dig: DNS Query Debugging in CLI
DNS resolvers return the wrong address, clients don’t see updates, or it’s unclear which server is handling requests. dig (Domain Information Groper) is the standard CLI tool for DNS diagnostics. Works on Linux, macOS, and Windows via WSL.
Installation
Basic Flags
dig has two classes of options: short flags (start with -) control query behavior, while keywords with + control output format.
Without arguments the output is verbose — lots of header information. For debugging you pick the pieces you need.
| Flag | Purpose |
|---|---|
-b <addr> | Outbound IP address (multi-interface hosts) |
-f <file> | Read queries from file, one per line |
-p <port> | Non-standard DNS server port |
-t <type> | Record type: A, AAAA, MX, TXT, SOA, NS, CNAME, ANY |
-c <class> | Network class (default: IN — Internet) |
-x <addr> | Reverse lookup (PTR) |
-6 | Force IPv6 |
-4 | Force IPv4 |
Quick Response: +short
For scripts and quick checks:
If the record doesn’t exist — empty output. For CNAMEs you see the final address but not the chain.
For AAAA records:
+short doesn’t show TTL and doesn’t guarantee it’s the final answer. A CNAME loop will return the last record in the chain, not an error.
Full Response: +noall +answer
When you need TTL, canonical name, and all records at once:
TTL in seconds. Small values (60–300) mean the record changes frequently.
Verbose response with timing:
Reverse Lookup: -x
Reverse zone: IP → hostname.
Not all PTR zones are populated. Empty response with -x is normal, especially for client addresses.
IPv6: -6
Force IPv6 transport to the DNS server:
If you want an AAAA record over IPv4 transport — just request the type:
Chain Tracing: +trace
Shows the path from root servers to the final answer:
Output is split into sections: . (root), TLD (.com), authoritative NS, response.
+trace is slow — walks the hierarchy recursively. Use it for NXDOMAIN and SERVFAIL diagnosis.
Specific Resolver: @server
By default dig uses the system resolver from /etc/resolv.conf. Specifying explicitly compares responses or bypasses local cache:
AXFR transfer works only if the NS allows it.
Full zone AXFR is sensitive. Don’t do this on third-party NS without reason.
Common Scenarios
Checking SOA and NS records
Serial in SOA — if you updated records but it didn’t increase, transfer hasn’t happened.
TTL of a specific record
300 seconds is low TTL, normal for frequently changing records. Static records usually sit at 3600+.
CNAME chain
The chain displays in full. If a redirect broke somewhere — NXDOMAIN or SERVFAIL at which step becomes clear from the output.
Comparing resolvers
If addresses differ — the issue isn’t on your service side, it’s with that specific resolver or record propagation.
SERVFAIL analysis
Check flags: SERVFAIL in the response means the NS couldn’t fetch data. Verify the requested record type actually exists in the zone.
ANY query (carefully)
Deprecated in production. But for quick diagnostics of all record types on a new NS — it works.