DNS record history for operators
See the DNS record before it changed.
A dated answer to the incident question a live DNS lookup cannot answer.
Type a domain to compare previously observed A, AAAA, MX, NS, TXT, and CNAME values. Each flip shows the old answer, the replacement, and the date the change was first seen, so an outage, mail failure, or handover starts with evidence instead of guesswork.
Publicly observed DNS history, not a complete zone backup.
In the archive
Read the change, not just the current answer.
Historical answers add sequence to a live lookup: the observed value before, the observed value after, and the first-seen date.
Previously observed addresses and the first-seen date of a replacement.
Previously observed mail hosts and the first-seen date of a routing change.
Observed SPF, DKIM, DMARC, and verification strings across time.
The nameservers of record, so registrar and DNS-host moves are visible.
What an alias resolved to before it was repointed somewhere new.
Built around the operator holding the incident.
- SREs: line up an outage with an A, CNAME, NS, or verification change.
- Email admins: recover the MX, SPF, DKIM, or DMARC value from before mail broke.
- MSPs and agencies: reconstruct the public DNS visible before a handover or migration.
- Security and diligence teams: inspect past domain-to-infrastructure relationships.
"And when, exactly, did it change?"
The follow-up question a current lookup cannot answer. DNS history gives the incident timeline a concrete lead to investigate.
Look up a domainBy the job
Common history lookups.
The records people reach for most. Each page covers one kind of DNS history and the exact question it answers.
For SREs, administrators, domain buyers, and analysts who need historical DNS records rather than another current snapshot.
DNS change history Find the DNS change that lines up with the incident.For SREs, sysadmins, and support engineers asking whether a DNS change lines up with the start of an incident.
Old DNS records Find the DNS record that was deleted or overwritten.For MSPs, agencies, and administrators recovering public DNS after a transfer, migration, or incomplete handover.
SPF record history See the SPF record that changed before mail broke.For email administrators and deliverability teams tracing an authentication failure to a past TXT value.
Past MX records See the MX records a domain used to use.For email administrators and MSPs diagnosing a failed Google Workspace, Microsoft 365, or other provider migration.
Cloudflare DNS history See a domain's previous Cloudflare DNS values.For Cloudflare administrators and agencies comparing account audit logs with independently observed public DNS history.
Direct answers
DNS record history, explained.
What is DNS record history?
DNS record history is a dated archive of previously observed DNS answers. It can show that an A, AAAA, MX, NS, TXT, or CNAME value was replaced, added, or removed, even though a live lookup only shows the current answer.
Can DNS history recover a deleted record?
It can recover a value that was publicly observable and captured before deletion. It is not a complete zone backup, and private or never-observed records may be absent.
How is DNS history useful during an incident?
Compare the first-seen date of a DNS change with the incident timeline. A matching date can identify a useful lead, but it does not by itself prove that the DNS edit caused the incident.
Which DNS record types can I look up?
DNSTimeMachine is designed around historical A, AAAA, MX, NS, TXT, and CNAME answers, including email-routing and email-authentication changes that were publicly observable.