DIG(1) BIND 9 DIG(1) (NAME) dig - DNS (SYNOPSIS) dig [@server] [-b address] [-c class] [-f filename] [-k filename] [-m] [-p port#] [-q name] [-t type] [-v] [-x addr] [-y [hmac:]name:key] [ [-4] | [-6] ] [name] [type] [class] [queryopt...] dig [-h] dig [global-queryopt...] [query...] (DESCRIPTION) dig DNS . DNS . DNS dig DNS . dig . dig (batch mode) . -h . dig BIND 9 . dig /etc/resolv.conf . dig (localhost) . dig NS "." ( root) . dig ${HOME}/.digrc . . -r . IN CH (TLD) IN CH . -t -c -q "IN." "CH." . (SIMPLE USAGE) dig : dig @server name type : server IP . IPv4 (dotted-decimal) IPv6 (colon-delimited) . server dig (resolve) . server dig /etc/resolv.conf . -4 -6 . dig . . name (resource record) . type - ANY A MX SIG . type . type dig A . (OPTIONS) -4 IPv4 . -6 IPv6 . -b address[#port] IP . address "0.0.0.0" "::" . #port . -c class . class IN HS Hesiod CH Chaosnet . -f file (batch mode) dig file . dig . -h . -k keyfile dig TSIG SIG(0) . tsig-keygen <#std-iscman-tsig-keygen> . TSIG dig . BIND key server named.conf <#std-iscman-named.conf> TSIG KEY SIG(0) . -m . -p port . . -q name . name . -r ${HOME}/.digrc . . -t type . BIND 9 ( NS AAAA) . A -x . (zone transfer) AXFR . (IXFR) type ixfr=N . SOA N . TYPEnn nn . BIND 9 RFC 3597 . -u . -v . -x addr . addr IPv4 IPv6 . -x name class type . dig 94.2.0.192.in-addr.arpa PTR IN . IPv6 (nibble format) IP6.ARPA . -y [hmac:]keyname:secret TSIG . keyname secret Base64 . hmac hmac-md5 hmac-sha1 hmac-sha224 hmac-sha256 hmac-sha384 hmac-sha512. hmac hmac-md5 MD5 hmac-sha256 . : -k -y -y . ps1 (history) . (QUERY OPTIONS) dig . (timeout) (retry) . (+) . no . . +keyword=value . +cd +cdflag . . : +aaflag, +noaaflag +aaonly +noaaonly . +aaonly, +noaaonly aa . +additional, +noadditional (additional section) [ ]. . +adflag, +noadflag AD ( authentic data) [ ] . (authority) . AD=1 OPT-OUT . AD=0 . . +all, +noall . +answer, +noanswer (answer section) [ ]. . +authority, +noauthority (authority section) [ ]. . +badcookie, +nobadcookie BADCOOKIE . +besteffort, +nobesteffort (malformed) . . +bufsize[=B] UDP EDNS0 B . . +bufsize . +cd, +cdflag, +nocdflag CD ( checking disabled) [ ] . DNSSEC . +class, +noclass CLASS [ ]. +cmd, +nocmd dig . . . +coflag, +co, +nocoflag, +noco EDNS CO ( Compact denial of existence Ok) [ ] . (Compact Denial of Existence) . +nocoflag . +comments, +nocomments OPT . . . +cmd +question +stats +rrcomments . +cookie=####, +nocookie EDNS COOKIE [ ]. COOKIE . +cookie . +trace +cookie . +crypto, +nocrypto DNSSEC . DNSSEC . . [omitted] DNSKEY [ key id = value ]. +defname, +nodefname +search +nosearch . +dns64prefix, +nodns64prefix AAAA IPV4ONLY.ARPA DNS64 . +dnssec, +do, +nodnssec, +nodo DNSSEC OK (DO) OPT (additional section) DNSSEC . +domain=somename somename domain /etc/resolv.conf +search . +edns[=#], +noedns EDNS . . EDNS EDNS . +noedns EDNS . EDNS . +ednsflags[=#], +noednsflags - EDNS ( Z) . . ( DO CO) . Z . +ednsnegotiation, +noednsnegotiation EDNS / . EDNS . +ednsopt[=code[:value]], +noednsopt EDNS code value . code EDNS ( NSID ECS) . +noednsopt EDNS . +expire, +noexpire EDNS Expire . +fail, +nofail SERVFAIL named <#std-iscman-named> [ ]. (stub resolver) . +fuzztime[=value], +nofuzztime . 00:00:00 1970 UTC . 1646972129 ( 11 2022 04:15:29 UTC) . +nofuzztime . +header-only, +noheader-only DNS (question section) . . . +https[=value], +nohttps DNS HTTPS (DoH) . 