DNS lookup fails but ping to IP works: 3 tests to find the cause
By Daniel Brooks Published 9 min read
On this page (8 sections)
- Key takeaways
- Why DNS lookup can fail while ping to IP succeeds
- How to test DNS server reachability with nslookup and dig
- How to check and adjust your DNS resolver settings
- Fallback to public DNS servers with exact commands
- How to interpret ping and nslookup results to identify the failing component
- How to stop DNS lookup failures happening again
- Questions people still ask
In short: DNS lookup fails but ping to IP works because DNS resolution is broken while direct IP routing is fine. Test with nslookup or dig, verify resolver settings, then try a public DNS like 8.8.8.8 to isolate the problem.
Part of our guide on how to run an internet speed test
This page guides you through testing DNS resolution step-by-step to pinpoint why DNS lookup fails even though ping to IP succeeds.
| Ping success | IP reachable |
|---|---|
| DNS failure | No name resolution |
| Common public DNS | 8.8.8.8 |
| DNS test tools | nslookup, dig |
| Typical TTL | 30-300 seconds |
Key takeaways
- DNS failure means domain names can’t resolve, but IP connectivity may still be healthy.
- Use nslookup or dig to test DNS server response precisely.
- Check your system’s DNS resolver IP and network settings first.
- Fallback to a reliable public DNS server like Google’s 8.8.8.8 to confirm DNS issues.
- Interpreting ping vs. DNS results helps pinpoint whether the issue is local, network, or server-based.
Why DNS lookup can fail while ping to IP succeeds
When DNS lookup fails but ping to IP works, it means your network can reach the device but cannot translate domain names to IP addresses.
DNS resolution depends on your DNS resolver or server responding correctly. If the DNS server is down, misconfigured, or unreachable, domain names won’t resolve.
Meanwhile, ping by IP bypasses DNS entirely. Success in pinging IP confirms that basic network connectivity functions.
Common causes include incorrect DNS settings on your device, firewall rules blocking DNS (UDP port 53), or your ISP's DNS servers failing. If that sounds like your situation, read up on how does dns run the internet next.
An additional reason DNS lookup can fail while ping to IP succeeds is intermittent DNS server response. Sometimes the DNS server may be reachable but slow or overloaded, causing timeouts or incomplete responses. This would lead to failed lookups even when network connectivity is intact.
Another scenario involves DNS cache poisoning or corrupted local DNS cache on your device. In such cases, the DNS resolver returns wrong or outdated results, causing lookup failure despite working IP routes. Flushing the DNS cache (e.g., ipconfig /flushdns on Windows) can resolve this issue by forcing fresh queries.
Some specialized network setups use split DNS, where internal domains resolve only on internal DNS servers. If you try to resolve such domains from outside the internal network, lookups will fail but ping to known IPs may still work if routing allows it. This is common in corporate VPN environments. It helps to understand mesh wifi slow after adding second node before going further.
- DNS server unreachable: your system can't contact the DNS server.
- Resolver misconfiguration: wrong DNS IP set on your device.
- Local firewall or network blocks DNS requests.
- ISP DNS outage or misbehavior.
How to test DNS server reachability with nslookup and dig
Use nslookup or dig commands to query your DNS server directly and check if it responds with domain name IP mappings.
On Windows, run: nslookup example.com. On Mac/Linux, run: dig example.com.
If these commands return an IP address, your DNS server is reachable and working for that domain. There is more on retry connections wget in a separate guide.
If they time out or report errors like 'server can’t be reached' or 'connection timed out,' your DNS server is either unreachable or malfunctioning.
You can also test DNS server responsiveness by specifying the DNS server explicitly in nslookup or dig. For example, nslookup example.com 8.8.8.8 queries Google’s public DNS, bypassing your configured resolver. Success here indicates your local DNS server is at fault.
With dig, use dig @8.8.8.8 example.com to test a specific server. This helps isolate whether the DNS failure is local or upstream. If only your configured DNS fails, switching to a public DNS might fix the issue. The other half of this decision is stabilizing internet connection.
Be aware that some DNS servers enforce rate limits or block certain queries. If you receive SERVFAIL or REFUSED responses, it could signify server policy issues or DNSSEC validation failures. These cases require additional troubleshooting steps like checking DNSSEC settings or server logs.
- Open your command prompt or terminal.
- Type nslookup example.com or dig example.com and press enter.
- Note if you get an IP address or an error message.
- Try querying a known reliable site like google.com if needed.
| Result | Meaning | Action |
|---|---|---|
| IP address returned | DNS server is reachable and resolving | No DNS server problem here |
| Timeout or no response | DNS server is unreachable or blocked | Check DNS server IP and firewall |
| NXDOMAIN or no such domain | Domain name not found | Possibly domain issue, try another domain |
How to check and adjust your DNS resolver settings
Your device uses DNS resolver IP addresses configured manually or via DHCP from your router.
Check your current DNS server settings on Windows with ipconfig /all, on Mac via System Preferences > Network > Advanced > DNS, or on Android/iPhone in the Wi-Fi settings. We go through how to fix an internet connection step by step elsewhere on the site.
If the DNS IP addresses look incorrect, private, or blank, your system can’t resolve DNS reliably.
Change DNS servers to known public ones like Google’s 8.8.8.8 or Cloudflare’s 1.1.1.1 to test if DNS failures stop.
On some devices, DNS settings can be overridden by VPN or proxy configurations. These may redirect DNS queries to different servers, causing unexpected failures if those servers are unreachable. We cover does speed enhancement software actually work in its own article.
