Skip to content

NS lookup: nameserver check

Enter a domain to see which nameservers answer for it, and therefore which DNS provider controls its records. The result compares four public resolvers with the zone's own NS list and flags domains that rely on a single nameserver.

What an NS record is

NS records name the authoritative nameservers for a domain, the servers that hold its real A, MX, TXT, and other records. They exist in two places. The parent zone, run by the registry for .com, .org, and so on, holds the delegation that you set at your registrar. The zone itself publishes its own NS records at your DNS provider. Resolvers follow the parent's delegation first, so the nameservers set at your registrar decide which provider's records the world actually sees.

When a domain's nameservers sit inside the domain itself, such as ns1.example.com serving example.com, resolvers would need example.com to find the server for example.com. Glue records break that loop: the registry stores the nameservers' IP addresses alongside the delegation. Registrars usually call this registering child nameservers or host records. The DNS standards ask for at least two nameservers per zone (RFC 1034), ideally on separate networks (RFC 2182), so one outage does not take the whole domain offline.

Example NS records

  • example.com. 86400 IN NS ns1.dns-provider.net. example.com. 86400 IN NS ns2.dns-provider.net.

    Two nameservers at a hosted DNS provider. All of the domain's other records are managed in that provider's dashboard.

  • example.com. 86400 IN NS ns1.example.com. ns1.example.com. 86400 IN A 192.0.2.53

    A nameserver inside its own domain. It only works if the registrar also holds a glue record with the address 192.0.2.53.

How to read your result

The hostnames identify your DNS provider
The nameserver names usually reveal who hosts your DNS. That provider is the only place where edits to your other records take effect. Compare the list with the nameservers shown at your registrar, and they should be the same set.
The source-of-truth row
This row shows the NS records the zone publishes about itself, read directly from its first nameserver. If it lists different servers from your registrar, the zone's own NS records are out of date. Update them at your DNS provider to match the delegation.
The single-nameserver warning
If only one nameserver comes back, the result flags it. That server is a single point of failure: if it goes down, every record on the domain stops resolving.
Subdomains usually return nothing
A lookup of www.example.com normally finds no NS records, because subdomains are part of the parent zone unless they have been delegated on purpose. Enter the bare domain to see its nameservers.

Common NS record problems

Records edited at the wrong provider
It is common to have DNS settings at both a registrar and a host, but only the provider named in the NS records is used. If your changes have no effect, check the nameservers here, then make the edit in that provider's dashboard.
Lame delegation
A listed nameserver does not actually serve the zone, often because the old provider deleted the zone after a move, or because of a typo at the registrar. Resolvers that try it get no useful answer, so lookups slow down or fail intermittently. Remove every nameserver from the registrar that is not set up to answer for the domain.
Missing or stale glue
If you run nameservers inside your own domain and their IP addresses change, the registry keeps the old addresses until you update the glue at your registrar. Until then, resolvers try to reach the nameservers at addresses that no longer work.
DNSSEC left on during a provider change
If the domain has a DS record at the registrar and you switch to a provider that signs with different keys, or not at all, validating resolvers reject every answer and the domain stops resolving for their users. Disable DNSSEC or migrate the keys before changing nameservers, then turn it back on at the new provider.
Only one nameserver, or both on one network
Two nameserver names that share one server or one network fail together. Use the full set your DNS provider assigns, or add a secondary DNS service on a separate network.

Other record lookups

Frequently asked questions

How do I find out who my DNS provider is?

Run an NS lookup on your bare domain. The nameserver hostnames usually include the provider's name or domain. Your DNS records are managed there, which may be a different company from your registrar or your web host.

How long does a nameserver change take?

The registry usually publishes the change quickly, but resolvers that cached the old delegation keep using it until its TTL expires. For .com and .net, the delegation TTL is two days, so leave the zone at the old provider intact and unchanged for at least that long.

What is the difference between nameservers and DNS records?

Nameservers are the servers that answer questions about your domain. DNS records, such as A, MX, and TXT, are the answers they give. NS records connect the two by telling resolvers which servers to ask.

Do I need to change nameservers to point my domain to a new host?

No. You can keep your current DNS provider and only change the A, AAAA, or MX records. Changing nameservers moves the whole zone, so every record must be recreated at the new provider first, or the domain loses them when the switch takes effect.

How many nameservers should a domain have?

At least two. That is what the DNS standards ask for, and many registries refuse a delegation with fewer. Use every nameserver your DNS provider assigns. Adding more only improves resilience if they run on separate networks.