DNS TXT Record Lookup: dig, nslookup & Online Tools
In brief
Look up DNS TXT records with dig, nslookup, PowerShell, or our free online checker. Find and interpret SPF, DKIM, DMARC, BIMI, and verification records.
A DNS TXT record lookup returns the text records published at one exact DNS name, which is how you read SPF, DKIM, and DMARC values for a domain. The fastest options are:
- Browser: enter the hostname in the free TXT record lookup (embedded below). It returns only the TXT records and labels each one as SPF, DMARC, DKIM, BIMI or a verification token.
- macOS or Linux: run
dig TXT example.com. - Windows: run
nslookup -type=TXT example.comorResolve-DnsName -Name example.com -Type TXTin PowerShell.
_dmarc.example.com, DKIM at selector._domainkey.example.com, and BIMI at default._bimi.example.com.
Run a DNS TXT lookup online
The embedded Palisade TXT record lookup above reads public DNS without a terminal. Enter the full hostname you need to inspect, such as _dmarc.example.com, and run the lookup. Each string comes back labelled by the protocol or service that reads it, and one-click links look up the related hosts (_dmarc, default._bimi, _mta-sts) for the same domain. For every other record type, the DNS lookup tool queries A, AAAA, CNAME, MX, NS, TXT, SOA, CAA and SRV together.
A lookup reads public DNS. It does not change the domain, prove that a production message was signed correctly, or show a private mailbox provider decision.
DNS TXT lookup commands you can copy
macOS and Linux with dig
Query TXT records at the root domain:
dig TXT example.comReturn a shorter answer without the surrounding DNS response:
dig +short TXT example.comQuery the most common email-security TXT records:
dig +short TXT _dmarc.example.com
dig +short TXT selector1._domainkey.example.com
dig +short TXT default._bimi.example.com
dig +short TXT _smtp._tls.example.comReplace selector1 with the selector that names the sending service's signing key. A generic DKIM lookup cannot discover every selector; the selector normally comes from the provider's setup instructions or a real message header.
To compare a specific resolver with your default resolver, add its IP address:
dig +short TXT _dmarc.example.com @1.1.1.1
dig +short TXT _dmarc.example.com @8.8.8.8Windows with nslookup
Run a one-line TXT query in Command Prompt or PowerShell:
nslookup -type=TXT example.comQuery a DMARC hostname through Cloudflare's public resolver:
nslookup -type=TXT _dmarc.example.com 1.1.1.1You can also open the interactive nslookup prompt:
nslookup
set type=TXT
_dmarc.example.comType exit when you are finished.
Windows with PowerShell
PowerShell returns structured DNS output that is easier to filter or reuse in a script:
Resolve-DnsName -Name example.com -Type TXTFor DMARC:
Resolve-DnsName -Name _dmarc.example.com -Type TXTIf your system resolver appears stale, specify another DNS server:
Resolve-DnsName -Name _dmarc.example.com -Type TXT -Server 1.1.1.1Which hostname should you query?
| Record | Typical hostname | Value usually starts with |
|---|---|---|
| SPF | example.com | v=spf1 |
| DKIM | selector._domainkey.example.com | v=DKIM1 or a public key |
| DMARC | _dmarc.example.com | v=DMARC1 |
| BIMI | default._bimi.example.com | v=BIMI1 |
| TLS reporting | _smtp._tls.example.com | v=TLSRPTv1 |
| Service verification | Provider-specific | A token supplied by the provider |
The root domain is not a universal shortcut. Querying example.com can reveal SPF and verification tokens, but it will not normally return DMARC, DKIM, or BIMI because those records use dedicated hostnames.
How to read the result
Read an nslookup TXT record answer
For nslookup -type=TXT _dmarc.example.com, an answer can look like this simplified example. These are illustrative values, not a live result for example.com:
Non-authoritative answer:
_dmarc.example.com text =
"v=DMARC1; p=none; rua=mailto:reports@example.com"The name before text = is the queried hostname; the quoted text is its TXT value. “Non-authoritative” means the answer came from a recursive resolver rather than directly from the domain's authoritative nameserver. It does not by itself mean the record is wrong or unverified. Use the nslookup command reference to select a specific DNS server when comparing answers.
Read a dig TXT record answer
Run dig TXT _dmarc.example.com without +short when you need the response status and TTL. This illustrative excerpt shows one successful answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 12345
;; ANSWER SECTION:
_dmarc.example.com. 300 IN TXT "v=DMARC1; p=none"Read the answer row as hostname → TTL in seconds → DNS class → record type → value. Here, 300 is the returned cache lifetime and TXT is the type. NOERROR means the DNS query completed without a protocol error; it does not validate the DMARC policy or prove that an email passes authentication. The BIND dig reference documents the full response and the terse +short option.
Quoted strings may be one logical record
DNS software can split a long TXT value into several quoted character strings. Tools may display an SPF or DKIM record as two adjacent quoted sections even though DNS returns one logical TXT record. Join the strings in order before interpreting the value.
An empty answer is different from an error
- NOERROR with no TXT answer: the lookup can succeed without finding that record type at the queried name. Inspect the full response and any CNAME chain before concluding a TXT record is absent.
