🔵 AAAA Record Lookup

See exactly which IPv6 address (or addresses) a domain resolves to, right now, from a live DNS query — including TTL, dual-stack detection against the A record, and the raw resolver response.

Examples: google.com   cloudflare.com   facebook.com
🕒 Recent Lookups
No recent lookups yet.
Type an IPv6-only address into most command lines and it looks nothing like the tidy dotted-quad most people grew up reading — it's longer, hexadecimal, and dotted with colons instead of periods. The AAAA record is the DNS entry responsible for handing that address back whenever a resolver asks, and as more networks quietly finish their IPv6 rollout, checking whether a domain actually publishes one has become a routine, genuinely useful diagnostic step. This page runs that lookup live against a public resolver, cross-checks it against the domain's A record to flag dual-stack status, and below it is a full reference on what AAAA records are, how they behave differently from their IPv4 counterpart, and where they trip people up in practice.
⭐ ToolsNovaHub Pro Tip
Never assume "no AAAA record" is a mistake. Plenty of well-run, high-traffic domains are still IPv4-only by deliberate choice, often because a piece of their infrastructure — a legacy load balancer, an on-prem firewall, a third-party CDN contract — doesn't support IPv6 cleanly yet. Treat a missing AAAA record as information, not automatically as a bug to file a ticket about.
⚠️ Common Beginner Mistake
Assuming an AAAA record and an A record for the same hostname must always resolve to "the same server." They resolve to the same logical service, but very often to physically different infrastructure — different load balancers, sometimes even a different CDN edge network entirely — because IPv4 and IPv6 traffic frequently take separate paths all the way to origin.

🔍 What This Tool Checks

An AAAA record maps a hostname to an IPv6 address. This tool runs a live query for that record against a public DNS-over-HTTPS resolver and returns exactly what's published right now — every IPv6 address found, its TTL, and a side-by-side check of whether the same hostname also has an A record, so you can see its dual-stack status at a glance. Useful during an IPv6 rollout, a CDN migration, a "some users can't connect" ticket, or a routine infrastructure audit, without reaching for a terminal.

For the naming history, record structure, and how AAAA compares to an A record at the protocol level, see AAAA Record Explained.

⚙️ How This Tool Resolves an AAAA Record

When you click Lookup, this tool sends a live DNS-over-HTTPS query for the AAAA record type against a public resolver and returns exactly what comes back — the same answer any properly configured IPv6-aware resolver anywhere in the world would receive at that moment. It isn't reading from a cached database or a stored snapshot; a domain that changes its AAAA record five minutes before you check will show the new value immediately, subject only to the TTL of whatever answer a resolver you personally use might already have cached elsewhere.

1

You Enter a Hostname

Type in the domain or subdomain you want to check, exactly as it would appear in a browser address bar.

2

A Live AAAA Query Is Sent

The tool queries a public DNS-over-HTTPS resolver directly from your browser for the AAAA record type.

3

The Result Is Parsed

Every returned IPv6 address, along with its TTL, is extracted and displayed in a readable table.

4

Dual-Stack Status Is Checked

The tool separately checks whether the same hostname also has an A record, and reports whether the domain is dual-stack or IPv6-only.

🔌 Dual-Stack: Reading the Result Correctly

Most production domains that publish an AAAA record also keep their A record — this combination is called dual-stack, and it's the safest, most widely recommended configuration for a public-facing hostname today. Dual-stack means an IPv6-capable visitor connects over IPv6 natively, while a visitor on an IPv4-only connection still reaches the exact same hostname over IPv4 without any special handling — nobody is left behind, and nobody's browser needs to do anything unusual to get there.

A domain that returns AAAA records but no A record at all is IPv6-only, which is still comparatively rare for public-facing services precisely because it excludes any visitor whose network path lacks IPv6 connectivity, whether that's an older ISP, a corporate network still mid-rollout, or a mobile carrier with incomplete IPv6 support on a specific plan. IPv6-only is far more common on internal infrastructure — private data-center segments, service meshes, and internal APIs — where every client on the network is already guaranteed IPv6-capable.

👀 Happy Eyeballs: How Clients Choose IPv4 vs IPv6

When a hostname returns both an A and an AAAA record, the client doesn't just blindly pick one — modern browsers and operating systems use an algorithm called Happy Eyeballs (formally RFC 8305), which fires off connection attempts to both address families in quick succession and uses whichever one completes its handshake first, usually giving IPv6 a small head start since it's normally faster on networks where it's genuinely well-supported. This is precisely why a dual-stack domain with a broken or slow IPv6 path can still feel fine to most users — Happy Eyeballs quietly falls back to IPv4 within a few hundred milliseconds if the IPv6 attempt stalls, masking a real IPv6 problem that would otherwise be invisible until someone checks the AAAA record directly.

That masking effect is exactly why this tool matters for troubleshooting: a site "working fine" in a browser tells you almost nothing about whether its IPv6 path is healthy, because Happy Eyeballs is specifically designed to hide that kind of partial failure from the end user.

⏳ TTL & Caching Behavior

TTL works identically for AAAA records as it does for A records — it's the number of seconds a resolver is permitted to cache the answer before it's required to ask again. A freshly changed AAAA record won't be visible to every resolver worldwide instantly; each one continues serving its previously cached answer until that entry's TTL expires, which is why a change can appear "live" from one location and "not yet applied" from another for a window of time entirely explained by caching, not by anything broken.

