Skip to main content
dns

AAAA Lookup

AAAA Lookup helps you query ipv6 address (aaaa) records, for authoritative DNS validation, resolver checks, and faster troubleshooting.

Enter a domain name to lookup IPv6 addresses

AAAA LookupIPv6 hex blocks pulse as AAAA records resolve.20010db842aa

Advertisement · Anuncio

Advertisement · Anuncio

Technical Analysis & Guide

What It Does

AAAA Lookup asks a recursive resolver for the IPv6 address records (type 28) of a hostname and lists every address returned together with its remaining TTL. If the name has no IPv6 addresses, the tool reports that as informational rather than as a failure, because IPv6 is still optional for many services. Use it to confirm that a host is reachable by IPv6-only and dual-stack clients.

Illustration of dns concept

Why It Matters

  • →Mobile reachability: Large mobile carriers run IPv6-only access networks with NAT64/DNS64, so a missing or broken AAAA forces every connection through a translation gateway.
  • →Silent breakage: Publishing an AAAA for a server whose IPv6 firewall or listener is not configured makes dual-stack clients try IPv6 first and stall before falling back.
  • →Mail and reputation: Receivers such as Gmail apply stricter checks to mail arriving over IPv6, including mandatory reverse DNS for the sending address.
  • →Migration audits: After moving to a new host or CDN, stale AAAA records often keep pointing at the old provider while the A record was updated.
  • →Cost and latency: Some networks route IPv6 more directly than IPv4 carrier-grade NAT, so a correct AAAA can shave round trips for real users.

How to Read Results

  • Status pass with a count: The resolver returned that many AAAA records; each row is one IPv6 address that clients may connect to.
  • address: The IPv6 address in compressed RFC 5952 form, for example 2606:4700::6810:84e5. Leading zeros and the longest zero run are collapsed into ::.
  • ttl and ttlFormatted: Seconds the answer may still be cached by the resolver that served it, plus a human-readable version. The value counts down between queries, so it is not always the zone's configured TTL.
  • Status info, no AAAA records found: The name exists but has no IPv6 address (NODATA) or does not exist at all (NXDOMAIN). This is not an error unless you expected IPv6.
  • Several addresses: Usually anycast or load-balanced front ends; verify each one actually answers on the expected port.
  • CNAME targets: If the name is an alias, the addresses shown belong to the final target the resolver reached, not to the alias itself.

Technical Background

The AAAA resource record was standardized in RFC 3596 as the IPv6 counterpart of the A record. Its RDATA is a fixed 128-bit address, and in zone-file syntax it looks like www.example.com. 3600 IN AAAA 2001:db8:10::25. The 2001:db8::/32 prefix is reserved for documentation by RFC 3849, so it should never appear in production answers. Text representation follows RFC 5952: lowercase hex, leading zeros dropped in each group, and the longest run of zero groups replaced by a double colon. Two strings that look different can therefore be the same address, which matters when you compare a DNS answer with an interface configuration.

A dual-stack client normally sends A and AAAA queries in parallel. Happy Eyeballs version 2 (RFC 8305) defines what happens next: if the AAAA answer arrives, the client tries IPv6 first; if the AAAA answer is late it waits a short resolution delay (50 ms recommended) before starting with IPv4, and between successive connection attempts it waits a connection attempt delay (250 ms recommended) instead of a full TCP timeout. This is why a broken IPv6 path rarely produces a hard error in browsers but shows up as an extra fraction of a second on every new connection, and why command-line tools that do not implement Happy Eyeballs may hang for the whole TCP timeout.

On IPv6-only mobile networks, DNS64 (RFC 6147) synthesizes AAAA records from A records using the 64:ff9b::/96 well-known prefix (RFC 6052) when a name has no native AAAA. Traffic then crosses a NAT64 gateway. That works, but it adds a stateful translator, loses the original client address on the server side and breaks protocols that embed IPv4 literals. Publishing a native AAAA removes that dependency. Remember that a public resolver you query from a desktop will not apply DNS64, so this tool shows only real AAAA data from the zone.

