Linux dig command

Linux 命令大全Linux Command Encyclopedia


dig (Domain Information Groper) is a powerful DNS query tool in the Linux system, used to query DNS domain name servers. Compared with the traditional nslookup, dig provides more detailed query results and more flexible query options.

Main features of the dig command:

  • Displays the complete DNS query process
  • Supports all DNS record type queries
  • Can specify a specific DNS server to query
  • Output format is clear and easy to read

dig command basic syntax

dig [@server] [domain] [query-type] [query-class] [query-options]

Parameter description

Parameter Description
@server Specify the DNS server to query (e.g.,@8.8.8.8)
domain The domain to query (e.g.,example.com)
query-type The record type to query (e.g.,A, MX, NSetc.)
query-class The class of the query (usuallyININ for Internet)
query-options Additional query options

Common query types

dig supports querying multiple DNS record types. The following are common record types:

Record type Description Example
A IPv4 address record dig example.com A
AAAA IPv6 address record dig example.com AAAA
MX Mail exchange record dig example.com MX
NS Name server record dig example.com NS
CNAME Canonical name record dig www.example.com CNAME
TXT Text record dig example.com TXT
SOA Start of authority record dig example.com SOA
ANY All records dig example.com ANY

dig command output parsing

Execute a simple dig query:

dig example.com

Typical output contains the following parts:

  1. HEADER section: Displays basic query information

    • opcode: Opcode
    • status: Response status
    • id: Query ID
    • flags: Flags (e.g., qr, rd, ra, etc.)
  2. QUESTION section: Displays the question of the query

    • Contains the queried domain name and record type
  3. ANSWER section: Query result

    • Contains the actual DNS record information
  4. AUTHORITY section: Authoritative name server information

    • Displays the authoritative DNS servers responsible for the domain
  5. ADDITIONAL section: Additional information

    • May contain additional useful information
  6. STATISTICS section: Query statistics

    • Displays query time, server, and other information

Practical query examples

1. Query a specific DNS server

dig @8.8.8.8 example.com

This command queries the A record of example.com from Google's public DNS server (8.8.8.8).

2. Query MX records

dig example.com MX

Query the mail server information for a domain.

3. Query the complete domain resolution process

dig +trace example.com

+traceThe +trace option displays the complete resolution process starting from the root name server.

4. Short output mode

dig +short example.com

Only displays query results, not other detailed information.

5. Reverse DNS lookup

dig -x 8.8.8.8

Query the corresponding domain name via an IP address.

6. Batch query multiple domains

dig -f domains.txt +short

Here, domains.txt contains the list of domains to query, one per line.


Advanced options

1. Control output format

dig +noall +answer example.com

+noallHide all sections,+answerOnly display the ANSWER section.

2. Set query timeout

dig +time=5 example.com

Set the query timeout to 5 seconds.

3. Specify query port

dig @dns.server.example.com -p 5353 example.com

Query the DNS server on a non-standard port (5353).

4. Display TTL information

dig +ttlid example.com

Display the TTL (Time To Live) value of the record.

5. Display query statistics

dig +stats example.com

Display detailed query statistics.


Frequently Asked Questions

1. What is the difference between dig and nslookup?

dig provides more detailed output and more query options than nslookup, and is a more professional DNS query tool. nslookup has gradually been replaced by dig.

2. How to install the dig command?

On most Linux distributions, dig is part of the bind-utils or dnsutils package:

  • Debian/Ubuntu:

    sudo apt install dnsutils
  • CentOS/RHEL:

    sudo yum install bind-utils

3. Why does my dig query not return the ANSWER section?

Possible reasons:

  • The queried record type does not exist
  • The domain does not exist
  • The DNS server has no record for that domain
  • Network connection issues

You can try using the+traceoption to view the complete resolution process.


Practical application scenarios

1. Troubleshoot DNS resolution problems

When a website is inaccessible, you can use dig to check whether DNS resolution is normal:

dig +trace example.com

2. Check mail server configuration

Verify whether the domain's mail server configuration is correct:

dig example.com MX

3. Monitor DNS record changes

By periodically executing dig queries and comparing results, you can monitor DNS record changes:

Example

dig example.com A | grep -v ";" > current.txt
diff current.txt previous.txt

4. Test DNS server response time

Compare the response speed of different DNS servers:

Example

time dig @8.8.8.8 example.com
time dig @1.1.1.1 example.com

Summary

The dig command is an essential DNS diagnostic tool for Linux system administrators and network engineers. Through this article, you should be able to:

  1. Understand the basic syntax and common options of the dig command
  2. Query various types of DNS records
  3. Parse the output of the dig command
  4. Use dig to solve practical DNS-related problems
  5. Master advanced usage and techniques of dig

To learn more about the dig command, you can view its manual page:

man dig

Or use the help option:

dig -h

Linux 命令大全Linux Command Encyclopedia

Other extensions