14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt<!ENTITY mdash "—">]>
83545641dd975e12f883abab94ddb749eb18de95Tinderbox User - Copyright (C) 2000-2011, 2013-2018 Internet Systems Consortium, Inc. ("ISC")
0c27b3fe77ac1d5094ba3521e8142d9e7973133fMark Andrews - This Source Code Form is subject to the terms of the Mozilla Public
0c27b3fe77ac1d5094ba3521e8142d9e7973133fMark Andrews - License, v. 2.0. If a copy of the MPL was not distributed with this
0c27b3fe77ac1d5094ba3521e8142d9e7973133fMark Andrews - file, You can obtain one at http://mozilla.org/MPL/2.0/.
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt<!-- Converted by db4-upgrade version 1.0 -->
83a28ca274521e15086fc39febde507bcc4e145eMark Andrews<refentry xmlns:db="http://docbook.org/ns/docbook" version="5.0" xml:id="man.dig">
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein <refentryinfo>
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt <corpauthor>Internet Systems Consortium, Inc.</corpauthor>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein </refentryinfo>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein <refnamediv>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein </refnamediv>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein </copyright>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein <refsynopsisdiv>
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt <arg choice="opt" rep="norepeat"><option>-b <replaceable class="parameter">address</replaceable></option></arg>
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt <arg choice="opt" rep="norepeat"><option>-c <replaceable class="parameter">class</replaceable></option></arg>
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt <arg choice="opt" rep="norepeat"><option>-f <replaceable class="parameter">filename</replaceable></option></arg>
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt <arg choice="opt" rep="norepeat"><option>-k <replaceable class="parameter">filename</replaceable></option></arg>
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt <arg choice="opt" rep="norepeat"><option>-m</option></arg>
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt <arg choice="opt" rep="norepeat"><option>-p <replaceable class="parameter">port#</replaceable></option></arg>
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt <arg choice="opt" rep="norepeat"><option>-q <replaceable class="parameter">name</replaceable></option></arg>
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt <arg choice="opt" rep="norepeat"><option>-t <replaceable class="parameter">type</replaceable></option></arg>
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt <arg choice="opt" rep="norepeat"><option>-v</option></arg>
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt <arg choice="opt" rep="norepeat"><option>-x <replaceable class="parameter">addr</replaceable></option></arg>
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt <arg choice="opt" rep="norepeat"><option>-y <replaceable class="parameter"><optional>hmac:</optional>name:key</replaceable></option></arg>
b7a823a402eb5c4e99f283e58d778a903d2e72f5Michał Kępień <arg choice="opt" rep="norepeat"><option>-4</option></arg>
b7a823a402eb5c4e99f283e58d778a903d2e72f5Michał Kępień <arg choice="opt" rep="norepeat"><option>-6</option></arg>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein </cmdsynopsis>
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt <arg choice="opt" rep="norepeat"><option>-h</option></arg>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein </cmdsynopsis>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein <arg choice="opt" rep="repeat">global-queryopt</arg>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein </cmdsynopsis>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein </refsynopsisdiv>
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt <refsection><info><title>DESCRIPTION</title></info>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein for interrogating DNS name servers. It performs DNS lookups and
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein displays the answers that are returned from the name server(s) that
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein were queried. Most DNS administrators use <command>dig</command> to
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein troubleshoot DNS problems because of its flexibility, ease of use and
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein clarity of output. Other lookup tools tend to have less functionality
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein Although <command>dig</command> is normally used with
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein command-line
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein arguments, it also has a batch mode of operation for reading lookup
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein requests from a file. A brief summary of its command-line arguments
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein and options is printed when the <option>-h</option> option is given.
561a29af8c54a216e7d30b5b4f6e0d21661654ecMark Andrews Unlike earlier versions, the BIND 9 implementation of
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein <command>dig</command> allows multiple lookups to be issued
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein command line.
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein Unless it is told to query a specific name server,
3b9d9ad58b2d85a10960819f5c7a4606b33e9ab2Evan Hunt <command>dig</command> will try each of the servers listed in
8012d70ea4906ba739036cc9903cb0ac0fc72e9fJeremy C. Reed <filename>/etc/resolv.conf</filename>. If no usable server addresses
3b9d9ad58b2d85a10960819f5c7a4606b33e9ab2Evan Hunt are found, <command>dig</command> will send the query to the local
d4f032db535ad5194d442fec535123f269422055Jeremy Reed When no command line arguments or options are given,
d4f032db535ad5194d442fec535123f269422055Jeremy Reed <command>dig</command> will perform an NS query for "." (the root).
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein It is possible to set per-user defaults for <command>dig</command> via
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein <filename>${HOME}/.digrc</filename>. This file is read and
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein any options in it
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein are applied before the command line arguments.
