📝 DNS TXT Record Lookup
Query DNS TXT records to retrieve text records associated with any domain. TXT records are commonly used for domain verification, SPF, DKIM, and DMARC authentication.
What a TXT record is for
TXT is the DNS record type that holds free-form text. It was never designed for any particular job, which is exactly why it ended up carrying most of them: if a service needs to confirm that you control a domain, or publish a policy other machines should read, it asks you to put a string in a TXT record.
Enter a domain above and this tool queries its TXT records and prints what is published. Everything it shows is public — TXT records are readable by anyone, which is worth remembering before putting anything in one.
What you will usually find
| Starts with | What it is |
|---|---|
v=spf1 | SPF — which servers may send mail as this domain |
v=DMARC1 | DMARC policy, published at _dmarc.yourdomain |
v=DKIM1 | A DKIM public key, on a selector subdomain |
google-site-verification= | Google Search Console domain ownership |
MS=, facebook-domain-verification= | Ownership proofs for other services |
Verification strings are the most common thing in a TXT record and the least interesting: they prove control of the domain and do nothing else. Leave them in place, because removing one un-verifies the service that asked for it.
Two rules that catch people out
One SPF record, not several
A domain may publish only one v=spf1 record. Two is not
twice as much protection — it is a permanent error, and receiving mail
servers treat the result as unusable. When you add a new sending service,
merge its include: into the existing record rather than
publishing a second one.
DMARC and DKIM are not on the root
Looking up the bare domain will not show them. DMARC lives at
_dmarc.yourdomain.com, and each DKIM key lives at
selector._domainkey.yourdomain.com, where the selector is
whatever your mail provider chose. Query those names directly.
When a record does not appear
- Propagation. A new record is limited by the previous answer’s TTL. If the old TTL was 3600, expect up to an hour.
- Quotes and length. A single TXT string cannot exceed 255 characters. Long DKIM keys are split into several quoted chunks that are joined back together on reading — that is correct, not broken.
- The wrong name. Adding a record for
@versusyourdomain.comversusyourdomain.com.behaves differently in different control panels. A trailing dot matters.
Frequently asked questions
How long does a new TXT record take to appear?
Up to the TTL of the previous answer, commonly a few minutes to an hour. Lowering the TTL before making a change shortens the wait next time, but it has no effect on the change you already made.
Can I have more than one TXT record?
Yes, and most domains do — verification strings, SPF and others sit side
by side. The exception is SPF: only one v=spf1 record is
allowed, and a second one breaks both.
Why can I not see my DMARC record?
Because it is not on the root domain. Query
_dmarc.yourdomain.com instead — that underscore name is where
DMARC is defined to live.
Is it safe to leave old verification records in place?
Harmless technically, but tidy them up when you stop using a service. They are public, so they quietly advertise which platforms you use.
Why is my DKIM record split into pieces?
Because one TXT string is capped at 255 characters and DKIM keys are longer. The chunks are concatenated when the record is read, so a split key is normal and working.