Operationally, an AAAA record is a promise that the service is fully reachable over IPv6: the address must be routed, filtered correctly on firewalls and security groups (ICMPv6 Packet Too Big must be allowed, or Path MTU discovery fails and large TLS handshakes hang), and the web server, mail server or load balancer must be listening on that address. TLS certificates are name-based, so they need no change, but access-control lists, rate limiters and logging pipelines that only understand IPv4 often do. For mail, add a PTR in ip6.arpa for every sending IPv6 address before publishing AAAA on an MX host, because large receivers reject IPv6 mail from addresses without valid reverse DNS.

Common Errors and How to Fix Them

ProblemAAAA published but the site times out for some users while others load fine.
FixThe IPv6 path is broken on the server side. Confirm the address is bound (ss -ltn or netstat), open TCP 80/443 for IPv6 in the firewall and cloud security group, and allow ICMPv6 type 2 (Packet Too Big). Remove the AAAA until curl -6 succeeds from an external network.
ProblemAAAA still points to the previous hosting provider after a migration.
FixMany control panels create A and AAAA separately. Delete or update the old AAAA, then wait for the previous TTL to expire. Check every resolver-facing name, including www and apex.
ProblemLink-local or private IPv6 (fe80::/10, fc00::/7) published in public DNS.
FixThese ranges are not routable on the internet. Publish the global unicast address assigned by your provider, usually inside 2000::/3.
ProblemIPv6 mail rejected with a reverse DNS or authentication error.
FixAdd a PTR for the IPv6 sending address in ip6.arpa through your provider, make it resolve forward to the same address, and include the IPv6 range in SPF with ip6:2001:db8:10::/64.
ProblemNo AAAA records found even though the CDN supports IPv6.
FixIPv6 is often a per-zone toggle in CDN dashboards. Enable it, or if you use a CNAME to the CDN, confirm the target hostname itself returns AAAA.

Frequently Asked Questions

Do I need an AAAA record for my website?

It is not mandatory, because IPv6-only clients can still reach IPv4 sites through NAT64. However, a native AAAA avoids that translation layer, gives you the real client address in logs and is increasingly expected by mobile networks. Only add it once the server, firewall and load balancer are verified to work over IPv6; a broken AAAA is worse than none.

What is the difference between an A and an AAAA record?

Both map a hostname to an address. An A record holds a 32-bit IPv4 address such as 192.0.2.10, while an AAAA record (RFC 3596) holds a 128-bit IPv6 address such as 2001:db8::10. A name can have both, and dual-stack clients pick between them using the Happy Eyeballs algorithm described in RFC 8305.

Why does my AAAA lookup return nothing when ping6 works?

Ping may be using a hosts-file entry, a local DNS64 resolver that synthesizes addresses, or a different hostname. This tool queries public DNS, so if no AAAA is listed the authoritative zone simply does not publish one for that exact name. Check the spelling, the www versus apex form and whether a CNAME target lacks IPv6.

Why is the TTL shown lower than the one I configured?

Recursive resolvers return the time remaining in their cache, which decreases every second after they fetched the record. Only an authoritative server returns the full configured TTL. Query your authoritative name server directly with dig @ns1.yourprovider.example AAAA name to see the original value.

Does Google penalize sites without IPv6?

There is no published ranking signal for IPv6. The practical impact is on users: visitors on IPv6-only mobile networks go through NAT64, which can add latency or break some features. Treat IPv6 as a reachability and performance improvement rather than an SEO factor.

Academic Documentation

Protocol context and primary references

REST API Documentation

v1.0
GET /api/tools/aaaa-lookup
					curl -X POST https://epcybertools.com/api/tools/aaaa-lookup \
  -H "Content-Type: application/json" \
  -d '{"domain":"google.com"}'
				
					{
  "success": true,
  "results": [
    { "test": "Sample Check", "status": "pass", "message": "All clear" }
  ]
}
				
Rate Limit: 100 requests / 15 minutes

Usage Examples

			# IPv6 addresses only

dig AAAA example.com +short

# Show remaining TTL and the CNAME chain

dig AAAA www.example.com +noall +answer

# Test that the service really answers over IPv6

curl -6 -sI https://example.com
		
100-Day Max Lifespan
155d 5h 18m 24s
PQC Migration Target
1178d 5h 18m 24s