Skip to content
fixyour.page

TXT Record Lookup

List and classify every TXT record on a domain.

Your data stays in your browser
Enter a domain to list its TXT records. Queries go straight from your browser to Cloudflare's public DNS resolver, never to our servers.

How to Look Up TXT Records

Type a domain and hit Check. The tool queries Cloudflare's public DNS resolver over HTTPS, straight from your browser, and lists every TXT record it finds. Each record gets classified: SPF, DKIM, DMARC, or one of two dozen known verification token formats. Records split across 255-character strings are joined for you, the way mail servers and verifiers actually read them.

You can also look up subdomains and special names directly. Paste selector1._domainkey.yourdomain.com to see a DKIM key, or _dmarc.yourdomain.com to see a DMARC policy in raw form.

What TXT Records Do

TXT records started as free-form notes in DNS. Then the internet needed somewhere to put machine-readable claims about a domain, and TXT was the only open slot. Now they carry your email authentication (SPF, DKIM, DMARC), your ownership proofs for Google Search Console and Microsoft 365, and a growing pile of verification tokens from every tool your company signed up for since 2015.

That pile matters. Old verification tokens for services you stopped using are safe to delete, and trimming them keeps your DNS responses small. This tool counts your records and flags the domains that have collected more than 20.

The Email Records Hiding in Your TXT

Three email authentication systems live entirely in TXT records. SPF sits at your root domain and lists the servers allowed to send your mail. Receivers reject the record entirely if you publish more than one, which is a surprisingly common mistake, so this tool checks the count. DKIM public keys sit under _domainkey subdomains. DMARC policies belong at _dmarc, and if one shows up at your root domain instead, it does nothing. We flag that too.

What are TXT records used for? +
Almost everything except actually routing traffic. SPF records live in TXT. So do DKIM keys, DMARC policies, and the verification tokens every SaaS product asks you to add (google-site-verification, MS=, apple-domain-verification, and friends). If a service ever asked you to "add a DNS record to prove you own the domain," that was a TXT record.
Why are my TXT records split into multiple strings? +
DNS limits each character-string to 255 bytes. Longer records, most commonly DKIM public keys, get split into chunks that receivers join back together with no separator. It looks broken in raw DNS output. It isn't. This tool joins the pieces and shows you the full record, plus a note about how many strings it came in.
How long do TXT record changes take to show up? +
Up to the record's TTL, shown next to each record here. If your TTL is 3600, resolvers can serve the old value for up to an hour after you change it. Public resolvers like Cloudflare's 1.1.1.1 usually pick up changes faster than that in practice. If you just changed a record and still see the old one, wait out the TTL before assuming something's wrong.
Do TXT records affect email deliverability? +
Directly. SPF is a TXT record at your root domain, DKIM keys are TXT records under _domainkey, and your DMARC policy is a TXT record at _dmarc. If those are missing or malformed, your mail is more likely to land in spam. Run our SPF Checker and DMARC Checker to test each one properly.