TXT Record Lookup
Look up DNS TXT records for any domain or hostname. Verify SPF, DKIM, and DMARC, confirm Google and Cloudflare verification strings, and debug Shopify domain TXT checks. Live results from Google DNS and Cloudflare - free, no signup.
What Is a TXT Record Lookup?
A TXT record lookup (DNS TXT lookup) retrieves text records published for a hostname. Those strings are how the internet proves domain ownership, authorises mail senders, and publishes policies such as DMARC. This page is a focused DNS TXT lookup tool - same live engine as our DNS lookup, locked to TXT so you are not wading through A/MX noise while debugging email or verification.
Keyword split: Broad DNS searches stay on /dns-lookup. Alias checks belong on /cname-lookup. SPF, DKIM, DMARC, and verification TXT strings belong here.
Real TXT Record Examples
SPF (Sender Policy Framework)
example.com. 300 IN TXT "v=spf1 include:_spf.google.com include:shops.shopify.com ~all"
Publish SPF on the apex. Mechanisms list authorised senders; ~all soft-fails unknowns while -all hard-fails. Never create two separate v=spf1 records on the same name - merge includes into one string.
DMARC
_dmarc.example.com. 300 IN TXT "v=DMARC1; p=quarantine; rua=mailto:[email protected]"
Always query _dmarc.example.com, not the naked domain. Policies progress from p=none (monitor) to quarantine/reject once reports look clean.
DKIM
google._domainkey.example.com. 300 IN TXT "v=DKIM1; k=rsa; p=MIIBIjANBg..."
Replace google with your ESP selector (s1, k1, etc.). Long keys appear as multiple quoted chunks - that is normal TXT splitting, not corruption.
Google site verification
example.com. 300 IN TXT "google-site-verification=AbCdEfGhIjKlMnOpQrStUvWxYz0123456789"
Cloudflare / email routing style markers
example.com. 300 IN TXT "v=spf1 include:_spf.mx.cloudflare.net ~all" cf-token.example.com. 300 IN TXT "cloudflare-verify-..."
Common TXT Record Mistakes
- Multiple SPF records: Two
v=spf1answers cause unpredictable mail failures. Combine includes into a single SPF TXT. - Wrong hostname for DKIM/DMARC: Looking up only
example.comwill not show_dmarcor_domainkeyrecords. Query the exact name your provider shows. - Extra quotes or spaces in the DNS UI: Some panels wrap values for you. Pasting already-quoted text creates nested quotes and breaks verification.
- Truncating DKIM keys: Copy the full public key. Partial
p=values fail signature checks even when SPF looks fine. - Mixing verification methods: Google TXT vs CNAME verification are different. Publish the method you selected in Search Console - then verify with this tool or CNAME lookup accordingly.
- Expecting instant global visibility: Respect TTL. After a change, re-run the TXT lookup until both Google DNS and Cloudflare paths agree.
How to Check Cloudflare, Shopify, and Google TXT Records
Cloudflare
- DNS → Records → filter by TXT. Note Name (apex vs subdomain) and Content.
- Enter that same name in this DNS TXT lookup. Proxied status does not rewrite TXT the way it rewrites A/CNAME - public resolvers should match the dashboard value.
- For Email Routing, confirm SPF includes Cloudflare's include and that MX points where Cloudflare documents. Pair with our email server test when delivery still fails.
Shopify
- Domains settings list any TXT verification or SPF includes Shopify needs for the store domain.
- Query the apex for SPF/verification TXT. Keep Shopify's include in the single SPF record alongside Google Workspace or other ESPs.
- Host aliases (www) are usually CNAMEs - verify those on CNAME lookup, not here.
Google verification & Workspace
- Search Console TXT method: apex should show
google-site-verification=.... Workspace may also require SPF (include:_spf.google.com), DKIM selector records, and DMARC. - Run separate lookups for apex,
_dmarc, andselector._domainkey. - After publishing, wait for TTL, then verify in Google's UI. Use blacklist check if mail still lands in spam after auth records look correct.
How to Use This DNS TXT Lookup Tool
- Paste the exact hostname (apex,
_dmarc, or DKIM selector host). - Click Look Up TXT for live answers from Google DNS and Cloudflare DNS.
- Match strings to your provider's docs character-for-character, including includes and policy tags.
Need MX and A records in the same view? Open the full DNS lookup. Debugging shop or CDN aliases? Use CNAME lookup.
Frequently Asked Questions - TXT Record Lookup
Answers about DNS TXT lookup, SPF/DKIM/DMARC hosts, and verification strings:
What is a TXT record lookup?
A TXT record lookup queries DNS for text records on a hostname. TXT data carries email authentication (SPF, DKIM, DMARC), domain ownership proofs for Google or Microsoft, and other machine-readable strings providers ask you to publish.
What is the difference between DNS TXT lookup and a full DNS lookup?
DNS TXT lookup focuses on text records only. A full DNS lookup returns A, MX, CNAME, NS, and more. Use this page for SPF/DKIM/DMARC and verification strings; use /dns-lookup when you need every record type together.
Where should I look up SPF, DKIM, and DMARC?
SPF: query the apex domain. DMARC: query _dmarc.yourdomain.com. DKIM: query selector._domainkey.yourdomain.com using the selector your ESP shows (for example google or s1). Looking up only the apex will miss DKIM and DMARC.
How do I check a Google site verification TXT record?
Google Search Console often asks for a TXT record on the apex that starts with google-site-verification=. Enter your root domain in this tool and confirm that exact string appears. If Google gave you a CNAME verification method instead, use the CNAME lookup page.
Why do I see multiple quoted strings in one TXT record?
DNS TXT values longer than 255 characters are split into multiple quoted chunks. Resolvers concatenate them. Seeing "v=DKIM1; ..." "p=MIGf..." is normal for DKIM keys - it is still one logical record.
Is this DNS TXT lookup tool free?
Yes. Unlimited TXT lookups, no account required. Queries use Google DNS and Cloudflare DNS over HTTPS for live answers.
Related Tools
Technical information
How this tool works, where data comes from, and known limitations. See also our methodology and accuracy & limitations pages.
How this tool works
Runs the shared DNS lookup engine locked to TXT queries against Google and Cloudflare DNS-over-HTTPS endpoints.
Data source
Limitations
DKIM and DMARC live on specific hostnames (selector._domainkey / _dmarc). Looking up only the apex will miss those records. Long TXT values may appear as concatenated quoted chunks.
Content revision 2026-09 (aligned with current tool implementation in this codebase)