Start with the symptom and scope
Record the exact error, hostname, time and whether the failure affects one network or everyone. Test the bare domain and www separately because they can have different records.
Check authoritative nameservers
Inspect NS and SOA records, then confirm the domain is delegated to the nameservers configured at the registrar. Inconsistent delegation can produce old or inconsistent answers.
Compare A and AAAA records
A supplies IPv4 and AAAA supplies IPv6. If IPv4 works but IPv6 fails, some visitors may still see an outage. Check the IPv6 server, firewall, load balancer and TLS configuration before correcting the AAAA record.
Separate DNS from HTTPS
If the hostname resolves to the expected public IP, use Website Diagnostics to check HTTPS status, response time, final URL and headers. Timeouts, 5xx responses or certificate mismatches usually require checking the origin, proxy, firewall or certificate.
Repeatable checklist
Confirm the hostname and error; query A, AAAA, CNAME, NS and SOA; compare the result with the intended server; check IPv4 and IPv6 reachability; inspect HTTPS and redirects; review origin logs; then retest after the relevant TTL expires.
Common mistakes
A DNS record does not prove the website is healthy, DNS propagation is not one global timer, and a PTR record does not list every domain on an IP. Verify important changes with the authoritative DNS provider.
Check real data now
Use the live IIPP tool to inspect the domain or IP address you are working with.
DNS Record Lookup →