dig: DNS Lookup Utility

dig (domain information groper) is a flexible command-line tool for interrogating DNS name servers. It performs DNS lookups and displays the answers that are returned from the name server(s) that were queried. dig is widely used by network administrators and developers for troubleshooting DNS-related issues, verifying DNS records, and performing network reconnaissance.

1. Basic DNS Lookups

Standard Query

Performs a simple A record lookup for a domain.

dig <domain.com>
# Example:
dig google.com

Query All Record Types (ANY)

Retrieves all available DNS record types for a domain.

dig <domain.com> ANY
# Example:
dig google.com ANY

2. Specific Record Types

You can query for specific DNS record types (e.g., MX for mail exchange, NS for name servers, TXT for text records).

Mail Exchange (MX) Record

dig <domain.com> MX
# Example:
dig google.com MX

Name Server (NS) Record

dig <domain.com> NS

Text (TXT) Record

dig <domain.com> TXT

3. Advanced Queries

Specify a Custom DNS Server

Query a particular DNS server instead of your system’s default configured server.

dig @<dns_server_ip> <domain.com>
# Example: Using Google's Public DNS
dig @8.8.8.8 google.com

Specify a Custom Port

Query a DNS server that is listening on a non-standard port.

dig -p <port_number> <domain.com>
# Example:
dig -p 5300 google.com

Query from a File

Perform multiple dig queries from a list of domains in a file.

dig -f <file.txt> +short
  • -f <file.txt>: Reads a list of queries to process from the specified file.
  • +short: Provides a concise output, showing only the answers.

4. Troubleshooting and Diagnostics

Trace the DNS Delegation Path (+trace)

Traces the delegation path from the root name servers to the authoritative name server for the queried domain. This helps diagnose delegation issues.

dig <domain.com> +trace
# Example:
dig google.com +trace

Reverse DNS Lookup (-x)

Performs a reverse DNS lookup (PTR record) to find the domain name associated with an IP address.

dig -x <target_ip>
# Example:
dig -x 216.58.220.110

Common dig Options (often combined with others):

  • +short: Display only the answer section.
  • +noall +answer: Show only the answer section (similar to +short but offers more control).
  • +noall +stats: Show only statistics (like query time).