the email deliverability test for message-path evidence.

Is a TXT record private?

Standard DNS TXT records are publicly queryable. Do not publish passwords, private keys, or secrets in them.

Read the TXT records that are actually published

Enter the domain, or the exact hostname such as _dmarc.yourdomain.com.

Look up TXT recordsGet started

Share this article

Johanie Dupont

Written by

Johanie Dupont

Brand & Ecommerce Email

Johanie Dupont works on brand and ecommerce email at Palisade: BIMI and verified marks, sender requirements, and getting marketing mail into the inbox.

More from Johanie →

Related articles and tools