065c66d9bf1c349600027bb50e3759a3736f73abMark Andrews The IN and CH class names overlap with the IN and CH top level
79a1c7502d0d1c5e654d9892c948d0123c3b3e2fEvan Hunt domain names. Either use the <option>-t</option> and
30eec077db2bdcb6f2a0dc388a3cdde2ede75ec1Mark Andrews <option>-c</option> options to specify the type and class,
d4f032db535ad5194d442fec535123f269422055Jeremy Reed use the <option>-q</option> the specify the domain name, or
065c66d9bf1c349600027bb50e3759a3736f73abMark Andrews use "IN." and "CH." when looking up these top level domains.
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt </refsection>
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt <refsection><info><title>SIMPLE USAGE</title></info>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein A typical invocation of <command>dig</command> looks like:
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein <programlisting> dig @server name type </programlisting>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein <variablelist>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews is the name or IP address of the name server to query. This
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews can be an IPv4 address in dotted-decimal notation or an IPv6
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews address in colon-delimited notation. When the supplied
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <parameter>server</parameter> argument is a hostname,
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <command>dig</command> resolves that name before querying
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews that name server.
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews If no <parameter>server</parameter> argument is
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews address is found there, it queries the name server at
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews that address. If either of the <option>-4</option> or
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews only addresses for the corresponding transport
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews will be tried. If no usable addresses are found,
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <command>dig</command> will send the query to the
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews local host. The reply from the name server that
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews responds is displayed.
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews </varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews is the name of the resource record that is to be looked up.
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews </varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews indicates what type of query is required —
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews ANY, A, MX, SIG, etc.
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <parameter>type</parameter> can be any valid query
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <parameter>type</parameter> argument is supplied,
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <command>dig</command> will perform a lookup for an
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews </varlistentry>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein </variablelist>
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt </refsection>
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt <variablelist>
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt <varlistentry>
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt Use IPv4 only.
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt </varlistentry>
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt <varlistentry>
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt Use IPv6 only.
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt </varlistentry>
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt <varlistentry>
ce67023ae3ad39a77da5361d0187ab6f3f0219cbMark Andrews <term>-b <replaceable class="parameter">address<optional>#port</optional></replaceable></term>
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt Set the source IP address of the query.
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt The <parameter>address</parameter> must be a valid address on
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt one of the host's network interfaces, or "0.0.0.0" or "::". An
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt optional port may be specified by appending "#<port>"
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt </varlistentry>
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt <varlistentry>
ce67023ae3ad39a77da5361d0187ab6f3f0219cbMark Andrews <term>-c <replaceable class="parameter">class</replaceable></term>
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt Set the query class. The
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt default <parameter>class</parameter> is IN; other classes
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt are HS for Hesiod records or CH for Chaosnet records.
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt </varlistentry>
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt <varlistentry>
ce67023ae3ad39a77da5361d0187ab6f3f0219cbMark Andrews <term>-f <replaceable class="parameter">file</replaceable></term>
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt Batch mode: <command>dig</command> reads a list of lookup
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt requests to process from the
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt given <parameter>file</parameter>. Each line in the file
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt should be organized in the same way they would be
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt presented as queries to
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt <command>dig</command> using the command-line interface.
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt </varlistentry>
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt <varlistentry>
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt Do reverse IPv6 lookups using the obsolete RFC1886 IP6.INT
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt domain, which is no longer in use. Obsolete bit string
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt label queries (RFC2874) are not attempted.
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt </varlistentry>
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt <varlistentry>
ce67023ae3ad39a77da5361d0187ab6f3f0219cbMark Andrews <term>-k <replaceable class="parameter">keyfile</replaceable></term>
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt Sign queries using TSIG using a key read from the given file.
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt Key files can be generated using
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt <citerefentry>
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt <refentrytitle>tsig-keygen</refentrytitle><manvolnum>8</manvolnum>
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt </citerefentry>.
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt When using TSIG authentication with <command>dig</command>,
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt the name server that is queried needs to know the key and
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt algorithm that is being used. In BIND, this is done by
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt </varlistentry>
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt <varlistentry>
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt Enable memory usage debugging.
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt <!-- It enables ISC_MEM_DEBUGTRACE and ISC_MEM_DEBUGRECORD
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt documented in include/isc/mem.h -->
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt </varlistentry>
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt <varlistentry>
ce67023ae3ad39a77da5361d0187ab6f3f0219cbMark Andrews <term>-p <replaceable class="parameter">port</replaceable></term>
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt Send the query to a non-standard port on the server,
fe12c35c3eb72588ffdec7c51070af64e1ae81ffJeremy C. Reed instead of the default port 53. This option would be used
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt to test a name server that has been configured to listen
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt for queries on a non-standard port number.
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt </varlistentry>
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt <varlistentry>
ce67023ae3ad39a77da5361d0187ab6f3f0219cbMark Andrews <term>-q <replaceable class="parameter">name</replaceable></term>
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt The domain name to query. This is useful to distinguish
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt the <parameter>name</parameter> from other arguments.
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt </varlistentry>
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt <varlistentry>
ce67023ae3ad39a77da5361d0187ab6f3f0219cbMark Andrews <term>-t <replaceable class="parameter">type</replaceable></term>
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt The resource record type to query. It can be any valid query type
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt supported in BIND 9. The default query type is "A", unless the
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt <option>-x</option> option is supplied to indicate a reverse lookup.
