Authoritative DNS evidence

TXT Record Lookup

Read complete TXT values, reconstruct quoted chunks, compare authoritative answers, and inspect TTL, DNSSEC, SPF, DMARC, DKIM, and verification clues without treating a lookup as a full policy audit.

  • Complete TXT values
  • Authority agreement and TTLs
  • SPF, DKIM, and DMARC clues
  • DNSSEC and raw evidence

Query a public DNS name

Paste a hostname or URL. Internationalized names are converted to their DNS form; paths, ports, and a trailing dot are normalized.

Use the exact record name for service verification, or choose a shortcut for DMARC or DKIM.

Comparison is case-sensitive. Pasted zone-file chunks such as "part one" "part two" are joined before matching.

Advanced query controls

This resolver helps discover delegation and contributes a DNSSEC claim. TXT answers are still queried directly from authoritative servers.

The lookup sends the normalized public DNS name to Octetify’s same-origin analyzer. Standard analyses have a 12-second service budget, protocol analyses 25 seconds, and may return partial evidence. Capacity limits or upstream DNS failures can require a retry. Results are live but DNS authorities, resolver caches, and DNSSEC validators can legitimately disagree.

Standards-aware, not a protocol certification

Chunk reconstruction follows RFC 1035. Format clues reference SPF (RFC 7208), DKIM (RFC 6376), and DMARC (RFC 9989). This tool does not recursively evaluate SPF, verify a DKIM signature/key pair, or simulate a receiver’s full DMARC decision.