dig - DNS lookup utility
dig [@server] [-x addr] [name] [type] [+queryopt...]
Options you will use
@server- ask this server instead of the first nameserver in /etc/resolv.conf
-x ADDR- reverse lookup (PTR)
+short- just the answers
+noall +answer- only the answer section, with TTLs
+trace- iterate from the root yourself, showing each delegation
+norecurse- do not ask the server to recurse
+search- apply the search list from resolv.conf (off by default!)
+showsearch- show every search-list attempt
+time=N +tries=N- timeout per try and number of tries
Examples
$ dig +short example.comthe address
$ dig example.com MXanother record type
$ dig @10.0.3.53 api.labask the authoritative server: aa flag, full TTL
$ dig +noall +answer example.comanswer and TTL only
$ dig +trace github.comroot -> com -> github.com
Gotchas
- status NXDOMAIN = the name does not exist. NOERROR with ANSWER: 0 = it exists but has no record of that type (NODATA). SERVFAIL = the resolver could not get an answer. "no servers could be reached" = nothing replied.
- dig exits 0 for NXDOMAIN and SERVFAIL - it got a DNS answer. It exits 9 when no server replied.
- dig does not read /etc/hosts itself, but on Ubuntu its default server is the systemd-resolved stub, which does.
Taught in
Try dig in a real terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.