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt A zone transfer can be requested by specifying a type of AXFR. When
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt an incremental zone transfer (IXFR) is required, set the
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt <parameter>type</parameter> to <literal>ixfr=N</literal>.
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt The incremental zone transfer will contain the changes
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt made to the zone since the serial number in the zone's SOA
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt </varlistentry>
002f1373374a0b72fc0329baa682917929bef168Tony Finch <varlistentry>
002f1373374a0b72fc0329baa682917929bef168Tony Finch Print query times in microseconds instead of milliseconds.
002f1373374a0b72fc0329baa682917929bef168Tony Finch </varlistentry>
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt <varlistentry>
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt Print the version number and exit.
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt </varlistentry>
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt <varlistentry>
ce67023ae3ad39a77da5361d0187ab6f3f0219cbMark Andrews <term>-x <replaceable class="parameter">addr</replaceable></term>
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt Simplified reverse lookups, for mapping addresses to
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt names. The <parameter>addr</parameter> is an IPv4 address
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt in dotted-decimal notation, or a colon-delimited IPv6
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt address. When the <option>-x</option> is used, there is no
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt need to provide
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt the <parameter>name</parameter>, <parameter>class</parameter>
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt arguments. <command>dig</command> automatically performs a
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt lookup for a name like
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt <literal>94.2.0.192.in-addr.arpa</literal> and sets the
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt query type and class to PTR and IN respectively. IPv6
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt addresses are looked up using nibble format under the
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt IP6.ARPA domain (but see also the <option>-i</option>
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt </varlistentry>
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt <varlistentry>
ce67023ae3ad39a77da5361d0187ab6f3f0219cbMark Andrews <term>-y <replaceable class="parameter"><optional>hmac:</optional>keyname:secret</replaceable></term>
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt Sign queries using TSIG with the given authentication key.
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt <parameter>keyname</parameter> is the name of the key, and
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt <parameter>secret</parameter> is the base64 encoded shared secret.
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt <parameter>hmac</parameter> is the name of the key algorithm;
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt <literal>hmac-sha1</literal>, <literal>hmac-sha224</literal>,
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt <literal>hmac-sha256</literal>, <literal>hmac-sha384</literal>, or
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt <literal>hmac-sha512</literal>. If <parameter>hmac</parameter>
c40906dfad6dd6e3a3e3c94b8c8847bc9bc064e5Mark Andrews is not specified, the default is <literal>hmac-md5</literal>
c40906dfad6dd6e3a3e3c94b8c8847bc9bc064e5Mark Andrews or if MD5 was disabled <literal>hmac-sha256</literal>.
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt NOTE: You should use the <option>-k</option> option and
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt with <option>-y</option> the shared secret is supplied as
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt a command line argument in clear text. This may be visible
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt in the output from
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt <citerefentry>
ce67023ae3ad39a77da5361d0187ab6f3f0219cbMark Andrews <refentrytitle>ps</refentrytitle><manvolnum>1</manvolnum>
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt </citerefentry>
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt or in a history file maintained by the user's shell.
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt </varlistentry>
53ae008f2749a29773b27a481452b292c8f53b65Evan Hunt </variablelist>
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt </refsection>
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt <refsection><info><title>QUERY OPTIONS</title></info>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein provides a number of query options which affect
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein the way in which lookups are made and the results displayed. Some of
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein these set or reset flag bits in the query header, some determine which
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein sections of the answer get printed, and others determine the timeout
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein and retry strategies.
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein Each query option is identified by a keyword preceded by a plus sign
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein (<literal>+</literal>). Some keywords set or reset an
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein option. These may be preceded
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein by the string <literal>no</literal> to negate the meaning of
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein that keyword. Other
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein keywords assign values to options like the timeout interval. They
eb447eca8847be14e93d7b2d524154433e4ee565Evan Hunt Keywords may be abbreviated, provided the abbreviation is
eb447eca8847be14e93d7b2d524154433e4ee565Evan Hunt unambiguous; for example, <literal>+cd</literal> is equivalent
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein The query options are:
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein <variablelist>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <varlistentry>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews A synonym for <parameter>+[no]aaonly</parameter>.
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews </varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <varlistentry>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews Sets the "aa" flag in the query.
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews </varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <varlistentry>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews Display [do not display] the additional section of a
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews reply. The default is to display it.
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews </varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <varlistentry>
70f292a50f9840fc25b3dbecfed71cdf835d4094Mark Andrews Set [do not set] the AD (authentic data) bit in the
70f292a50f9840fc25b3dbecfed71cdf835d4094Mark Andrews query. This requests the server to return whether
70f292a50f9840fc25b3dbecfed71cdf835d4094Mark Andrews all of the answer and authority sections have all
70f292a50f9840fc25b3dbecfed71cdf835d4094Mark Andrews been validated as secure according to the security
70f292a50f9840fc25b3dbecfed71cdf835d4094Mark Andrews policy of the server. AD=1 indicates that all records
70f292a50f9840fc25b3dbecfed71cdf835d4094Mark Andrews have been validated as secure and the answer is not
70f292a50f9840fc25b3dbecfed71cdf835d4094Mark Andrews from a OPT-OUT range. AD=0 indicate that some part
3fb5bccf59abe5a0b545b4979181df0b17adee3bMark Andrews of the answer was insecure or not validated. This
3fb5bccf59abe5a0b545b4979181df0b17adee3bMark Andrews bit is set by default.
