Querying DNS with dig
Use dig to see exactly what DNS answers, from any resolver.
dig is the standard command-line DNS tool (on Debian and Ubuntu it comes in the dnsutils or bind9-dnsutils package). It shows the real answers, which beats guessing.
Everyday commands
dig example.com # A record, with the full answer
dig +short example.com # just the value
dig AAAA example.com # IPv6
dig MX example.com # mail servers
dig TXT example.com # SPF, verification records
dig NS example.com # authoritative nameservers
dig @8.8.8.8 example.com # ask a specific resolver
dig +trace example.com # follow the delegation from the root
dig -x 93.184.216.34 # reverse lookupReading the answer
example.com. 3600 IN A 93.184.216.34The columns are: name, TTL (the seconds this cache will still keep it), class (IN for internet), type and value. If you ask the same resolver twice, the TTL counts down, which shows you the answer came from its cache.
Comparing resolvers
When a change "has not arrived", ask both the authoritative server and a public resolver:
dig +short NS example.com # which servers are authoritative
dig +short example.com @ns1.provider.com # what the authority says
dig +short example.com @8.8.8.8 # what a cache saysIf the authoritative server is right and the resolver is not, you are simply waiting for the cache to expire.
Other tools
nslookup example.comworks on Windows and Unix with simpler output.host example.comgives short, readable answers on Linux and macOS.
Test yourself
Answer all the questions, then check them. Finish with every answer right to mark the lesson as done.