Reverse DNS Lookup
Reverse DNS Lookup helps you reverse lookup to find hostname from ip address, for routing analysis, ownership checks, and faster network troubleshooting.
Advertisement · Anuncio
Advertisement · Anuncio
Technical Analysis & Guide
What It Does
Reverse Lookup takes an IPv4 or IPv6 address, converts it to its in-addr.arpa or ip6.arpa name and queries the PTR records there, returning the host name or names the address owner has assigned. The first name is shown as the primary result. It answers the question 'what does this IP call itself', which mail servers, logs and security tools ask constantly.

Why It Matters
- →Mail acceptance: Major receivers expect every sending IP to have a PTR whose name resolves back to the same IP; missing reverse DNS is a classic reason for 550 rejections or spam-folder placement.
- →Generic names hurt: A PTR such as 203-0-113-25.dyn.isp.example looks like a residential connection, and many spam filters score it accordingly.
- →Incident triage: Turning attacker or scanner IPs into names quickly reveals hosting providers, VPN exits or known crawlers in firewall and web logs.
- →Crawler verification: Search engines document that you can confirm a genuine crawler by reverse-resolving its IP and then forward-resolving the returned name.
- →Inventory hygiene: PTRs left pointing at decommissioned host names after an IP is reassigned confuse troubleshooting and can mislead reputation systems.
How to Read Results
- Status pass, 'resolves to': At least one PTR exists; primary is the first host name returned and is the one most receivers will use.
- hostnames: Every PTR value for the address. More than one is legal but discouraged for mail servers, because receivers may pick any of them for their checks.
- ip: The address you queried, as validated by the tool. Enter a bare address such as 192.0.2.25 or 2001:db8::25, not a host name.
- Status info, no PTR record found (ptr: null): The reverse zone has no PTR for that address or has not been delegated. Contact whoever owns the IP block to create one.
- Forward confirmation is up to you: The tool does not re-resolve the name. Run an A or AAAA lookup on the primary host name and confirm it returns the same IP before relying on it for mail.
Technical Background
Reverse DNS maps addresses back to names using ordinary DNS delegation under special domains. For IPv4, RFC 1035 section 3.5 defines in-addr.arpa: the four octets are written in reverse order, so 192.0.2.25 becomes 25.2.0.192.in-addr.arpa. For IPv6, RFC 3596 defines ip6.arpa with one label per hexadecimal nibble, also reversed, so 2001:db8::25 becomes a 32-label name ending in ...8.b.d.0.1.0.0.2.ip6.arpa. The record found at that name is a PTR (type 12), for example 25.2.0.192.in-addr.arpa. 3600 IN PTR mail.example.com. Reversing the order puts the network part on the right, matching DNS's right-to-left hierarchy so that address blocks can be delegated like domains.
That delegation follows address allocation, not domain ownership. The regional internet registries (ARIN, RIPE NCC, APNIC, LACNIC, AFRINIC) delegate reverse zones to the networks they assign space to, which then delegate further or host the PTRs themselves. As a result, the PTR for an IP is controlled by whoever owns or leases the address, usually your ISP, cloud provider or hosting company, and never by the registrar of your domain. On cloud platforms you typically set it in the console for an elastic or static IP; with an ISP or colocation provider you open a ticket. Blocks smaller than a /24 cannot be delegated on octet boundaries, so RFC 2317 describes classless delegation using CNAMEs from the parent reverse zone into a customer-controlled zone.
A PTR on its own proves little, since anyone controlling a reverse zone can claim any name. Receivers therefore use forward-confirmed reverse DNS (FCrDNS): look up the PTR, resolve that name forward with A or AAAA, and check that the original IP is in the result. Google's sender guidelines require valid forward and reverse DNS for sending IPs, and many receivers reject or penalize mail that fails FCrDNS or whose PTR looks dynamic. The best practice for a mail server is a single PTR naming a host inside a domain you control, for example mail.example.com, with a matching A/AAAA record and the same name used in the SMTP HELO/EHLO greeting and the TLS certificate.
