What a PTR record is

Reverse DNS maps an IP address back to a hostname using a PTR record published in the special in-addr.arpa zone for IPv4, or ip6.arpa for IPv6, as described in RFC 1035. Unlike forward DNS, which the domain owner controls, reverse DNS for an address is normally set by whoever controls that IP address block, typically the hosting provider or internet service provider, not the website or domain operator.

Why it often does not match the domain

Because the hosting provider usually sets the PTR record, it very often shows a generic hostname belonging to that provider's own naming scheme, such as a string of numbers under a hosting company's domain, rather than anything resembling the website being investigated. This is completely normal for shared hosting, cloud platforms and most consumer and business internet connections, and a mismatch between the forward hostname and the reverse PTR name is not, on its own, a sign of anything suspicious.

Mail server configurations are one of the few places reverse DNS matters practically: many receiving mail systems check that a sending IP has a PTR record at all, and some expect it to resolve to a name in the same organisation, because missing or mismatched reverse DNS is historically correlated with poorly configured or abusive sending systems. Even there it is treated as one signal among several, not a standalone verdict.

Using it in an investigation

Reverse DNS can support identifying which hosting provider actually controls an IP address, since the PTR hostname's domain often names the provider directly even when RDAP network ownership data is sparse. It can also, in some cases, hint at which specific shared platform or service tier a server belongs to. It should never be used alone to attribute a website to an operator, since the provider, not the operator, chooses the PTR value.

Reverse DNS lookups of arbitrary IP addresses are not part of a standard public DNS or RDAP domain report; a public DNS report for a domain name returns the records published under that name, such as A, AAAA, MX, NS and TXT, not the PTR record for an IP address it resolves to. Investigators who need PTR data for an IP should query it directly against the relevant in-addr.arpa or ip6.arpa zone, or use a general-purpose DNS lookup tool, and record the resolver and time used, since reverse DNS can change independently of the forward record.

  • Query the PTR record directly for the IP in question.
  • Expect a provider-branded hostname rather than the website name.
  • Use PTR mainly to help identify the hosting provider, not the operator.
  • Note resolver and timestamp, since PTR records can change.
  • Do not treat a PTR mismatch alone as evidence of wrongdoing.

Sources and further reading

RFC 1035, Domain names, implementation and specificationIANA, in-addr.arpa and ip6.arpaM3AAWG, Sending domain and IP reputation
This resource supports investigative triage. It is not legal advice, an attribution finding or a certification that a website is safe.