The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →When a site will not load, first find out whether the failure affects one device, one network, one domain, or all DNS lookups. Then query the resolver directly and use its response—timeout, NXDOMAIN, SERVFAIL, or an unexpected answer—to choose the next check. A cache flush may help with stale client data, but it cannot fix incorrect authoritative records, broken delegation, or a DNSSEC chain.
1. Scope the problem before changing DNS settings
Start by recording what fails and where. Browser messages such as DNS_PROBE_FINISHED_NXDOMAIN and operating-system alerts such as “DNS server not responding” describe symptoms; by themselves, they do not identify the faulty layer.
- One device or all devices? If other devices on the same network can resolve the name, inspect the affected device’s DNS configuration, VPN, and local cache first.
- One network or several? If the same device works on another permitted network, investigate the original network’s resolver, firewall, router, or filtering policy.
- One domain or many? A single failing domain suggests checking that name’s records, delegation, and DNSSEC. Many unrelated names failing points more toward the client’s resolver configuration, the resolver itself, or network connectivity.
- One record type or application? Record whether the application needs A, AAAA, MX, or another record. A lookup can succeed while the specific type an application needs is absent.
Note the exact domain, time, error text, device and network, configured DNS server, and any recent record, nameserver, VPN, router, or security-policy change. Compare with a working device or network when available, but follow organizational rules before testing with an external resolver.
2. Check client configuration and query the intended resolver
On Windows, Microsoft recommends checking the client’s IP address, subnet mask, and default gateway with ipconfig /all, then querying the intended DNS server directly. For example:
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →#1 Best Overall
nslookup example.com 192.0.2.53
Replace 192.0.2.53 with the DNS server IP you are investigating. Record the response and compare it with a query using the normal configured resolver, if that test is permitted. Microsoft frames DNS failures as client-side or server-side issues and recommends beginning with the client unless the scope points to the server (Microsoft Learn: Troubleshooting DNS Servers; Microsoft Learn: Troubleshooting Domain Name System (DNS) issues).
A successful ping to an IP address does not prove DNS is working: it tests IP reachability, not name resolution. Likewise, a failed ping alone does not prove DNS is broken.
3. Interpret the DNS response
Timeout or no response
A timeout means no usable reply arrived from the resolver during the query. Check whether the configured resolver is reachable, its DNS service is running, and it is listening on the queried interface. Also check firewall and network rules. Microsoft notes that nslookup normally uses UDP port 53; filtering, or a server listening on a different port, can prevent a response. On a managed network, have the DNS or network administrator check service status, interfaces, logs, and permitted traffic rather than changing client settings at random.
Rank #2
NXDOMAIN
NXDOMAIN means the resolver reports that the queried name does not exist. Check spelling, the intended domain and zone, whether the record exists, and whether the domain delegates to the right nameservers. If a name was recently created or changed, a cached negative answer can persist temporarily. RFC 9520 covers caching of DNS resolution failures, including negative results (RFC 9520).
NOERROR, but no requested address or record
A successful DNS response does not guarantee that the requested record type exists. For example, a name may have an A record but no AAAA record, or a service may lack the MX record an application expects. Check the query type against the records actually published in the authoritative zone.
SERVFAIL
SERVFAIL means the resolver could not complete the lookup. Check upstream reachability and resolver logs. If the domain uses DNSSEC, investigate validation and the DS/DNSKEY chain; do not assume DNSSEC is the cause of every SERVFAIL.
Wrong or stale address
Compare the authoritative answer with the recursive resolver’s answer. Review the record’s TTL, recent changes, and whether the query went to the DNS provider that currently hosts the zone. This comparison helps distinguish stale cached data from an incorrect authoritative record or an unintended resolver.
4. Clear the cache only at the layer that is stale
On a Windows client, run ipconfig /flushdns to clear the client resolver cache. Then repeat the same lookup against the same DNS server. A Windows Server can have separate client and DNS service caches: Microsoft documents Clear-DnsClientCache for the DNS client cache and Clear-DnsServerCache for the DNS Server service cache. Clearing one does not clear the other (Microsoft Learn: Troubleshooting DNS Servers).
