Free tool

DNS history lookup

Check historical DNS records for any domain. Enter a domain to see how its DNS changed over time, with the two most recent changes for each record type: A, AAAA, NS, MX, TXT, CNAME and SOA. Useful for finding a domain's old IPs, past nameservers or previous mail hosts.

No account needed. Need the full historical DNS timeline? Get in touch.

What is DNS history?

DNS history (also called historical DNS or DNS record history) is a log of the values a domain's DNS records have held over time, with the dates each value was first and last observed. It shows where a domain pointed before, the domain's IP history, which nameservers and mail servers it used, and when its SPF or other TXT records changed.

  1. Enter a domain in the box above, without http:// or a path.
  2. Read each record type. The top row is the most recent value on record, the rows under it are past DNS records.
  3. Compare the dates between rows to see when the domain changed hosting, DNS provider or mail provider.

Need the full DNS history?

The free lookup shows the two most recent changes per record. If you're working an incident, checking a migration or tracing where a domain used to point, we can pull the complete historical DNS data for you.

Contact us

What can historical DNS records tell you?

Finding an origin IP behind a CDN

If a site moved behind a proxy, its IP history often still has the origin server's address in older A and AAAA records. If that IP wasn't changed or firewalled, it can be reachable directly.

Incident timelines

When an A record or nameserver changed is often the first question after a defacement or suspected DNS hijack. DNS history gives you a date to line up against logs.

SPF record history

TXT history shows when an SPF record went from -all to ~all, or when an include for an old mail provider was left behind. Useful when mail starts getting spoofed and nobody remembers the change.

Nameserver and MX history

NS and MX changes tell you when a domain switched DNS provider or mail host. Handy when you inherit a domain portfolio with no documentation.

Which DNS records does the lookup cover?

RecordWhat its history shows
AIPv4 addresses the domain resolved to. This is the domain's IP history, including hosting and CDN moves
AAAAIPv6 addresses over time. Often forgotten when a site moves, so old values can outlive the A record change
NSNameserver history. When the domain moved between DNS providers or back to registrar parking
MXMail hosts and priorities. Shows mail provider migrations
TXTSPF, verification tokens and other text records at the apex, including policy changes like -all to ~all
CNAMEWhere www and other aliases pointed, including CDN and load balancer hostnames
SOAPrimary nameserver and admin mailbox in the zone's start of authority

DNS history FAQ

How do I check the DNS history of a domain?

Type the domain in the lookup box at the top of this page. You get the two most recent recorded values for A, AAAA, NS, MX, TXT, CNAME and SOA, each with first seen and last seen dates. No account needed.

What's the difference between DNS history and passive DNS?

Passive DNS is one common way historical DNS data gets collected. DNS answers seen on resolvers or sensors are recorded with timestamps, without querying the domain's own nameservers. DNS history is the per-domain timeline you read out of data like that. A passive DNS dataset can also answer other questions, like which domains have pointed at a given IP.

Can DNS history reveal a website's origin IP?

Sometimes. If a site was reachable directly before it was put behind a CDN or WAF, its IP history may include the origin address in old A or AAAA records. That only matters if the server still lives at that IP and accepts traffic from outside the proxy.

Is this the live DNS for the domain?

No. These are historical DNS records. The row marked "current" is the most recent value on record, which can lag behind what the authoritative servers return right now. For live records, run a DNSAudit scan.

What do "first seen" and "last seen" mean?

They're the first and last dates a value was observed for that record. They are not the exact moment someone edited the zone, so treat them as a window.

Why does the lookup only show two changes?

The free lookup shows the latest two per record type. If you need older DNS records, contact us and tell us what you're looking into.

Why would an SPF record change matter?

Moving from -all to ~all or ?all weakens what receivers do with mail from unlisted senders. SPF alone does not stop spoofing, but a loosened record next to a weak DMARC policy is worth knowing about.

Updated September 2026