70f292a50f9840fc25b3dbecfed71cdf835d4094Mark Andrews </varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <varlistentry>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews Set or clear all display flags.
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews </varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <varlistentry>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews Display [do not display] the answer section of a
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews reply. The default is to display it.
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews </varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <varlistentry>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews Display [do not display] the authority section of a
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews reply. The default is to display it.
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews </varlistentry>
ce67023ae3ad39a77da5361d0187ab6f3f0219cbMark Andrews <varlistentry>
ce67023ae3ad39a77da5361d0187ab6f3f0219cbMark Andrews Retry lookup with the new server cookie if a
ce67023ae3ad39a77da5361d0187ab6f3f0219cbMark Andrews BADCOOKIE response is received.
ce67023ae3ad39a77da5361d0187ab6f3f0219cbMark Andrews </varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <varlistentry>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews Attempt to display the contents of messages which are
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews malformed. The default is to not display malformed
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews </varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <varlistentry>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews Set the UDP message buffer size advertised using EDNS0
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews to <parameter>B</parameter> bytes. The maximum and
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews minimum sizes of this buffer are 65535 and 0 respectively.
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews Values outside this range are rounded up or down
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews appropriately. Values other than zero will cause a
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews EDNS query to be sent.
3fb5bccf59abe5a0b545b4979181df0b17adee3bMark Andrews </varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <varlistentry>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews Set [do not set] the CD (checking disabled) bit in
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews the query. This requests the server to not perform
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews DNSSEC validation of responses.
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews </varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <varlistentry>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews Display [do not display] the CLASS when printing the
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews </varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <varlistentry>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews Toggles the printing of the initial comment in the
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews output identifying the version of <command>dig</command>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews and the query options that have been applied. This
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews comment is printed by default.
3fb5bccf59abe5a0b545b4979181df0b17adee3bMark Andrews </varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <varlistentry>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews Toggle the display of comment lines in the output.
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews The default is to print comments.
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews </varlistentry>
ce67023ae3ad39a77da5361d0187ab6f3f0219cbMark Andrews <varlistentry>
ce67023ae3ad39a77da5361d0187ab6f3f0219cbMark Andrews <term><option>+[no]cookie<optional>=####</optional></option></term>
ce67023ae3ad39a77da5361d0187ab6f3f0219cbMark Andrews Send a COOKIE EDNS option, with optional
ce67023ae3ad39a77da5361d0187ab6f3f0219cbMark Andrews value. Replaying a COOKIE from a previous response will
ce67023ae3ad39a77da5361d0187ab6f3f0219cbMark Andrews allow the server to identify a previous client. The
ce67023ae3ad39a77da5361d0187ab6f3f0219cbMark Andrews <command>+cookie</command> is also set when +trace
ce67023ae3ad39a77da5361d0187ab6f3f0219cbMark Andrews is set to better emulate the default queries from a
ce67023ae3ad39a77da5361d0187ab6f3f0219cbMark Andrews </varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <varlistentry>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews Toggle the display of cryptographic fields in DNSSEC
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews records. The contents of these field are unnecessary
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews to debug most DNSSEC validation failures and removing
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews them makes it easier to see the common failures. The
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews default is to display the fields. When omitted they
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews are replaced by the string "[omitted]" or in the
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews DNSKEY case the key id is displayed as the replacement,
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews e.g. "[ key id = value ]".
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews </varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <varlistentry>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews Deprecated, treated as a synonym for
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews </varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <varlistentry>
2d0bc1e0f3f5ed26c8f43bc12dd08ffa6b9a6460Mark Andrews Requests DNSSEC records be sent by setting the DNSSEC
2d0bc1e0f3f5ed26c8f43bc12dd08ffa6b9a6460Mark Andrews OK bit (DO) in the OPT record in the additional section
2d0bc1e0f3f5ed26c8f43bc12dd08ffa6b9a6460Mark Andrews of the query.
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews </varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <varlistentry>
2d0bc1e0f3f5ed26c8f43bc12dd08ffa6b9a6460Mark Andrews Set the search list to contain the single domain
2d0bc1e0f3f5ed26c8f43bc12dd08ffa6b9a6460Mark Andrews <parameter>somename</parameter>, as if specified in
2d0bc1e0f3f5ed26c8f43bc12dd08ffa6b9a6460Mark Andrews <filename>/etc/resolv.conf</filename>, and enable
2d0bc1e0f3f5ed26c8f43bc12dd08ffa6b9a6460Mark Andrews search list processing as if the
2d0bc1e0f3f5ed26c8f43bc12dd08ffa6b9a6460Mark Andrews <parameter>+search</parameter> option were given.
