Reverse DNS lookup

Examples:

Transparency

A browser cannot query the DNS directly. Your browser therefore asks a public DNS resolver, the one you choose among four, over HTTPS (DNS over HTTPS). The server of r-no.fr is not involved: it never sees the address you look up.

What the resolver sees
Each lookup sends to the chosen resolver, and to it alone, the reverse name of the address (for example 139.6.0.193.in-addr.arpa), then the name or names found, to check them. Like any website, the resolver receives your IP address with these requests, and learns that they come from r-no.fr (the Origin header, which browsers send and pages cannot remove). No cookie is sent.
The four resolvers
  • DNS4EU, European Union: a project co-funded by the EU, run by Whalebone (Czech Republic), unfiltered version unfiltered.joindns4.eu. Its commitments.
  • Quad9, Switzerland: a Swiss foundation, version without block list dns10.quad9.net. Its commitments.
  • Cloudflare, United States: cloudflare-dns.com. Its commitments.
  • Google Public DNS, United States: dns.google. Its commitments.
Always the version without filtering: a diagnostic tool must see the real answer, not that of a block list. Only resolvers that let a web page read their answers can be offered here: your browser requires it (the Access-Control-Allow-Origin header). On 28 September 2026, no French public resolver allowed it (FDN, Aquilenet, La Contre-Voie…): they will be added if that changes.
Enforced by your browser
This page's Content Security Policy allows the four resolvers (https://unfiltered.joindns4.eu, https://dns10.quad9.net, https://cloudflare-dns.com, https://dns.google), and this site itself, for the “My address” button, which asks ip/my-ip. No form submission (form-action 'none'). One more destination is allowed, as on every page of the site: https://stats.r-no.fr, the audience measurement (see below). You can read the policy at the top of the page source.
Audience measurement
Like every page of the site, this one counts its visit with Umami, installed on R-no’s own server (stats.r-no.fr). It receives the address of the page, without parameters or anchor, the site you came from (its domain only), your browser, system, language and screen size, and the country, region and city deduced from your IP address, which is not kept. It never receives what you type, nor the result of the tool. No cookie, nothing stored in your browser; if your browser asks not to be tracked (Do Not Track), nothing is measured. The data is erased after 25 months.
  • /commun/mesure.js: the filter applied before each sending, written for R-no Toolbox. 1.4 kB
    SHA-256 225eec74fd12623d82fc05ee7d222be629ce454d081c129e8d1e249ed37ee716
  • https://stats.r-no.fr/m.js: Umami’s tracker, open source (MIT), served by the measurement server. Its fingerprint is not shown here: it changes with each version of Umami, and you cannot check from your browser that it is the published code. For that part, you have to trust R-no.
What is never sent
Private, local, documentation and other reserved addresses (10.0.0.0/8, 192.168.0.0/16, fe80::/10…) are recognised in your browser and never sent: public DNS has no name for them, and they describe an internal network.
Guardrail
This page makes at most 20 lookups per minute. The requests leave from your address, not from the server, but they carry the r-no.fr origin: the limit keeps r-no.fr welcome at the resolvers.
What is stored
No cookie, and nothing in the address of this page: a lookup cannot be found in the server's logs. What you type is not kept. Your language is given by the address itself (/en/ or /fr/): nothing is stored to remember it. Like any website, the server records the download of the page and its files in its access logs (IP address, date and time, address requested, browser name), and the “My address” button's request in the same way.
Code that runs here
  • app.js: builds the reverse name, asks the chosen resolver, and checks each name found. Written for R-no Toolbox, not minified, no third-party library. 20.7 kB
    SHA-256 c21e04a9cea8618c6a45d19089e33cb846c9b08957ab7044dedcfe54ab074563
  • /commun/doh.js: the DNS over HTTPS format (RFC 8484), shared with domains/dns: it writes the question as a DNS packet, reads the binary answer, and holds the list of the four resolvers. It makes no request itself. Written for R-no Toolbox, not minified, no third-party library. 16.5 kB
    SHA-256 88afaa695a1c2b3212d3cc449b81add7736a6756d96213ecd5771cddc09129a1
  • textes.js: the French messages of the tool, shown by its script (the rest of the French page is written into its HTML when the site is built). It only defines texts, with no logic. 10.4 kB
    SHA-256 2528691a26aa12e3f538d9fe106e18bbabe6b79edaf584cd078103e6459fb0b3
  • /commun/langue.js: the language helper, the same on every page of the site. It reads the language of the page and gives the tool its messages in that language. It stores nothing. 1.6 kB
    SHA-256 80f76f69773ef628d36d09bf8387cfedebda4529210d7120649b6f5603310631
Tested
The reverse names, the writing of questions, the reading of binary DNS answers (real answers recorded from the four resolvers) and the check of each name are covered by automated tests, run on every deployment.
Check it yourself
Download the script and compare its fingerprint with the one above:
curl -s https://r-no.fr/ip/reverse/app.js | shasum -a 256
Limits
The answer is the one of the chosen resolver at that moment, which may keep it in cache for the time shown (TTL). Up to five names are checked for one address. Your browser's own DNS settings are not used: the lookup always goes to the resolver chosen on this page.