appzasGamesToolsDevLearnReferenceNetworkTimeCalculatorsCompareLLM prices

Querying DNS with dig

Lesson 4 of 410 minBeginner

Use dig to see exactly what DNS answers, from any resolver.

dig is the standard command-line DNS tool (on Debian and Ubuntu it comes in the dnsutils or bind9-dnsutils package). It shows the real answers, which beats guessing.

Everyday commands

dig example.com                 # A record, with the full answer
dig +short example.com          # just the value
dig AAAA example.com            # IPv6
dig MX example.com              # mail servers
dig TXT example.com             # SPF, verification records
dig NS example.com              # authoritative nameservers
dig @8.8.8.8 example.com        # ask a specific resolver
dig +trace example.com          # follow the delegation from the root
dig -x 93.184.216.34            # reverse lookup

Reading the answer

example.com.    3600    IN    A    93.184.216.34

The columns are: name, TTL (the seconds this cache will still keep it), class (IN for internet), type and value. If you ask the same resolver twice, the TTL counts down, which shows you the answer came from its cache.

Comparing resolvers

When a change "has not arrived", ask both the authoritative server and a public resolver:

dig +short NS example.com                  # which servers are authoritative
dig +short example.com @ns1.provider.com   # what the authority says
dig +short example.com @8.8.8.8            # what a cache says

If the authoritative server is right and the resolver is not, you are simply waiting for the cache to expire.

Other tools

  • nslookup example.com works on Windows and Unix with simpler output.
  • host example.com gives short, readable answers on Linux and macOS.

Test yourself

Answer all the questions, then check them. Finish with every answer right to mark the lesson as done.

Hintdig has a +short option.
HintUse @resolver and the record type.
3. In a dig answer, what does the number 3600 in the second column mean?

Key terms