Query a zone with dig
Install dig, ask Azion's nameservers for a zone's records, compare a public resolver, trace the delegation, and check DNSSEC signatures.
You can query an Edge DNS zone with dig to see what Azion’s nameservers answer for each record. The queries work before and after you delegate the domain. dig, the Domain Information Groper, is part of BIND, the DNS toolset that the Internet Systems Consortium (ISC) maintains. It sends one query to a resolver or a nameserver and prints the full response.
host and nslookup ask the same questions with shorter output. All three check DNS answers only: to test whether the application behind a name responds over HTTP or TLS, use a client such as curl or openssl s_client. To see the network path to a nameserver, refer to Trace the route to a host.
Prerequisites
- A zone in Edge DNS with at least one record. To create them, refer to Create, edit, or delete a zone and Add, edit, or delete a record.
- A terminal: Terminal on macOS or Linux, and Command Prompt, PowerShell, or Git Bash on Windows.
digon your machine. To get it, see Install dig.
Install dig
Most macOS versions and some Linux distributions include dig. Windows and many Linux distributions do not.
macOS
dig comes with macOS. To confirm, print its version:
The command prints the version of the tool:
Linux
On Debian-based distributions, such as Ubuntu and Kali Linux, dig is in the dnsutils package. To install it and confirm the version, run:
The second command prints the installed version of DiG. For another distribution, refer to its documentation for the package that holds dig.
Windows
On Windows, dig comes with the BIND tools. To install them:
From the ISC downloads page, download the Current-Stable, ESV version of BIND.
Extract the whole archive, such as BIND9.18.14.tar.xz, into a dedicated folder.
In the folder, run BINDInstall.exe as an administrator.
Select Tools Only to install only dig, host, nslookup, and nsupdate.
The three query tools are available in your terminal. ISC removed Windows support from BIND in a 2021 update, so the tools run on Windows without support from ISC.
Query Azion’s nameserver
With no server named, dig asks the resolvers your system uses, usually configured in resolv.conf, and gets their cached answers. With no arguments at all, it queries the DNS root zone.
To ask Azion’s nameserver directly, without your resolver’s cache, put @ before the nameserver. This works before you delegate the domain. Replace example.com with your domain:
The response shows the record and the server that answered:
status: NOERROR with the aa flag marks an authoritative answer from the nameserver that hosts the zone.
Read the response
Each part of the full response answers a different question:
| Part | What it tells you |
|---|---|
status in the header | The result of the query: NOERROR when the name has records, NXDOMAIN when the name does not exist, SERVFAIL when the server failed to answer. |
flags in the header | aa marks an authoritative answer, from a nameserver that hosts the zone. ra marks a resolver that looks up names for you. |
WARNING: recursion requested but not available | Azion’s nameservers are authoritative only. They answer for the zones they host and do not look up other domains. |
| OPT PSEUDOSECTION | The EDNS options of the query. It shows flags: do when you ask for DNSSEC signatures. |
| QUESTION SECTION | The name and the record type you asked for. |
| ANSWER SECTION | One line per value: name, TTL in seconds, class, type, and value. Azion’s nameservers count the TTL down while they hold an answer in cache. |
| AUTHORITY SECTION and ADDITIONAL SECTION | Referrals and related records, such as the SOA returned with a name that does not exist. |
Query time | How long the server took to answer, in milliseconds. |
SERVER | The address of the server that answered. 179.191.160.2 is ns1.aziondns.net. |
Print only the values
+short drops every part of the response except the values. To print the address of a name:
The output is the value of the record:
Change the record type after the name to read another record set. An MX query prints each mail server with its priority:
At the apex, Azion’s nameservers answer an NS query with their own names:
Each output line is one value of the record set.
Compare with a public resolver
A public resolver returns what users on the internet receive, including its cached copies. Google’s public resolvers are 8.8.8.8, 8.8.4.4, 2001:4860:4860::8888, and 2001:4860:4860::8844. To ask one of them for the same record:
Before the domain is delegated to Azion, the resolver finds no answer:
The SOA in the AUTHORITY SECTION belongs to the registry of the top-level domain, not to Azion. After the registrar delegates the domain to Azion’s nameservers, the resolver returns the values that ns1.aziondns.net returns, once its cached copy expires.
Each resolver answers from its own cache, so two resolvers can return different values for a while. Some networks also intercept or filter DNS queries, which changes the answers you see. To find why the answers differ, refer to Troubleshoot Edge DNS.
Trace the delegation
+trace follows the delegation from the root zone, through the servers of the top-level domain, to the nameservers that answer for the domain. To trace it:
dig prints one block per referral, each listing the nameservers of the next level. For a domain delegated to Edge DNS, the last referral lists ns1.aziondns.net, ns2.aziondns.com, and ns3.aziondns.org. If it lists other nameservers, the registrar still delegates the domain elsewhere. To change that, refer to Migrate nameservers to Azion.
Check DNSSEC signatures
When DNSSEC is on for the zone, Azion signs its answers. +dnssec asks the nameserver to return the signatures with the answer:
The OPT PSEUDOSECTION shows flags: do. A signed answer carries an RRSIG record, algorithm 13, next to the A record in the ANSWER SECTION. For a few minutes after you turn DNSSEC on, an answer cached earlier can still come back without an RRSIG.
To read the zone’s public keys, query its DNSKEY records at the apex:
The zone publishes two keys, both with algorithm 13:
Flags 257 mark the key-signing key, and 256 the zone-signing key. A signature shows that the zone is signed, not that resolvers validate it. Validation also needs the DS record at your registrar. For the steps, refer to Turn on DNSSEC for a zone.
Query several names at once
In batch mode, dig reads one query per line from a file, written as you would type it after dig. Create a file named domains.txt with one name and record type per line:
To send every query in the file to Azion’s nameserver, pass the file to -f:
dig prints one full response per line of the file, in the order of the file.