- NXDOMAIN: the queried hostname does not exist.
- SERVFAIL: the resolver could not complete the lookup, often because of a DNS or DNSSEC problem.
- Timeout: the resolver or network did not answer in time.
dig +short result alone does not distinguish these cases. Rerun dig TXT _dmarc.example.com without +short, replacing _dmarc.example.com with your exact hostname. Read the status before assuming a record is missing.
TTL explains part of propagation
The time to live (TTL) tells recursive resolvers how long they may cache an answer. After you change a TXT record, one resolver can show the new value while another still serves the cached value. Compare more than one public resolver and the authoritative nameserver before declaring propagation complete.
Missing records can also be cached: RFC 2308 defines negative caching for NXDOMAIN and no-data answers. Adding a previously absent record does not immediately clear those cached answers.
Use the DNS propagation guide for a step-by-step comparison.
How to interpret email-authentication TXT records
SPF
An SPF record starts with v=spf1 and lists mechanisms that authorize sending infrastructure. A domain must not publish multiple SPF records at the same hostname; use the SPF checker to inspect syntax and the DNS-lookup chain.
DKIM
A DKIM record is tied to a selector. The query name looks like selector._domainkey.example.com. DNS can show the published public key, but only a real signed message proves which selector and signing domain the production stream used. The DKIM checker is useful once you know the selector.
DMARC
A DMARC record starts with v=DMARC1 and is published at _dmarc.example.com. Read the p= policy, reporting addresses, and alignment tags. The DMARC checker validates the public record and explains each state.
BIMI
A BIMI record starts with v=BIMI1 and is normally published at default._bimi.example.com. It points to the logo and, when used, certificate evidence. Use the BIMI checker to validate the public record, but remember that each mailbox provider applies its own display criteria.
Troubleshoot a TXT record that is missing or stale
Work through these checks in order:
- Confirm the full hostname.
_dmarc,_domainkey, and_bimiare not interchangeable. - Check the provider's host-field convention. Some DNS panels want only
_dmarc; others want_dmarc.example.com. Entering the full domain when the panel appends it automatically can create_dmarc.example.com.example.com. - Check authoritative DNS. Make sure you edited the DNS zone used by the domain's current nameservers, not an old registrar panel.
- Compare resolvers. Query your default resolver,
1.1.1.1, and8.8.8.8. - Wait out the previous TTL. Lowering the TTL after a change does not erase answers already cached under the old TTL.
- Look for duplicates. Multiple SPF or DMARC records at the same hostname can invalidate evaluation even though the lookup returns text.
- Preserve exact punctuation. Missing semicolons, smart quotes, copied line breaks, or an incorrect hostname can make a record unusable.
Evidence
Sources and further reading
- RFC 2308: Negative caching of DNS queries
- RFC 1035: Domain names — implementation and specification
- BIND 9
digcommand reference - Microsoft
nslookupcommand reference - Microsoft
Resolve-DnsNamereference - RFC 7208: Sender Policy Framework
- RFC 6376: DomainKeys Identified Mail
- RFC 9989: Domain-based Message Authentication, Reporting, and Conformance
Check the full public email-security posture
Use the Email Security Score when you want one public-domain assessment across DMARC, SPF, DKIM, BIMI, MX, MTA-STS, and TLS-RPT. It is a point-in-time DNS assessment, not continuous monitoring or proof of inbox placement.
Questions readers ask
Frequently asked questions
How do I look up a TXT record for a domain?
Run dig TXT example.com on macOS or Linux, nslookup -type=TXT example.com on Windows, or use the browser-based TXT record lookup. Replace the root domain with the full protocol hostname when checking DMARC, DKIM, BIMI, or TLS-RPT.
Can I find every TXT record used by a domain?
A TXT query returns the TXT records at the exact hostname you enter. It does not enumerate TXT records on other names such as _dmarc.example.com, DKIM selector names, BIMI names, or provider-created subdomains. Query each known hostname separately.
Why does my TXT record show multiple quoted sections?
DNS permits one TXT record to contain multiple character strings. Many tools display those strings separately. Join them in order before reading a long SPF or DKIM value.
Why can one DNS checker see my new record while another cannot?
DNS checkers can show different TXT values because their recursive resolvers cache answers according to TTL and may refresh at different times. Compare public resolvers and the authoritative nameserver, then wait until the previous cached answer expires.
Can a TXT lookup confirm that email authentication passes?
A TXT lookup can confirm what public DNS currently publishes. It cannot prove that a particular message used the expected Return-Path, DKIM selector, signing domain, or aligned identity. Use a real message header or the email deliverability test for message-path evidence.
Is a TXT record private?
Standard DNS TXT records are publicly queryable. Do not publish passwords, private keys, or secrets in them.
Read the TXT records that are actually published
Enter the domain, or the exact hostname such as _dmarc.yourdomain.com.

Written by
Johanie DupontBrand & Ecommerce Email
Johanie Dupont works on brand and ecommerce email at Palisade: BIMI and verified marks, sender requirements, and getting marketing mail into the inbox.
More from Johanie →


