What it is¶
`dig` (Domain Information Groper) is the standard DNS troubleshooting tool, part of BIND's utilities (`dnsutils` on Debian/Ubuntu, `bind-utils` on RHEL/Fedora). It queries a nameserver directly and shows you the raw response rather than going through the system resolver like `getent hosts` or the legacy `nslookup` do.
Installation¶
```bash
Debian/Ubuntu¶
sudo apt-get install dnsutils
RHEL/CentOS/Fedora¶
sudo dnf install bind-utils ```
Basic usage¶
```bash dig example.com # full A record lookup, verbose output dig +short example.com # just the answer, one line per record dig example.com MX # a specific record type dig example.com AAAA # IPv6 dig -x 93.184.216.34 # reverse lookup (PTR) ```
Querying a specific nameserver¶
```bash dig @1.1.1.1 example.com # bypass local resolver, ask Cloudflare directly dig @8.8.8.8 example.com +short # same, against Google dig @ns1.example.com example.com SOA # ask the authoritative server directly ``` This is the fastest way to tell whether something is a DNS propagation issue or a local resolver/cache issue — if `@8.8.8.8` gives the right answer but your default resolver does not, the problem is local (stale cache, wrong resolver config, split-horizon DNS).
Tracing resolution from the root¶
```bash dig +trace example.com ``` Walks the full delegation chain — root servers, TLD servers, authoritative servers — showing exactly where resolution happens. Useful for diagnosing broken delegation or a misconfigured NS record.
Useful flags¶
| Flag | Meaning |
|---|---|
| `+short` | just the answer, no header/stats |
| `+noall +answer` | only the ANSWER section |
| `+trace` | full delegation trace from the root |
| `+dnssec` | request DNSSEC records (RRSIG etc.) |
| `+tcp` | force TCP instead of UDP |
| `-t |
explicit record type |
| `+stats` / `+nostats` | show/hide query time and message size stats |
Checking propagation / TTL¶
```bash dig example.com +noall +answer ;; example.com. 300 IN A 93.184.216.34 ``` The second column is the remaining TTL in seconds — useful for knowing when a DNS change will actually take effect for resolvers that already cached the old value.
Batch queries¶
```bash dig -f hostnames.txt +short # one query per line in the file ```
Cheat sheet¶
```bash dig +short example.com # quick A lookup dig @1.1.1.1 example.com +short # bypass local resolver dig example.com MX # mail servers dig -x 1.2.3.4 # reverse lookup dig +trace example.com # full delegation trace dig +dnssec example.com # DNSSEC records ```