How to look up a DNS TXT record
A TXT record stores text at a specific DNS hostname. Email authentication and domain verification commonly use them, but the hostname matters as much as the value. Looking up example.com will not show a DKIM key stored at selector._domainkey.example.com.
Open the DevDecode DNS Lookup, enter the exact hostname, choose TXT only, then select Lookup. The tool queries Google Public DNS through its DNS over HTTPS API. It shows that resolver's answer, including the TTL. It does not query every resolver worldwide.
| What you need | Hostname to query | Example result |
|---|---|---|
| SPF policy | example.com |
"v=spf1 include:_spf.example.net -all" |
| DKIM key | selector._domainkey.example.com |
"v=DKIM1; k=rsa; p=..." |
| DMARC policy | _dmarc.example.com |
"v=DMARC1; p=reject" |
| Domain ownership token | Usually example.com, but follow the service's instructions |
"google-site-verification=..." |
These are illustrative values, not settings to copy into your zone. Use the exact host and value supplied by your email or verification provider.
Check an SPF record
Enter the domain used in the email's envelope sender, such as example.com, and select TXT. Find the value starting with v=spf1. RFC 7208 defines SPF records as DNS TXT records. A domain should publish no more than one SPF policy at that name; multiple v=spf1 records can cause evaluation errors.
Some DNS providers split one long TXT record into several quoted character strings. Those strings belong to one TXT record and are concatenated for SPF evaluation without inserting spaces. Keep this distinction separate from several distinct TXT records. This lookup displays the resolver's TXT presentation form, including quotes, to avoid silently altering the answer.
Check a DKIM key
Find the selector in your email provider's setup instructions or in an email's DKIM-Signature header (s=selector). Query selector._domainkey.example.com, replacing both parts with your actual selector and domain. A DKIM TXT result commonly begins v=DKIM1 and includes a public key in p=. The DKIM specification, RFC 6376, defines the selector lookup and key record.
The selector is not optional: querying only _domainkey.example.com usually misses the key. Some providers use a CNAME at the selector hostname instead; if TXT returns nothing, check CNAME and the provider's instructions.
Check a verification record
Copy the host/name and value from the service asking you to verify ownership. For example, a service may ask for a TXT token at the root domain, or an ACME challenge at _acme-challenge.example.com. Enter that exact full hostname in the lookup. Check that your DNS provider did not append the domain twice when you entered a fully qualified name.
If the expected record is absent:
- Confirm you edited the DNS zone used by the domain's authoritative nameservers. An unused provider dashboard will not affect live DNS.
- Query the exact hostname and TXT type. For DKIM and DMARC, include the underscore labels.
- Compare the authoritative nameserver's answer with Google Public DNS. A recent change may still be cached at a recursive resolver until an earlier TTL expires.
- Check the full value, including spaces and punctuation, against the provider's required token. A TXT display may include quotes around DNS character strings.
There is no guaranteed global “propagation time.” TTLs and resolver behavior determine when cached answers refresh. For the meaning of A, MX, CNAME, TXT, and other record types, see DNS record types explained.