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews </varlistentry>
2064e46209f35d2afad526622d975647f9c2098bMark Andrews <varlistentry>
2064e46209f35d2afad526622d975647f9c2098bMark Andrews <term><option>+dscp=value</option></term> <listitem>
2064e46209f35d2afad526622d975647f9c2098bMark Andrews Set the DSCP code point to be used when sending the
2064e46209f35d2afad526622d975647f9c2098bMark Andrews query. Valid DSCP code points are in the range
821350367e2c7313c02eb275e8e05d5193b47cfdJeremy C. Reed [0..63]. By default no code point is explicitly set.
2064e46209f35d2afad526622d975647f9c2098bMark Andrews </varlistentry>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews <varlistentry>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews Specify the EDNS version to query with. Valid values
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews are 0 to 255. Setting the EDNS version will cause
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews a EDNS query to be sent. <option>+noedns</option>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews clears the remembered EDNS version. EDNS is set to
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews 0 by default.
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews </varlistentry>
3867312e4cc5c53d20f4020cc5b2459154406135Mark Andrews <varlistentry>
3867312e4cc5c53d20f4020cc5b2459154406135Mark Andrews <term><option>+[no]ednsflags[=#]</option></term>
3867312e4cc5c53d20f4020cc5b2459154406135Mark Andrews Set the must-be-zero EDNS flags bits (Z bits) to the
3867312e4cc5c53d20f4020cc5b2459154406135Mark Andrews specified value. Decimal, hex and octal encodings are
3867312e4cc5c53d20f4020cc5b2459154406135Mark Andrews accepted. Setting a named flag (e.g. DO) will silently be
3867312e4cc5c53d20f4020cc5b2459154406135Mark Andrews ignored. By default, no Z bits are set.
3867312e4cc5c53d20f4020cc5b2459154406135Mark Andrews </varlistentry>
0f5144163c44a67d9be986383769852a0dae502aMark Andrews <varlistentry>
0f5144163c44a67d9be986383769852a0dae502aMark Andrews <term><option>+[no]ednsnegotiation</option></term>
0f5144163c44a67d9be986383769852a0dae502aMark Andrews Enable / disable EDNS version negotiation. By default
0f5144163c44a67d9be986383769852a0dae502aMark Andrews EDNS version negotiation is enabled.
0f5144163c44a67d9be986383769852a0dae502aMark Andrews </varlistentry>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews <varlistentry>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews <term><option>+[no]ednsopt[=code[:value]]</option></term>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews Specify EDNS option with code point <option>code</option>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews and optionally payload of <option>value</option> as a
474577728422b990f94e57988674e7646375491dTinderbox User hexadecimal string. <option>code</option> can be
403e7b451207fe6514a5d641562713b1af233b9cEvan Hunt either an EDNS option name (for example,
403e7b451207fe6514a5d641562713b1af233b9cEvan Hunt <literal>NSID</literal> or <literal>ECS</literal>),
403e7b451207fe6514a5d641562713b1af233b9cEvan Hunt or an arbitrary numeric value. <option>+noednsopt</option>
97553eec86d43d4d886401e7ea17dc0172fb5759Mark Andrews clears the EDNS options to be sent.
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews </varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <varlistentry>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews Send an EDNS Expire option.
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews </varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <varlistentry>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews Do not try the next server if you receive a SERVFAIL.
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews The default is to not try the next server which is
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews the reverse of normal stub resolver behavior.
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews </varlistentry>
f274cbeaed0e4c5fdbde9f5c30833d7f1da37cd3Mark Andrews <varlistentry>
f274cbeaed0e4c5fdbde9f5c30833d7f1da37cd3Mark Andrews Send a query with a DNS header without a question section.
f274cbeaed0e4c5fdbde9f5c30833d7f1da37cd3Mark Andrews The default is to add a question section. The query type
f274cbeaed0e4c5fdbde9f5c30833d7f1da37cd3Mark Andrews and query name are ignored when this is set.
f274cbeaed0e4c5fdbde9f5c30833d7f1da37cd3Mark Andrews </varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <varlistentry>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews Show [or do not show] the IP address and port number
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews that supplied the answer when the
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews <parameter>+short</parameter> option is enabled. If
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews short form answers are requested, the default is not
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews to show the source address and port number of the
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews server that provided the answer.
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews </varlistentry>
6552f33198438390724c5823b8dbcf477ec9638cEvan Hunt <varlistentry>
6552f33198438390724c5823b8dbcf477ec9638cEvan Hunt Convert [do not convert] puny code on output.
6552f33198438390724c5823b8dbcf477ec9638cEvan Hunt This requires IDN SUPPORT to have been enabled at
6552f33198438390724c5823b8dbcf477ec9638cEvan Hunt compile time. The default is to convert output.
