How to fix dns not resolving ip address: Practical Guide
Step-by-step guide to diagnose and fix DNS resolution failures. Learn safe troubleshooting methods to restore name resolution quickly.

On this page
- Understanding DNS Resolution and Common Failure Points
- Initial Diagnosis: Isolating the Resolution Failure
- Clearing Local DNS Caches
- Verifying Nameserver Configuration at Domain Registrar
- Checking Authoritative DNS Records
- Understanding and Managing DNS Propagation
- Advanced Troubleshooting and Network-Level Issues
TL;DR — Key takeaways
- DNS resolution failures occur when a domain name cannot be translated to an IP address, typically caused by misconfigured nameservers, propagation delays, or local cache issues.
- Start troubleshooting by verifying nameserver configuration at your domain registrar, then test resolution using dig or nslookup to isolate whether the issue is local or authoritative.
- Clear local DNS caches on your device and flush resolver caches on your network to eliminate stale records before investigating upstream configuration problems.
- Propagation delays after DNS changes can take 24-48 hours; verify changes were applied correctly at the authoritative level before waiting for full propagation.
- Use multiple DNS testing tools and query different public resolvers to confirm whether resolution works globally or only fails from specific locations or networks.
DNS resolution is the process that translates human-readable domain names into IP addresses that computers use to communicate. When DNS stops resolving, websites become unreachable even though servers remain online. This guide walks through systematic troubleshooting to identify and fix DNS resolution failures.
You'll learn how to diagnose the root cause, whether it's local cache corruption, incorrect nameserver configuration, propagation delays, or authoritative zone issues. Each section provides safe, testable steps you can perform without disrupting working services.
Understanding DNS Resolution and Common Failure Points
DNS resolution follows a hierarchical query path. Your device asks a recursive resolver (usually your ISP or a public DNS service like 8.8.8.8), which queries root servers, then TLD nameservers, then authoritative nameservers for your domain. Failures can occur at any point in this chain.
Common failure points include: misconfigured nameservers at your domain registrar, missing or incorrect DNS records at your hosting provider, local cache containing outdated information, network-level DNS blocking, or propagation delays after recent changes. Identifying which layer is failing determines the fix.
- Local resolver cache: stale records on your device or router
- Recursive resolver issues: problems with your ISP or public DNS service
- Authoritative configuration: incorrect nameservers or missing zone records
- Propagation state: changes not yet distributed globally
- Network interference: firewall rules or ISP-level filtering
Initial Diagnosis: Isolating the Resolution Failure
Start by confirming the domain truly fails to resolve. Open a terminal or command prompt and run 'nslookup yourdomain.com' (replace yourdomain.com with your actual domain). If it returns 'server can't find' or times out, resolution is failing. If it returns an IP address, the issue may be application-specific or intermittent.
Next, test against multiple DNS resolvers to determine scope. Run 'nslookup yourdomain.com 8.8.8.8' to query Google's public DNS, then 'nslookup yourdomain.com 1.1.1.1' for Cloudflare's resolver. If resolution works on public DNS but fails on your local resolver, the problem is likely local cache or ISP-level. If it fails everywhere, the authoritative configuration is incorrect.
- Test resolution with your default resolver first
- Query at least two different public DNS services
- Note whether failure is consistent or intermittent
- Check if other domains resolve correctly to rule out network issues
- Record exact error messages for reference
Clearing Local DNS Caches
DNS caches store previous lookup results to improve performance, but stale cache entries cause resolution to fail even after upstream fixes. Clear caches at multiple levels: your operating system, web browser, and local router.
On Windows, open Command Prompt as administrator and run 'ipconfig /flushdns'. On macOS, run 'sudo dscacheutil -flushcache; sudo killall -HUP mDNSResponder' in Terminal. On Linux, the command depends on your resolver service: 'sudo systemd-resolve --flush-caches' for systemd-resolved, or 'sudo service nscd restart' for nscd. Restart your browser after flushing system cache.
- Flush operating system DNS cache using OS-specific commands
- Clear browser cache or restart browser completely
- Reboot your router if it maintains a cache (check router documentation)
- Wait 2-3 minutes after flushing before retesting resolution
- Document whether flushing cache resolves the issue
Verifying Nameserver Configuration at Domain Registrar
Nameservers tell the global DNS system where to find authoritative records for your domain. Incorrect nameserver configuration at your domain registrar is a frequent cause of resolution failure, especially after transfers or hosting changes.
Log into your domain registrar's control panel and locate the nameserver or DNS management section. Verify the listed nameservers match those provided by your hosting company or DNS provider. Common hosting nameservers follow patterns like ns1.hostingcompany.com and ns2.hostingcompany.com. If they don't match or point to old providers, update them. After updating, propagation begins but may take 24-48 hours to complete globally.
- Confirm current nameservers listed at your registrar
- Compare against nameservers provided by your hosting or DNS service
- Check for typos in nameserver hostnames
- Ensure at least two nameservers are configured for redundancy
- Document old and new nameserver values before making changes
Understanding and Managing DNS Propagation
DNS propagation is the time required for changes to distribute across the global DNS infrastructure. TTL (Time To Live) values in DNS records control how long resolvers cache responses. If you recently changed nameservers or DNS records, resolution may fail intermittently as caches expire at different rates worldwide.