🔧 Troubleshooting

⚠️ Lookup returns no AAAA records
The domain is most likely IPv4-only right now — confirm by checking the same hostname with our A Record Lookup tool; if that returns results and this doesn't, IPv6 simply hasn't been enabled for it.
⚠️ AAAA record exists but the site is unreachable over IPv6
The record can exist while the actual server isn't listening on that address — verify with a direct connectivity test from an IPv6-connected network rather than trusting DNS alone.
⚠️ Results differ from what my computer resolves
Your device's local resolver may hold a cached answer with a different remaining TTL than the public resolver this tool queries directly.
⚠️ Only some subdomains have AAAA records
This is common and often intentional during a phased IPv6 rollout — teams frequently enable IPv6 on lower-risk subdomains first before touching the apex domain.

🎓 Expert Tips

🎓
Always Check Both Records Together
Never evaluate an AAAA record in isolation — comparing it against the A record for the same hostname is what actually tells you whether a domain is dual-stack, IPv6-only, or IPv4-only.
🔧
Test From a Real IPv6 Network
A DNS-level AAAA check confirms the record exists; it doesn't confirm the path actually works. Test from a genuinely IPv6-connected network before calling a rollout done.
🔐
Audit Firewall Parity Regularly
Make IPv4/IPv6 firewall-rule parity a recurring audit item, not a one-time setup step — configuration drift between the two stacks is one of the most common silent security gaps.

For the complete record picture beyond AAAA, use DNS Lookup. To check the IPv4 side of the same hostname, use A Record Lookup. For a deeper geolocation and metadata check on any IPv6 address itself, try IPv6 Lookup, or expand and subnet an IPv6 prefix with the IPv6 Calculator. To confirm whether a DNS change has propagated globally, use DNS Propagation Checker, and to go the other direction — from address back to hostname — try Reverse DNS Lookup.

📚 Want the full mechanics behind this record type? Read: AAAA Record Explained → · New to IPv6 DNS records generally? IPv6 DNS Records →

ToolsNovaHub tools are built and independently maintained with a focus on accurate, no-signup network and security utilities. Spotted an error? Let us know.

📋 Related Tools & Guides Comparison

ResourceTypeLink
A Record LookupNetworkOpen Tool →
IPv6 LookupIP & NetworkOpen Tool →
IPv6 CalculatorCalculatorOpen Tool →
DNS LookupNetworkOpen Tool →
AAAA Record ExplainedGuideRead Guide →
Dual Stack DNSGuideRead Guide →

FAQ

An AAAA record ("quad-A") is the DNS record type that maps a hostname directly to an IPv6 address — the same role an A record plays for IPv4, scaled up for the 128-bit IPv6 address space.
An IPv6 address is 128 bits, exactly four times a 32-bit IPv4 address. The record name quadruples the letter A as a mnemonic for that 4x size increase, rather than moving to the next free letter.
Not strictly, but most production domains publish both — called dual-stack — so IPv6-capable visitors connect natively while IPv4-only visitors still reach the same hostname.
Plenty of major sites are still IPv4-only, or only enabled IPv6 on some subdomains. No AAAA record just means that specific hostname doesn't publish one right now — not an error.
An A record points to a 32-bit IPv4 address; an AAAA record points to a 128-bit IPv6 address. They do the same job for two different address families and can coexist for the same hostname.
Dual-stack means a hostname publishes both an A and an AAAA record, letting clients connect over either IPv4 or IPv6 depending on what their network supports.
Yes — a hostname can publish AAAA records with no A record at all. It's uncommon for public sites but increasingly normal for internal infrastructure where every client is IPv6-capable.
Happy Eyeballs silently falls back to IPv4 within a few hundred milliseconds if the IPv6 attempt stalls, which can mask a real IPv6 problem from an ordinary user's experience.
TTL (Time to Live) is how many seconds resolvers will cache this answer before querying again — a TTL of 3600 means roughly one hour of caching.
Live — every lookup queries a public DNS resolver directly at the moment you click Lookup, reflecting the currently published record, not a stored snapshot.
Yes — enter the full subdomain, like api.example.com, and the tool queries that exact name rather than the root domain.
Generally no — IPv6's address space is large enough to assign a globally routable address per device, removing the practical necessity for NAT that shaped most IPv4 network design.
Not inherently — risk comes from what's actually listening on the address, not the address family. IPv6's huge space does make brute-force subnet scanning impractical, though that shouldn't be relied on as a security layer by itself.
Reverse-proxying CDNs publish their own edge network's address, not your backend's. This is expected behavior for any domain sitting behind a CDN or reverse proxy.
Yes — free, no sign-up. Results come from a public DNS resolver and appear instantly. Queries run through a public DNS resolver, so usage is bounded by that provider's own fair-use limits rather than anything we impose.
Use our My IP Address tool — if it detects a public IPv6 address for your connection, your network has working IPv6 outbound connectivity.
Confirm the rule was actually duplicated on the IPv6 firewall or security-group layer — most firewalls treat IPv4 and IPv6 rules as entirely separate rule sets that don't inherit from each other automatically.
Yes — a CNAME simply aliases to another name, and the resolver follows that alias to whatever records (A, AAAA, or both) the target name actually publishes.