Network tools · Network tools

dig Commands for DNS Troubleshooting

DNS troubleshooting works best when the query is precise: a name, record type and server. Write down all three before comparing results. Asking one resolver for an A record and another for an AAAA record does not test whether the resolvers agree.

Scope: ISC BIND dig; queries generate DNS traffic but do not change DNS configuration.

Use these commands with your actual name and resolver. The 192.0.2.53 address is an example, not a public DNS service.

Ask a specific question #

Ask a specific question
Network tools · Local shell; platform and privileges as described below

Active test

Replace these example values: example.com.

dig example.com A
Active test

Replace these example values: 192.0.2.53, example.com.

dig @192.0.2.53 example.com A
Active test

Replace these example values: 192.0.2.53, example.com.

dig @192.0.2.53 example.com AAAA
Active test

Replace these example values: 192.0.2.53, example.com.

dig @192.0.2.53 example.com MX
Active test

Replace these example values: 192.0.2.53, 192.0.2.20.

dig @192.0.2.53 -x 192.0.2.20
Active test

Replace these example values: 192.0.2.53, example.com.

dig @192.0.2.53 example.com A +tcp
Active test

Replace these example values: example.com.

dig example.com A +trace

The explicit server form removes uncertainty about which resolver answered. The reverse lookup asks for PTR data. The TCP query helps compare DNS transport behavior. Trace follows delegations through iterative queries; it does not reproduce every policy or cache decision made by the company's recursive resolver.

Read the whole response first #

ResultMeaningUseful next check
NOERROR with the expected recordThe query completed successfullyCompare the returned address with the intended service
NXDOMAINThe queried name does not exist in the answer's DNS viewCheck spelling, delegation and split DNS
NOERROR without the requested recordThe name may exist without that record typeRead the authority section and query the intended type
SERVFAILThe server could not complete the queryCompare another resolver and inspect resolver logs
TimeoutNo usable response arrived before the client gave upCheck reachability, filtering and server availability

NXDOMAIN and an empty NOERROR response are not interchangeable. Negative responses can also be cached. A newly created record may therefore appear at the authoritative server before a recursive resolver returns it. Preserve the status, authority section and TTL information when reporting this case.

Compare like with like #

Run the same query against the affected resolver and an authorized comparison resolver. Different answers can be intentional: internal zones, geographic responses and separate DNS views all exist. Record the queried server from dig's output rather than assuming the operating system chose the expected one.

Use +short only after the failure is understood. It is convenient for a successful lookup, but hides context needed to distinguish an empty result from an error. A successful DNS answer also says nothing about TCP reachability or application health; continue with a port or HTTP test when resolution is correct.

Sources

Documentation reviewed: 8 October 2026