Andrew Mercer
on this page

What it is

`dig` (Domain Information Groper) is the standard DNS troubleshooting tool, part of BIND's utilities (`dnsutils` on Debian/Ubuntu, `bind-utils` on RHEL/Fedora). It queries a nameserver directly and shows you the raw response rather than going through the system resolver like `getent hosts` or the legacy `nslookup` do.

Installation

```bash

Debian/Ubuntu

sudo apt-get install dnsutils

RHEL/CentOS/Fedora

sudo dnf install bind-utils ```

Basic usage

```bash dig example.com # full A record lookup, verbose output dig +short example.com # just the answer, one line per record dig example.com MX # a specific record type dig example.com AAAA # IPv6 dig -x 93.184.216.34 # reverse lookup (PTR) ```

Querying a specific nameserver

```bash dig @1.1.1.1 example.com # bypass local resolver, ask Cloudflare directly dig @8.8.8.8 example.com +short # same, against Google dig @ns1.example.com example.com SOA # ask the authoritative server directly ``` This is the fastest way to tell whether something is a DNS propagation issue or a local resolver/cache issue — if `@8.8.8.8` gives the right answer but your default resolver does not, the problem is local (stale cache, wrong resolver config, split-horizon DNS).

Tracing resolution from the root

```bash dig +trace example.com ``` Walks the full delegation chain — root servers, TLD servers, authoritative servers — showing exactly where resolution happens. Useful for diagnosing broken delegation or a misconfigured NS record.

Useful flags

Flag Meaning
`+short` just the answer, no header/stats
`+noall +answer` only the ANSWER section
`+trace` full delegation trace from the root
`+dnssec` request DNSSEC records (RRSIG etc.)
`+tcp` force TCP instead of UDP
`-t ` explicit record type
`+stats` / `+nostats` show/hide query time and message size stats

Checking propagation / TTL

```bash dig example.com +noall +answer ;; example.com. 300 IN A 93.184.216.34 ``` The second column is the remaining TTL in seconds — useful for knowing when a DNS change will actually take effect for resolvers that already cached the old value.

Batch queries

```bash dig -f hostnames.txt +short # one query per line in the file ```

Cheat sheet

```bash dig +short example.com # quick A lookup dig @1.1.1.1 example.com +short # bypass local resolver dig example.com MX # mail servers dig -x 1.2.3.4 # reverse lookup dig +trace example.com # full delegation trace dig +dnssec example.com # DNSSEC records ```