In enterprise environments, DNS settings might be centrally managed via group policies or network profiles, preventing manual changes. If local adjustments don’t persist, check with your system administrator.
When manually changing DNS servers, ensure you update both IPv4 and IPv6 DNS addresses if applicable. Some devices prefer IPv6 DNS, and leaving those empty can cause resolution failures despite correct IPv4 settings.
- Find DNS settings on your device (varies by OS).
- Note current DNS IP addresses.
- Replace with public DNS IPs: 8.8.8.8 and 8.8.4.4 (Google) or 1.1.1.1 and 1.0.0.1 (Cloudflare).
- Save and reconnect network, then retest DNS lookup.
Fallback to public DNS servers with exact commands
Switching to public DNS servers is a reliable way to bypass problematic ISP or internal DNS.
On Windows, use: netsh interface ip set dns "Wi-Fi" static 8.8.8.8 to set Google DNS.
On Mac, you can use networksetup -setdnsservers Wi-Fi 8.8.8.8 8.8.4.4 in Terminal.
On Linux, edit /etc/resolv.conf to add nameserver 8.8.8.8 or use nmcli tool to configure NetworkManager DNS settings.
After switching, run nslookup or dig again to confirm the DNS resolution works.
If you experience DNS lookup failures after switching to public DNS servers, verify that your network allows outbound DNS queries to external servers. Some corporate or ISP firewalls restrict DNS to specific IPs.
When editing /etc/resolv.conf on Linux, note that some distributions overwrite the file on reboot or network restart. Use tools like resolvconf or NetworkManager to make persistent changes.
After changing DNS servers, clearing the DNS cache on your device and browsers helps avoid stale results. For example, on Mac, use sudo killall -HUP mDNSResponder to flush the DNS cache.
| OS | Command to set Google DNS | Restart required |
|---|---|---|
| Windows | netsh interface ip set dns "Wi-Fi" static 8.8.8.8 | No, reconnect network |
| Mac | networksetup -setdnsservers Wi-Fi 8.8.8.8 8.8.4.4 | No, reconnect Wi-Fi |
| Linux | Edit /etc/resolv.conf or nmcli dev set dns 8.8.8.8 | Yes, restart network service |
How to interpret ping and nslookup results to identify the failing component
If ping to an IP succeeds but nslookup to the domain fails, the problem lies in DNS resolution, not basic connectivity.
If nslookup to your configured DNS server times out but ping succeeds, your DNS server is unreachable or blocked.
If nslookup returns an error but you can ping the DNS server IP, the server is reachable but may not resolve names correctly.
If both ping and nslookup fail, your network connection is problematic beyond DNS.
A practical test is to ping the DNS server IP itself. If ping to the DNS server fails but ping to other IPs succeeds, your DNS server may be down or blocked by network rules.
If nslookup returns SERVFAIL or NXDOMAIN errors, it indicates the DNS server responded but could not resolve the domain. This points to issues with the server’s zone data or forwarding settings.
Combining ping and nslookup with traceroute to the DNS server IP can pinpoint network routing issues. For example, traceroute failures to the DNS server indicate network path problems affecting DNS resolution.
| Ping result | Nslookup result | Likely cause |
|---|---|---|
| Success | Success | No network or DNS issue |
| Success | Fail (timeout) | DNS server unreachable or blocked |
| Success | Fail (error response) | DNS server misconfigured or domain unknown |
| Fail | Fail | Network connectivity issue |
How to stop DNS lookup failures happening again
Keep your DNS resolver settings stable and avoid switching to unknown DNS servers unless necessary.
Regularly update your device and router firmware to fix bugs impacting DNS.
Use a secondary public DNS server as fallback in your settings to ensure redundancy.
Avoid firewall or security software rules that block outbound UDP port 53 or TCP port 53 needed for DNS.
If your ISP’s DNS is unreliable, consider permanently switching to a trustworthy public DNS provider.
Automatically renewing DHCP leases can reset DNS settings unexpectedly. To avoid this, set static DNS servers or configure your router to hand out reliable DNS addresses.
Monitoring DNS server logs or using diagnostic tools like Wireshark can help detect intermittent DNS failures or unusual query patterns.
Testing DNS resolution from multiple devices on the same network can reveal if the problem is device-specific or network-wide. If only one device fails, focus on its DNS configurations and local software.
- Firmware updates: prevent DNS bugs.
- Double DNS entries: improve availability.
- Firewall rules: check for DNS blocking.
- Avoid manual DNS changes from unknown sources.
Testing DNS with nslookup and fallback to public DNS reliably isolates DNS resolution issues from network problems.
Questions people still ask
Why can I ping a website’s IP but not access it in a browser?
Ping to IP tests network reachability, but web access requires DNS to resolve domain names. DNS failure means the browser can't find the site’s IP, even if the IP is reachable.
How can I find out which DNS server my device uses?
Use ipconfig /all on Windows, network settings on Mac, or check Wi-Fi details on phones. The listed DNS server IPs are what your device uses.
Can DNS failure be caused by malware?
Yes, some malware changes DNS settings to redirect traffic or block resolution. Running malware scans and resetting DNS to trusted servers can help.
Is switching to public DNS servers always safe?
Public DNS servers by reputable providers are usually safe and can increase reliability and speed. Avoid unknown or suspicious DNS servers for privacy and security reasons.
What ports and protocols does DNS use that might be blocked?
DNS mostly uses UDP port 53 for queries. Sometimes TCP port 53 is used for larger transfers. Blocking these ports will stop DNS resolution.