> For the complete documentation index, see [llms.txt](https://docs.cloudeka.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.cloudeka.ai/reference/how-to-troubleshooting-dns/introduction.md).

# Introduction

The DNS is a critical aspect of modern network infrastructure. This section provides step-by-step procedures to help your organization verify DNS configuration, check domain security status, request category changes, and handle DNS unblock requests.

## DNS Troubleshooting Flow Overview

When experiencing DNS issues where a domain cannot be resolved properly, follow the step-by-step process below to identify the cause and determine the appropriate action:

### Verify DNS Resolution

Check whether the domain can be resolved properly using a DNS verification tool. For detailed instructions, see the [DNS Verification Steps](/reference/how-to-troubleshooting-dns/dns-verification-steps.md) section.

### Verify and Evaluate PTR Record

Use the **PTR Record** to perform an initial verification of the hostname associated with the domain's IP address. For more information on how to perform verification using a PTR (Pointer) Record, refer to the [Using PTR Records](/reference/how-to-troubleshooting-dns/using-ptr-records.md) section.

After performing the PTR (Pointer) Record verification, review the results to ensure that the hostname shown is valid and correct.

* If the **PTR Record is valid**, proceed to check the domain category using [Palo Alto URL Filtering.](/reference/how-to-troubleshooting-dns/checking-in-palo-alto-url-filtering.md)
* If the **PTR Record is invalid**, proceed with further investigation before continuing to the next check. Possible causes of an invalid PTR (Pointer) Record include a **PTR (Pointer) Record that has not been configured on the DNS server, an incorrect PTR (Pointer) Record configuration or one that points to an incorrect hostname, DNS propagation still in progress after a change, or the ISP/hosting provider has not configured the PTR (Pointer) Record for the IP address**. If the PTR Record has not been configured or there is an issue with its configuration, **contact the DNS Administrator or Hosting Provider** to check and configure the PTR (Pointer) Record.

### Check Domain Category in Palo Alto URL Filtering

Use **Palo Alto URL Filtering** to check the domain category and security status. Enter the domain or URL you want to check, then review the category provided by Palo Alto Networks. For detailed steps, refer to the [Checking in Palo Alto URL Filtering](/reference/how-to-troubleshooting-dns/checking-in-palo-alto-url-filtering.md) section.

### Check Security Category

Review the Palo Alto check results to determine whether the domain belongs to a **Security** category, such as categories indicating potentially harmful activity.

* If the domain **belongs to a Security category**, proceed to the [DNS Unblock Handling and Request ](#dns-unblock-handling-and-request)process.
* If the domain **does not belong to a Security category**, no further action is required.

### DNS Unblock Handling and Request

If the domain belongs to a Security category, take the following two actions:

* **Report to the DNS Service Provider** to report the issue and provide supporting information.
* **Fill Out the DNS Unblock Request Form** if the domain is legitimate and meets the requirements for unblocking. For more information about this process, refer to [How To Request a DNS Category Change](/reference/how-to-troubleshooting-dns/how-to-request-a-dns-category-change.md).