6552f33198438390724c5823b8dbcf477ec9638cEvan Hunt </varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <varlistentry>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews Ignore truncation in UDP responses instead of retrying
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews with TCP. By default, TCP retries are performed.
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews </varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <varlistentry>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews Keep the TCP socket open between queries and reuse
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews it rather than creating a new TCP socket for each
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews lookup. The default is <option>+nokeepopen</option>.
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews </varlistentry>
49762dffc45b6c02abe5d131cb7c49369cf13e09Mark Andrews <varlistentry>
49762dffc45b6c02abe5d131cb7c49369cf13e09Mark Andrews Allow mapped IPv4 over IPv6 addresses to be used. The
49762dffc45b6c02abe5d131cb7c49369cf13e09Mark Andrews </varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <varlistentry>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews Print records like the SOA records in a verbose
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews multi-line format with human-readable comments. The
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews default is to print each record on a single line, to
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews facilitate machine parsing of the <command>dig</command>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews </varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <varlistentry>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews Set the number of dots that have to appear in
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews <parameter>name</parameter> to <parameter>D</parameter>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews for it to be considered absolute. The default value
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews is that defined using the ndots statement in
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews <filename>/etc/resolv.conf</filename>, or 1 if no
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews ndots statement is present. Names with fewer dots
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews are interpreted as relative names and will be searched
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews for in the domains listed in the <option>search</option>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews </varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <varlistentry>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews Include an EDNS name server ID request when sending
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews </varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <varlistentry>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews When this option is set, <command>dig</command>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews attempts to find the authoritative name servers for
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews the zone containing the name being looked up and
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews display the SOA record that each name server has for
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews </varlistentry>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews <varlistentry>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews Print only one (starting) SOA record when performing
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews an AXFR. The default is to print both the starting
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews and ending SOA records.
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews </varlistentry>
c7463967dbcb31c2ec0dd513986a9dec05994a0aMark Andrews <varlistentry>
c7463967dbcb31c2ec0dd513986a9dec05994a0aMark Andrews <term><option>+[no]opcode=value</option></term>
c7463967dbcb31c2ec0dd513986a9dec05994a0aMark Andrews Set [restore] the DNS message opcode to the specified
c7463967dbcb31c2ec0dd513986a9dec05994a0aMark Andrews value. The default value is QUERY (0).
c7463967dbcb31c2ec0dd513986a9dec05994a0aMark Andrews </varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <varlistentry>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews Print [do not print] the query as it is sent. By
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews default, the query is not printed.
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews </varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <varlistentry>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews Print [do not print] the question section of a query
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews when an answer is returned. The default is to print
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews the question section as a comment.
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews </varlistentry>
eb447eca8847be14e93d7b2d524154433e4ee565Evan Hunt <varlistentry>
eb447eca8847be14e93d7b2d524154433e4ee565Evan Hunt A synonym for <parameter>+[no]recurse</parameter>.
eb447eca8847be14e93d7b2d524154433e4ee565Evan Hunt </varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <varlistentry>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews Toggle the setting of the RD (recursion desired) bit
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews in the query. This bit is set by default, which means
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews <command>dig</command> normally sends recursive
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews queries. Recursion is automatically disabled when
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews <parameter>+trace</parameter> query options are used.
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews </varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <varlistentry>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews Sets the number of times to retry UDP queries to
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews server to <parameter>T</parameter> instead of the
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews default, 2. Unlike <parameter>+tries</parameter>,
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews this does not include the initial query.
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews </varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <varlistentry>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews Toggle the display of per-record comments in the
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews output (for example, human-readable key information
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews about DNSKEY records). The default is not to print
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews record comments unless multiline mode is active.
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews </varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <varlistentry>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews Use [do not use] the search list defined by the
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews searchlist or domain directive in
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews <filename>resolv.conf</filename> (if any). The search
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews list is not used by default.
40b28f54029a5399fc17d895dd9e8bbcd97d6b70Mark Andrews 'ndots' from <filename>resolv.conf</filename> (default 1)
40b28f54029a5399fc17d895dd9e8bbcd97d6b70Mark Andrews which may be overridden by <parameter>+ndots</parameter>
40b28f54029a5399fc17d895dd9e8bbcd97d6b70Mark Andrews determines if the name will be treated as relative
40b28f54029a5399fc17d895dd9e8bbcd97d6b70Mark Andrews or not and hence whether a search is eventually
40b28f54029a5399fc17d895dd9e8bbcd97d6b70Mark Andrews performed or not.
e560fbdf77b08ff23ab71b107f022829bcd552dbMark Andrews </varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <varlistentry>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews Provide a terse answer. The default is to print the
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews answer in a verbose form.
1fc4793844c9613b17866c33dbeab8aaa94b66ffMark Andrews </varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <varlistentry>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews Perform [do not perform] a search showing intermediate
13396661f46572d7b94703a25721aad040fbd91aMark Andrews </varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <varlistentry>
cf710c81aee40b565323bdb9422b53fe225526f5Evan Hunt Chase DNSSEC signature chains. Requires dig be compiled
cf710c81aee40b565323bdb9422b53fe225526f5Evan Hunt with -DDIG_SIGCHASE. This feature is deprecated.