443 . HTTP POST . value HTTP URI /dns-query . dig @example.com +https URI https://example.com/dns-query . +https-get[=value], +nohttps-get +https HTTP GET . +https-post[=value], +nohttps-post +https . +http-plain[=value], +nohttp-plain +https HTTP . HTTP POST . +http-plain-get[=value], +nohttp-plain-get +http-plain HTTP GET . +http-plain-post[=value], +nohttp-plain-post +http-plain . +identify, +noidentify +short IP [ ]. . +idn, +noidn IDN . IDN . IDN dig IDN_DISABLE . +ignore, +noignore (truncation) UDP [ ] TCP . TCP . +keepalive, +nokeepalive EDNS Keepalive [ ]. +keepopen, +nokeepopen TCP [ ] TCP . +nokeepopen . +multiline, +nomultiline SOA [ ]. dig . +ndots=D (D) name . ndots /etc/resolv.conf ndots 1 . +search search domain /etc/resolv.conf . +nsid, +nonsid EDNS (NSID) . +nssearch, +nonssearch dig SOA . . +onesoa, +noonesoa AXFR SOA () . SOA . +opcode=value, +noopcode (opcode) DNS ( ) . QUERY (0) . +padding=value EDNS Padding value . +padding=32 . (padding) . . TCP DNS COOKIE . +proxy[=src_addr[#src_port]-dst_addr[#dst_port]], +noproxy dig PROXYv2 . PROXY . PROXYv2 . 0 53 . DNS PROXYv2 : (handshake) . () DNS PROXYv2 . PROXYv2 LOCAL . (relay) . +proxy-plain[=src_addr[#src_port]-dst_addr[#dst_port], +noproxy-plain +[no]proxy dig PROXYv2 . dig PROXY . ( dnsdist PROXYv2 TLS HAProxy ). DNS +[no]proxy . +qid=value (query ID) . +qr, +noqr . . +question, +noquestion (question section) . . +raflag, +noraflag RA ( Recursion Available) [ ] . +noraflag . QUERY . +rdflag, +nordflag +recurse +norecurse . +recurse, +norecurse RD ( recursion desired) . dig . +nssearch +trace . +retry=T UDP TCP T . +tries . +rrcomments, +norrcomments ( DNSKEY). (multiline) . +search, +nosearch searchlist domain resolv.conf ( ) [ ]. . ndots resolv.conf ( 1) +ndots . +short, +noshort . . . +showbadcookie, +noshowbadcookie BADCOOKIE . . +showbadvers, +noshowbadvers BADVERS . . +showsearch, +noshowsearch [ ]. +split=W Base64 W ( W ) . +nosplit +split=0 . . +stats, +nostats : . . +subnet=addr[/prefix-length], +nosubnet EDNS CLIENT-SUBNET IP [ ]. dig +subnet=0.0.0.0/0 dig +subnet=0 EDNS CLIENT-SUBNET . +tcflag, +notcflag TC ( TrunCation) [ ] . +notcflag . QUERY . +tcp, +notcp TCP . UDP any ixfr=N TCP . AXFR TCP . TCP TC=1 UDP +ignore . +timeout=T T . . T . +tls, +notls DNS TLS (DoT) . . +tls-ca[=file-name], +notls-ca TLS DNS TLS . (CA) PEM (file-name) . . +tls-certfile=file-name, +tls-keyfile=file-name, +notls-certfile, +notls-keyfile DNS TLS . PEM . . +tls-hostname=hostname, +notls-hostname dig TLS . DNS . +tls-ca . +trace, +notrace (delegation path) . . dig (iterative) . . @server . +trace +dnssec . delv +ns (delv(1) <# std-iscman-delv> ). +tries=T UDP TCP T . T . +ttlid, +nottlid TTL [ ]. +ttlunits, +nottlunits TTL s () m () h () d () w () [ ]. +ttlid . +unknownformat, +nounknownformat RDATA RR (RFC 3597 ) . RDATA . +vc, +novc TCP [ ]. +tcp . vc "virtual circuit" ( ) . +yaml, +noyaml ( +qr ) YAML . +zflag, +nozflag DNS DNS [ ] . . (MULTIPLE QUERIES) dig BIND 9 ( -f). . query . . . (tuple) . ( +cmd +short) . : dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr dig : ANY www.isc.org 127.0.0.1 NS isc.org. +qr dig . +noqr dig NS isc.org . (RETURN CODES) dig : 0 DNS NXDOMAIN 1 8 (batch file) 9 10 (FILES) /etc/resolv.conf ${HOME}/.digrc (EXAMPLES) () IP example.com: dig +short example.com f.gtld-servers.net example.com: dig @f.gtld-servers.net example.com TXT example.com: dig txt example.com IP DNS : dig -x 192.0.2.1 TTL : dig +noall +answer example.com (SEE ALSO) delv(1) <#std-iscman-delv>, host(1) <#std-iscman-host>, named(8) <#std- iscman-named>, dnssec-keygen(8) <#std-iscman-dnssec-keygen>, RFC 1035 . (BUGS) . (AUTHORS) Internet Systems Consortium (COPYRIGHT) 2026, Internet Systems Consortium 9.20.27 2026-08-19 DIG(1)