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
A client flush does not purge caches on recursive resolvers run by an ISP, organization, or public DNS provider. If the authoritative data is correct but a recursive resolver still returns an old answer, allow the applicable TTL or negative-cache period to expire, or use that resolver provider’s cache controls if available. Flushing a local cache cannot correct a wrong record or delegation.
Rank #4
5. Verify authoritative records and nameserver delegation
If the domain owner or DNS administrator recently changed records or moved providers, verify the authoritative layer:
- Confirm that the registrar delegates the domain to the nameservers currently hosting its zone.
- Check that the record is in the correct zone and has the intended name, type, target, and TTL.
- Check for leftover nameserver delegation or security data from a previous provider.
- After correcting authoritative data or registrar delegation, query the authoritative nameserver and then the recursive resolver again.
If the authoritative answer is wrong, changing a device’s cache will not fix it. Correct the record at the authoritative DNS host, or update delegation at the registrar when that is the error.
6. Investigate DNSSEC when validation may be failing
DNSSEC helps resolvers validate DNS data, but a mismatch in the chain of trust can cause validating resolvers to return SERVFAIL. A common situation is stale DS data left at the registrar after a nameserver change. Cloudflare’s troubleshooting guide describes checking the chain and using dig with +cd (checking disabled) as a diagnostic comparison (Cloudflare: Troubleshooting DNSSEC).
Recommended Free Tools
If a normal validated lookup returns SERVFAIL but a query with checking disabled returns data, treat that as evidence to investigate DS/DNSKEY alignment—not as proof that the unchecked answer is authentic. Correct the DNSSEC data at the registrar or authoritative provider, or restore a valid signed chain. Do not leave validation disabled as the fix. RFC 9520 also notes that DNSSEC validation failures can be cached, so a resolver may continue to return a cached failure briefly after the underlying configuration is repaired.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.7. Treat encrypted DNS as a transport and policy choice
DNS over HTTPS (DoH) and DNS over TLS (DoT) encrypt DNS traffic between a client and resolver. They do not create missing records, repair incorrect delegation, or fix a broken DNSSEC chain. On a managed network, an unapproved encrypted resolver can also bypass protective DNS filtering and organizational controls. CISA’s warning about using upstream resolvers other than approved protective resolvers applies to federal agencies; it is not a universal recommendation for every network (CISA: Addressing DNS Resolution on Federal Networks Memo).
For Windows Server DoH deployments, check the service state, endpoint URI, certificate trust, client connectivity, firewall access to the configured TCP port, and upstream resolution. Keep approved resolver and filtering policies intact on organizational devices. CISA encourages encrypted communications, but the appropriate resolver depends on the network’s privacy, security, and operational requirements (CISA guidance on encrypting DNS traffic).
8. Consider LLMNR as a separate local-network security issue
Link-Local Multicast Name Resolution (LLMNR) is a Windows name-resolution mechanism that may be used when DNS is unavailable or fails. CISA warns that LLMNR poisoning can enable man-in-the-middle activity and credential harvesting. Disabling LLMNR is an administrator security-hardening decision, not a routine end-user repair for a website that will not resolve. Administrators should inventory dependencies and test applications first; disabling it can disrupt software that relies on it. Where it cannot be disabled, consider network segmentation (CISA: Disable Link-Local Multicast Name Resolution (LLMNR) Service (CM0053)).
Quick Recap
When to escalate
- Contact your network or DNS administrator if multiple clients fail, the configured resolver times out, or firewall, service, or resolver-log checks are needed.
- Contact the domain’s DNS host or registrar if authoritative records, nameserver delegation, or DS/DNSKEY data are wrong.
- Keep evidence with the report: the exact name and error, timestamp, network, configured resolver, direct-query result, and any recent configuration change. Avoid disabling DNSSEC, bypassing managed filtering, or changing a shared resolver until the responsible administrator has assessed the effect.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