Beyond mail, RFC 1912 recommends that every internet-reachable host have consistent reverse and forward records, and some services such as SSH logging, older FTP daemons and network monitoring perform reverse lookups on every connection, adding latency when the reverse zone is slow or lame. Reverse DNS is also a useful but not authoritative signal: names are chosen by the address owner and can be stale or deliberately misleading, so treat them as hints and corroborate with WHOIS, ASN and geolocation data.
Common Errors and How to Fix Them
- ProblemTrying to create the PTR in the domain's DNS panel at the registrar.
- FixReverse zones belong to the IP owner. Set the PTR in your cloud provider's console for that IP, or ask your ISP or hosting company to create it, giving them the exact host name.
- ProblemPTR set to mail.example.com but that name has no A record, so FCrDNS fails.
- FixCreate mail.example.com with an A (and AAAA if applicable) record pointing to the same IP, then verify that dig +short $(dig -x IP +short) returns the original address.
- ProblemMail server sends from an IP with a generic ISP PTR such as 25-113-0-203.static.isp.example.
- FixRequest a custom PTR naming your mail host, or relay outbound mail through a provider whose IPs already have proper reverse DNS.
- ProblemIPv6 enabled on the mail server but no ip6.arpa PTR exists.
- FixLarge receivers reject IPv6 mail without reverse DNS. Add a PTR for the IPv6 sending address, or bind the MTA to IPv4 for outbound SMTP until it is in place.
- ProblemPTR value entered without a trailing dot in a self-hosted reverse zone, producing mail.example.com.2.0.192.in-addr.arpa.
- FixIn zone files, write the target fully qualified with a final dot: mail.example.com.
Frequently Asked Questions
How do I set up reverse DNS for my IP address?
Contact whoever provides the IP. On most cloud platforms you can set the PTR for a static or elastic IP in the console, sometimes only after the matching forward A record exists. For ISP, VPS or colocation addresses, open a support ticket with the IP and desired host name. Your domain registrar cannot do it.
What is FCrDNS and why do mail servers check it?
Forward-confirmed reverse DNS means the PTR of an IP points to a name, and that name's A or AAAA record points back to the same IP. Because anyone controlling a reverse zone can write any PTR, the forward check proves the domain owner agrees. Receivers use it as a basic legitimacy signal for sending servers.
Does the PTR have to match my domain name?
It should be a name in a domain you control and should match your HELO/EHLO hostname, but it does not need to equal your From domain. A mail server at mail.example.com can send for many customer domains as long as SPF, DKIM and DMARC are aligned for each of them.
Why does my IP have no PTR record?
Many providers leave new addresses without reverse DNS or with a generic placeholder. It can also happen when the reverse zone for a block has not been delegated to the provider that now uses it. Ask the IP owner to publish a PTR; there is nothing you can change in your own domain's zone.
How long does a reverse DNS change take?
Once the provider updates the reverse zone, new queries see it immediately, but resolvers that cached the previous PTR or a negative answer keep it until the TTL expires, often one hour to one day. Some ISPs process PTR tickets manually, which usually adds more delay than DNS caching.
Academic Documentation
Protocol context and primary references
REST API Documentation
v1.0GET /api/tools/reverse-lookup
curl -X POST https://epcybertools.com/api/tools/reverse-lookup \
-H "Content-Type: application/json" \
-d '{"ip":"8.8.8.8"}'
{
"success": true,
"results": [
{ "test": "Sample Check", "status": "pass", "message": "All clear" }
]
}
Usage Examples
# PTR for an IPv4 address
dig -x 192.0.2.25 +short
# Same for IPv6 (dig builds the ip6.arpa name)
dig -x 2001:db8::25 +short
# Forward-confirm the returned name
dig A mail.example.com +short