dnstrace.dev
live sources

Domain & IP intelligence

See where anything
on the internet lives.

DNS, ownership, hosting, ASN, location and security signals, resolved into one readable lookup.

Try
Your connection
Detecting… Checking IPv4
Locating network Checking provider

What the result means

See where anything on the internet lives.

DNSTrace.dev connects answers from DNS, regional registries, public routing data, certificate transparency and live HTTPS responses. Results distinguish observed evidence from inference, so a CDN edge is never presented as a hidden origin server.

  • Domain and IP reports
  • Worldwide DNS probes
  • Machine-readable JSON API

Diagnostic field guide

Use the evidence, not the guess.

Three practical ways to use this lookup, followed by the boundary the result cannot cross.

Reviewed Sep 2026
01

Plan a migration

Capture DNS, mail, certificate and routing evidence before a provider or nameserver change.

02

Verify a vendor

Separate the DNS operator, public delivery edge, mail provider and network announcer instead of treating them as one company.

03

Start incident triage

Check whether a failure begins at resolution, registration, routing, TLS, HTTP or email policy.

How to read the result

  1. Resolve the submitted name or address and confirm that it exists publicly.
  2. Read each layer independently: DNS, registration, routing, web delivery and security.
  3. Use the evidence labels and source status before drawing a conclusion about an operator.

Common questions

Before you act on the result

What can one domain lookup reveal?

A domain can expose DNS records, registry data, mail routes, certificate evidence, public web responses and the networks announcing its resolved addresses. Each signal describes a different layer.

Does DNSTrace.dev scan the target for vulnerabilities?

No. It reads public records and ordinary public responses. It does not attempt exploitation, port scanning, authentication or access to private systems.

Quiet by design

Look up the internet.
Leave less behind.

Public infrastructure research should not require a private profile. DNSTrace keeps only the operational signals needed to run a reliable, fair service.

Read the privacy approach
No ad tracking

No ad pixels, cross-site profiles or sale of lookup history.

Necessary metrics only

Uptime, latency and failure signals, plus cookieless visit counts on our own server.

Fair-use limits active

30 requests/min · 6 heavy checks/min

Choose the question

One system, fourteen focused tools.

Each tool has its own indexable page and opens the report at the evidence that answers its question.

Evidence before certainty

The internet has layers.
We keep them separate.

A nameserver identifies the DNS operator. An edge address identifies a public delivery network. An ASN identifies the organization announcing a route. None automatically proves where a hidden origin application runs.

ObservedCorrelatedUnknown stays unknown
Read the detection methodology

Field notes

Read the signal correctly.

All guides

Agent-ready JSON

Give your script or your AI the same public evidence.

GET /api/dns?target=example.com&type=MX
API reference llms.txt

One input, several sources

What a full lookup includes

DNSTrace.dev resolves published DNS answers, follows the primary address to its network owner, and reads registry data for the domain or IP. Your own IP is detected separately and only when this page is open.

DNSRDAPASNGeo IP

Your public network address

What is “My IP”?

Your public IP is the address websites see for your internet connection. It is assigned by your ISP, mobile carrier, workplace, VPN, or proxy and is used to route traffic back to you.

Why it is useful Diagnose your connection

Inspect your ISP, ASN, approximate network location, reverse DNS, and whether traffic is passing through a VPN or hosting network.

What it cannot reveal Not your exact location

IP location usually identifies a city or network region. It does not expose your home address or your device's GPS position.

Privacy Relay-aware, not bypassing

The primary address comes from Cloudflare. An IPv4-only check uses ipify with icanhazip as fallback. Apple Private Relay is verified against Apple's published egress ranges. The original address hidden by a relay cannot be recovered.

Copied