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews </varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <varlistentry>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews Split long hex- or base64-formatted fields in resource
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews records into chunks of <parameter>W</parameter>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews characters (where <parameter>W</parameter> is rounded
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews up to the nearest multiple of 4).
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews <parameter>+split=0</parameter> causes fields not to
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews be split at all. The default is 56 characters, or
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews 44 characters when multiline mode is active.
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews </varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <varlistentry>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews This query option toggles the printing of statistics:
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews when the query was made, the size of the reply and
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews so on. The default behavior is to print the query
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews </varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <varlistentry>
05b7b63f17bad4ca8ca0de8f65f806f365e727d7Evan Hunt <term><option>+[no]subnet=addr[/prefix-length]</option></term>
8ede7a974b126b3afe766c11ca621aee52c9889aEvan Hunt Send (don't send) an EDNS Client Subnet option with the
05b7b63f17bad4ca8ca0de8f65f806f365e727d7Evan Hunt specified IP address or network prefix.
8ede7a974b126b3afe766c11ca621aee52c9889aEvan Hunt <command>dig +subnet=0.0.0.0/0</command>, or simply
05b7b63f17bad4ca8ca0de8f65f806f365e727d7Evan Hunt <command>dig +subnet=0</command> for short, sends an EDNS
db9781d4a2ed15c4b34bb5c97ea68b8f598992fcMark Andrews CLIENT-SUBNET option with an empty address and a source
05b7b63f17bad4ca8ca0de8f65f806f365e727d7Evan Hunt prefix-length of zero, which signals a resolver that
05b7b63f17bad4ca8ca0de8f65f806f365e727d7Evan Hunt the client's address information must
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews </varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <varlistentry>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews Use [do not use] TCP when querying name servers. The
3001a1b4e6298466882a4147307b4c28a3b08f91Mark Andrews default behavior is to use UDP unless a type
3001a1b4e6298466882a4147307b4c28a3b08f91Mark Andrews <literal>any</literal> or <literal>ixfr=N</literal>
3001a1b4e6298466882a4147307b4c28a3b08f91Mark Andrews query is requested, in which case the default is TCP.
3001a1b4e6298466882a4147307b4c28a3b08f91Mark Andrews AXFR queries always use TCP.
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews </varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews Sets the timeout for a query to
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews timeout is 5 seconds.
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews An attempt to set <parameter>T</parameter> to less
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews than 1 will result
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews in a query timeout of 1 second being applied.
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews </varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <varlistentry>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews When chasing DNSSEC signature chains perform a top-down
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews validation. Requires dig be compiled with -DDIG_SIGCHASE.
cf710c81aee40b565323bdb9422b53fe225526f5Evan Hunt This feature is deprecated. Use <command>delv</command> instead.
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews </varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <varlistentry>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews Toggle tracing of the delegation path from the root
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews name servers for the name being looked up. Tracing
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews is disabled by default. When tracing is enabled,
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews <command>dig</command> makes iterative queries to
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews resolve the name being looked up. It will follow
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews referrals from the root servers, showing the answer
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews from each server that was used to resolve the lookup.
2561b2dd842a25ef3a7fa9a1868ec87fee3da427Mark Andrews If @server is also specified, it affects only the
2561b2dd842a25ef3a7fa9a1868ec87fee3da427Mark Andrews initial query for the root zone name servers.
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews <command>+dnssec</command> is also set when +trace
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews is set to better emulate the default queries from a
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews </varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <varlistentry>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews Sets the number of times to try UDP queries to server
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews to <parameter>T</parameter> instead of the default,
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews 3. If <parameter>T</parameter> is less than or equal
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews to zero, the number of tries is silently rounded up
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews </varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <term><option>+trusted-key=####</option></term>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews Specifies a file containing trusted keys to be used
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews with <option>+sigchase</option>. Each DNSKEY record
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews must be on its own line.
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews If not specified, <command>dig</command> will look
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews for <filename>/etc/trusted-key.key</filename> then
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews <filename>trusted-key.key</filename> in the current
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews Requires dig be compiled with -DDIG_SIGCHASE.
cf710c81aee40b565323bdb9422b53fe225526f5Evan Hunt This feature is deprecated. Use <command>delv</command> instead.
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews </varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <varlistentry>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews Display [do not display] the TTL when printing the
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews </varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews Display [do not display] the TTL in friendly human-readable
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews time units of "s", "m", "h", "d", and "w", representing
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews seconds, minutes, hours, days and weeks. Implies +ttlid.