Use online DNS propagation checkers to view resolution status from multiple geographic locations. These tools query various public resolvers globally and show whether your changes have reached each location. Propagation typically completes within 24-48 hours, but old TTL values can extend this. You cannot speed propagation globally, but lowering TTL before making changes reduces delay. After changes propagate, increase TTL again to reduce query load.
- Expect 24-48 hours for full global propagation after nameserver changes
- Record-level changes propagate faster, typically within the record's TTL period
- Lower TTL to 300-600 seconds at least 24 hours before planned changes
- Monitor propagation progress using global DNS checking tools
- Avoid making multiple changes rapidly; wait for each to propagate
Advanced Troubleshooting and Network-Level Issues
If standard fixes don't resolve the issue, investigate network-level problems. Some ISPs or corporate networks implement DNS filtering, redirect queries, or block certain domains. Test by switching to a mobile hotspot or different network. If resolution works on alternate networks, the problem is network-specific.
Check for DNSSEC validation failures by running 'dig yourdomain.com +dnssec'. If DNSSEC is enabled but misconfigured, validators reject responses. Disable DNSSEC at your DNS provider temporarily to test. Firewall rules blocking UDP port 53 or TCP port 53 can also cause failures. Ensure your firewall allows outbound DNS queries. For persistent issues after exhausting these checks, contact your hosting provider's support team with diagnostic results.
- Test resolution on different networks to isolate network-specific issues
- Check for DNSSEC misconfigurations if DNSSEC is enabled
- Verify firewall rules permit DNS traffic on UDP and TCP port 53
- Review recent network or security configuration changes
- Collect diagnostic output (dig, nslookup results) before contacting support
Quick troubleshooting checklist
- Run nslookup or dig to confirm resolution failure
- Test against multiple public DNS resolvers (8.8.8.8, 1.1.1.1)
- Flush local DNS caches on device, browser, and router
- Verify nameserver configuration at domain registrar
- Query authoritative nameservers directly to check zone records
- Check DNS propagation status if changes were made recently
- Test resolution from different networks or devices
- Review DNSSEC configuration if enabled
- Verify firewall permits DNS traffic on port 53
- Document all diagnostic results before escalating to support
FAQ
How long does it take for DNS changes to propagate globally?
DNS propagation typically takes 24 to 48 hours to complete globally after nameserver changes. Record-level changes (A, CNAME, MX) propagate faster, usually within the record's TTL period, which is often 1 to 24 hours. Propagation time depends on TTL values and how frequently resolvers refresh their caches.
Why does my domain resolve on some networks but not others?
Inconsistent resolution across networks indicates DNS propagation in progress, cached stale records on specific resolvers, or network-level DNS filtering. Some resolvers update faster than others, and ISP or corporate networks may cache records longer or implement content filtering that affects DNS responses.
What is the difference between recursive and authoritative DNS servers?
Authoritative DNS servers hold the actual DNS records for your domain and provide definitive answers. Recursive DNS servers (resolvers) query authoritative servers on behalf of clients and cache responses. When troubleshooting, querying authoritative servers directly bypasses resolver caches and shows the current configured state.
Can I speed up DNS propagation after making changes?
You cannot force faster propagation globally, but you can prepare by lowering TTL values to 300-600 seconds at least 24 hours before making changes. This shortens cache lifetimes so resolvers refresh sooner. After changes propagate fully, increase TTL back to 3600 or higher to reduce query load on authoritative servers.
How do I know if the problem is local cache or authoritative configuration?
Query your domain directly against authoritative nameservers using 'dig yourdomain.com @ns1.yourprovider.com' (replace with your actual nameserver). If the authoritative query succeeds but general resolution fails, the issue is cache or resolver-related. If the authoritative query also fails, the zone configuration is incorrect at the source.
Related articles
- Hosting OperationsSelf-Hosted App Deployment Fails? Check DNS, SSL, Reverse Proxy, and Logs FirstTroubleshoot failed self-hosted app deployments by checking DNS, SSL, reverse proxy routing, container status, logs, and ports.
- Hosting OperationsSelf-Hosted PaaS on a VPS: What to Check Before Installing Coolify, Dokploy, or CapRoverA hosting support checklist for preparing a VPS before installing self-hosted PaaS tools like Coolify, Dokploy, or CapRover.
- Hosting OperationsLinux Server Security Lessons from the Arch Linux Malware Package IncidentPractical Linux server security checklist for VPS admins after package malware concerns, with safe checks, rollback steps, and support guidance.
- Hosting OperationsAWS Lightsail Hong Kong VPS Latency: Practical Hosting Guide for IndonesiaLearn how to test AWS Lightsail Hong Kong VPS latency, compare regions, migrate safely, and troubleshoot hosting performance.
- Hosting OperationsCloudflare Tomorrow Watchlist: A Practical Hosting Operations GuidePractical Cloudflare troubleshooting checklist for DNS, SSL, caching, WAF, origin health, safe testing, and rollback planning.
- Hosting OperationsNetwork Safety Checklist for AI Agent Skills in Hosting OperationsAudit AI agent skills safely with network checks, secret protection, sandbox testing, rollback steps, and hosting support troubleshooting guidance.