Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

To read dig output, check the DNS response status first, then the flags and section counts, and finally inspect the records and the server that replied. An empty ANSWER section does not automatically mean the lookup failed: the response may be a referral or a successful response without the requested record. The DNS status and the command’s shell exit code are separate signals.

How do I read dig output?

A typical response contains a header, the requested question, one or more response sections, and a footer. For troubleshooting, keep the full output: short formats can hide the status, flags, authority information, and server details that explain an unexpected result.

  1. Read the status. Find the header’s status: value, such as NOERROR, NXDOMAIN, or SERVFAIL.
  2. Check the flags. Flags such as aa and ra help show whether the response is authoritative and whether recursion is available.
  3. Read the section counts. QUERY, ANSWER, AUTHORITY, and ADDITIONAL count records in their respective message sections. They are not a score of whether the lookup was useful.
  4. Inspect the sections. Confirm what name, class, and type you asked for, then look for returned records and any authority or related data.
  5. Check the footer. It can show query time, the responding server, and message size. The server matters because a recursive resolver and an authoritative server may give different context for the same name.

The BIND DNSSEC guide provides a worked example of these fields. BIND DNSSEC Guide.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What does a record line mean?

A common answer line looks like www.example.com. 60 IN A 10.1.0.1. Read it as owner name, TTL, class, record type, and record data. In this example, A is the type and 10.1.0.1 is the returned address.

What does NXDOMAIN mean in dig?

NXDOMAIN is a DNS response status indicating that the responding DNS process says the queried name does not exist. It is not the same as a timeout or no reply: in those cases, there is no DNS response status to read.

The shell exit code is a separate command-level signal. BIND documents exit code 0 when dig receives a DNS response, including an NXDOMAIN response; code 9 means no reply. Other documented codes are 1 for a usage error, 8 for failure to open a batch file, and 10 for an internal error. So a zero exit code does not prove that the requested record exists. See the BIND 9 dig manual.

How should I interpret NOERROR?

NOERROR means the DNS response code indicates no error, but it does not guarantee that the requested record appears in ANSWER. An alias, referral, or successful response with no matching record can still require you to inspect the other sections and the question you sent.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What do the flags in dig mean?

  • aa means the response is marked as authoritative: the server is answering from authority for the relevant zone.
  • ra means recursion is available from the server.

A record in ANSWER alone does not tell you whether it was served authoritatively or obtained by a recursive resolver, possibly from cache. Check which server you queried and read the flags in context. BIND’s examples show ra on a recursive resolver response and aa on a direct authoritative-server response; a directly queried server can also indicate that recursion was requested but is unavailable. BIND DNSSEC Guide.

Why is the ANSWER section empty?

An empty ANSWER section can still be a meaningful response. In a referral, the queried server does not provide the answer there; instead, AUTHORITY identifies nameservers to ask next, and ADDITIONAL commonly contains related address records for those nameservers. BIND describes a referral as indicating that the queried server does not know the answer. Introduction to DNS and BIND.

  • QUESTION: the name, class, and record type requested.
  • ANSWER: records that answer the query, if present.
  • AUTHORITY: authority information; in a referral, this commonly lists nameservers.
  • ADDITIONAL: related records, often address records for nameservers named in a referral.

Before concluding that nothing happened, read the status and AUTHORITY section alongside the ANSWER count.

What does the TTL in dig mean?

The TTL is the time value shown with that returned record. In www.example.com. 60 IN A 10.1.0.1, the displayed TTL is 60. It belongs to that record in that response; one output line does not guarantee what every client or cache will observe. The BIND manual also documents display options that affect whether TTL values are printed. BIND 9 dig manual.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Which dig command should I use?

Use full output when diagnosing an unexpected response. Choose a shorter command when you only need to extract a returned value and already know what question and server you are checking. These examples are from the BIND 9 manual; default-server behavior depends on the environment where dig runs. BIND 9 dig manual.

Goal Command What it retains or changes
Inspect a DNS lookup in context dig example.com Full response, including status, flags, sections, and server metadata.
Get a short result dig +short example.com Shortened output; useful for quick value checks, but omits diagnostic context.
Show only answer records dig +noall +answer example.com Compact answer section without the rest of the response.
Ask a named server dig @f.gtld-servers.net example.com Queries the server named after @, rather than relying on the default resolver.
Request TXT records dig txt example.com Queries the TXT record type.
Perform a reverse lookup dig -x 192.0.2.1 Queries the reverse-DNS name for the supplied address.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Can DNSSEC cause SERVFAIL?

It can be one possible cause: a validating recursive resolver may return SERVFAIL when it cannot validate a response. But that status alone does not prove DNSSEC is responsible. BIND’s DNSSEC guide recommends +cd as a diagnostic comparison that asks the server to disable checking for the query. BIND DNSSEC Guide.

For comparison, run the same query with and without checking disabled, for example dig example.com and dig +cd example.com. If the latter returns an answer while the ordinary query returns SERVFAIL, a validation-path problem may be involved. That comparison does not identify the broken record, signature, trust chain, or responsible operator, and +cd is not a security fix.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.