Use these commands with your actual name and resolver. The 192.0.2.53 address is an example, not a public DNS service.
Ask a specific question #
Ask a specific question
Network tools · Local shell; platform and privileges as described below
Replace these example values: example.com.
dig example.com AReplace these example values: 192.0.2.53, example.com.
dig @192.0.2.53 example.com AReplace these example values: 192.0.2.53, example.com.
dig @192.0.2.53 example.com AAAAReplace these example values: 192.0.2.53, example.com.
dig @192.0.2.53 example.com MXReplace these example values: 192.0.2.53, 192.0.2.20.
dig @192.0.2.53 -x 192.0.2.20Replace these example values: 192.0.2.53, example.com.
dig @192.0.2.53 example.com A +tcpReplace these example values: example.com.
dig example.com A +traceThe explicit server form removes uncertainty about which resolver answered. The reverse lookup asks for PTR data. The TCP query helps compare DNS transport behavior. Trace follows delegations through iterative queries; it does not reproduce every policy or cache decision made by the company's recursive resolver.
Read the whole response first #
| Result | Meaning | Useful next check |
|---|---|---|
| NOERROR with the expected record | The query completed successfully | Compare the returned address with the intended service |
| NXDOMAIN | The queried name does not exist in the answer's DNS view | Check spelling, delegation and split DNS |
| NOERROR without the requested record | The name may exist without that record type | Read the authority section and query the intended type |
| SERVFAIL | The server could not complete the query | Compare another resolver and inspect resolver logs |
| Timeout | No usable response arrived before the client gave up | Check reachability, filtering and server availability |
NXDOMAIN and an empty NOERROR response are not interchangeable. Negative responses can also be cached. A newly created record may therefore appear at the authoritative server before a recursive resolver returns it. Preserve the status, authority section and TTL information when reporting this case.
Compare like with like #
Run the same query against the affected resolver and an authorized comparison resolver. Different answers can be intentional: internal zones, geographic responses and separate DNS views all exist. Record the queried server from dig's output rather than assuming the operating system chose the expected one.
Use +short only after the failure is understood. It is convenient for a successful lookup, but hides context needed to distinguish an empty result from an error. A successful DNS answer also says nothing about TCP reachability or application health; continue with a port or HTTP test when resolution is correct.
Sources
Documentation reviewed: 8 October 2026