Overview
If your website does not open, the problem is not always with DNS. Several different systems are involved between entering a website address and seeing the website in your browser.
DNS is the system that looks up a domain name, such as example.com, and provides information that your computer can use to reach the destination. After that lookup succeeds, your computer still needs to connect to the system providing the website.
This means a website can fail to open even when its DNS lookup is working. The problem can occur later in the connection, such as at a web server, content delivery network (CDN), proxy, web application firewall (WAF), load balancer, or during the secure HTTPS connection.
The steps below help determine which part of the connection needs further investigation. These instructions are for Windows. You do not need to understand the command results. If you contact UltraDNS Support, send us the complete results and we can review them.
When to Use This Article
Use these steps when a domain or website does not open as expected in your browser.
You may see an error such as:
Server IP address could not be foundThis site can't be reachedConnection timed outConnection refused- An error page displayed by a CDN, proxy, WAF, or hosting provider
The browser message alone does not determine whether DNS is the source of the problem. The following tests check DNS and the website connection separately.
Before You Begin
Perform these tests from a Windows computer where you are experiencing the problem.
Open Command Prompt:
- Open the Windows Start menu.
- Type
cmd. - Select Command Prompt.
In each command below, replace example.com with the domain that is not working.
Step 1: Check the DNS Lookup
The first test checks what DNS information your computer currently receives for the domain.
Run:
nslookup example.com
The result includes information about the DNS server your computer asked and the response that server returned.
For example, a result may look similar to:
Server: resolver.example Address: 192.0.2.53 Name: example.com Address: 192.0.2.100
An address in the result shows that the DNS server returned an address for that lookup. This does not by itself confirm that the returned address is the correct address for the website. UltraDNS Support can compare the result with the expected DNS configuration.
If the command returns an error or does not return an address, keep the complete result. The error provides information that can be used for further DNS troubleshooting.
Step 2: Compare the DNS Result
Your computer normally uses a DNS service provided by your organization, network, or Internet provider. The next two commands ask two public DNS services for the same domain.
First, check using Google Public DNS:
nslookup example.com 8.8.8.8
Then check using Cloudflare DNS:
nslookup example.com 1.1.1.1
Keep the complete result from both commands.
Comparing these results helps determine whether different DNS services are returning the same information. For example, if your normal DNS lookup fails while the public DNS lookups return an address, the results show that the DNS responses are different and help identify where additional investigation is needed.
Some networks restrict connections to external DNS services. If either public DNS command returns an error, include that complete error with the other results.
Step 3: Test the Website Connection
The previous commands test DNS. The next commands test the connection to the website.
This distinction is important. DNS can return the expected destination while another system involved in providing the website prevents the page from loading.
On current Windows systems, curl.exe can be used to test the web connection.
First, test the HTTP connection:
curl.exe -v http://example.com/
Then test the secure HTTPS connection:
curl.exe -v https://example.com/
Keep the complete result from both commands.
These results provide information about what happens when your computer attempts to connect to the website. Depending on the result, the connection may return a website response, a redirect, a connection error, a TLS or certificate error, or an error generated by another service handling the website.
What the Results Can Tell Us
The tests separate the DNS lookup from the website connection.
- If DNS does not return the expected information, the DNS configuration or DNS resolution path may require further investigation.
- If different DNS services return different results, those differences provide information for further DNS troubleshooting.
- If DNS returns the expected information but the website connection fails, the next investigation may need to focus on what happens after the DNS lookup.
- If the website test returns an error page from a CDN, proxy, WAF, hosting provider, or web server, the request reached that system. The error returned by that system provides information for the next troubleshooting step.
A successful DNS lookup does not mean that the website itself is working. It means that DNS returned a result for that specific test.
Why Ping Is Not a Website Test
You may also try to ping the domain or its IP address and receive no response. A failed ping does not establish that DNS or the website is unavailable.
Ping uses a network protocol called ICMP. Websites use different protocols, primarily HTTP and HTTPS. A server or network can ignore ping requests while continuing to accept website connections.
For this troubleshooting process, use nslookup to check DNS and curl.exe or your browser to check the website connection.
Information to Send UltraDNS Support
If you need assistance after completing the tests, send UltraDNS Support the complete output from these commands:
nslookup example.comnslookup example.com 8.8.8.8nslookup example.com 1.1.1.1curl.exe -v http://example.com/curl.exe -v https://example.com/
Replace example.com with the affected domain before running each command.
Copy the complete output from each command. You do not need to determine what the results mean before contacting Support. The results provide the information needed to determine whether additional investigation should focus on DNS resolution or the website connection.