79a55d4f4dcf3d6f617523228503d8584b72a3a3Mukund Sivaraman </varlistentry>
79a55d4f4dcf3d6f617523228503d8584b72a3a3Mukund Sivaraman <varlistentry>
79a55d4f4dcf3d6f617523228503d8584b72a3a3Mukund Sivaraman <term><option>+[no]unknownformat</option></term>
79a55d4f4dcf3d6f617523228503d8584b72a3a3Mukund Sivaraman Print all RDATA in unknown RR type presentation format
79a55d4f4dcf3d6f617523228503d8584b72a3a3Mukund Sivaraman (RFC 3597). The default is to print RDATA for known types
79a55d4f4dcf3d6f617523228503d8584b72a3a3Mukund Sivaraman in the type's presentation format.
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews </varlistentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <varlistentry>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews Use [do not use] TCP when querying name servers. This
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews alternate syntax to <parameter>+[no]tcp</parameter>
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews is provided for backwards compatibility. The "vc"
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews stands for "virtual circuit".
9c36846e41822f3a933d5e7d91d5008879cdd1cdMark Andrews </varlistentry>
f0a54842b1a50dac0b020958eb6025ed676f9a34Mark Andrews <varlistentry>
f0a54842b1a50dac0b020958eb6025ed676f9a34Mark Andrews Set [do not set] the last unassigned DNS header flag in a
f0a54842b1a50dac0b020958eb6025ed676f9a34Mark Andrews DNS query. This flag is off by default.
f0a54842b1a50dac0b020958eb6025ed676f9a34Mark Andrews </varlistentry>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein </variablelist>
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt </refsection>
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt <refsection><info><title>MULTIPLE QUERIES</title></info>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein The BIND 9 implementation of <command>dig </command>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein specifying multiple queries on the command line (in addition to
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein supporting the <option>-f</option> batch file option). Each of those
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein queries can be supplied with its own set of flags, options and query
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein In this case, each <parameter>query</parameter> argument
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein represent an
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein individual query in the command-line syntax described above. Each
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein consists of any of the standard options and flags, the name to be
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein looked up, an optional query type and class and any query options that
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein should be applied to that query.
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein A global set of query options, which should be applied to all queries,
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein can also be supplied. These global query options must precede the
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein first tuple of name, class, type, options, flags, and query options
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein supplied on the command line. Any global query options (except
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein overridden by a query-specific set of query options. For example:
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein <programlisting>
f202f2587b9ba4753afba49b796f599cc12b4d0fAndreas Gustafssondig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr
f202f2587b9ba4753afba49b796f599cc12b4d0fAndreas Gustafsson</programlisting>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein shows how <command>dig</command> could be used from the
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein command line
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein to make three lookups: an ANY query for <literal>www.isc.org</literal>, a
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein reverse lookup of 127.0.0.1 and a query for the NS records of
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein A global query option of <parameter>+qr</parameter> is
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein that <command>dig</command> shows the initial query it made
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein lookup. The final query has a local query option of
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein <parameter>+noqr</parameter> which means that <command>dig</command>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein will not print the initial query when it looks up the NS records for
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt </refsection>
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt <refsection><info><title>IDN SUPPORT</title></info>
6cf369f528c4acd8182eada41ad83b8d97623db8Mark Andrews If <command>dig</command> has been built with IDN (internationalized
6cf369f528c4acd8182eada41ad83b8d97623db8Mark Andrews domain name) support, it can accept and display non-ASCII domain names.
6cf369f528c4acd8182eada41ad83b8d97623db8Mark Andrews <command>dig</command> appropriately converts character encoding of
6cf369f528c4acd8182eada41ad83b8d97623db8Mark Andrews domain name before sending a request to DNS server or displaying a
6cf369f528c4acd8182eada41ad83b8d97623db8Mark Andrews reply from the server.
6cf369f528c4acd8182eada41ad83b8d97623db8Mark Andrews If you'd like to turn off the IDN support for some reason, defines
6cf369f528c4acd8182eada41ad83b8d97623db8Mark Andrews the <envar>IDN_DISABLE</envar> environment variable.
30eec077db2bdcb6f2a0dc388a3cdde2ede75ec1Mark Andrews The IDN support is disabled if the variable is set when
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt </refsection>
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt </refsection>
cf710c81aee40b565323bdb9422b53fe225526f5Evan Hunt <refentrytitle>delv</refentrytitle><manvolnum>1</manvolnum>
cf710c81aee40b565323bdb9422b53fe225526f5Evan Hunt </citerefentry>,
cf710c81aee40b565323bdb9422b53fe225526f5Evan Hunt <citerefentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <refentrytitle>host</refentrytitle><manvolnum>1</manvolnum>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein </citerefentry>,
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein <citerefentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <refentrytitle>named</refentrytitle><manvolnum>8</manvolnum>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein </citerefentry>,
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein <citerefentry>
0af902c0df86a1ddfa54f68b4cf0fab7b469d4e7Mark Andrews <refentrytitle>dnssec-keygen</refentrytitle><manvolnum>8</manvolnum>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein </citerefentry>,
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt </refsection>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein There are probably too many query options.
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt </refsection>