man.delv.html revision a3ff24aaa545c45b8c581b2127d02d735aff8881
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<!--
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony - Copyright (C) 2004-2014 Internet Systems Consortium, Inc. ("ISC")
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony - Copyright (C) 2000-2003 Internet Software Consortium.
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony -
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony - Permission to use, copy, modify, and/or distribute this software for any
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony - purpose with or without fee is hereby granted, provided that the above
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony - copyright notice and this permission notice appear in all copies.
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony -
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
d29d9ab4614ff992b0e8de6e2b88d52b6f1f153erbowen - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
2e545ce2450a9953665f701bb05350f0d3f26275nd - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
d29d9ab4614ff992b0e8de6e2b88d52b6f1f153erbowen - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
d29d9ab4614ff992b0e8de6e2b88d52b6f1f153erbowen - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony - PERFORMANCE OF THIS SOFTWARE.
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony-->
af33a4994ae2ff15bc67d19ff1a7feb906745bf8rbowen<!-- $Id$ -->
3f08db06526d6901aa08c110b5bc7dde6bc39905nd<html>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<head>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<title>delv</title>
3f08db06526d6901aa08c110b5bc7dde6bc39905nd<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<link rel="start" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<link rel="up" href="Bv9ARM.ch10.html" title="Manual pages">
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<link rel="prev" href="man.host.html" title="host">
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<link rel="next" href="man.dnssec-checkds.html" title="dnssec-checkds">
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony</head>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<div class="navheader">
f086b4b402fa9a2fefc7dda85de2a3cc1cd0a654rjung<table width="100%" summary="Navigation header">
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<tr><th colspan="3" align="center">delv</th></tr>
35ac4e1a6ec5aa3cfa1a34d8f20fe8a841cc46b7rbowen<tr>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<td width="20%" align="left">
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<a accesskey="p" href="man.host.html">Prev</a>�</td>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<th width="60%" align="center">Manual pages</th>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<td width="20%" align="right">�<a accesskey="n" href="man.dnssec-checkds.html">Next</a>
94cfb5d816f18c39adb74a03b6502ab73e35a73bnilgun</td>
94cfb5d816f18c39adb74a03b6502ab73e35a73bnilgun</tr>
94cfb5d816f18c39adb74a03b6502ab73e35a73bnilgun</table>
94cfb5d816f18c39adb74a03b6502ab73e35a73bnilgun<hr>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony</div>
94cfb5d816f18c39adb74a03b6502ab73e35a73bnilgun<div class="refentry" lang="en">
94cfb5d816f18c39adb74a03b6502ab73e35a73bnilgun<a name="man.delv"></a><div class="titlepage"></div>
94cfb5d816f18c39adb74a03b6502ab73e35a73bnilgun<div class="refnamediv">
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<h2>Name</h2>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<p>delv &#8212; DNS lookup and validation utility</p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony</div>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<div class="refsynopsisdiv">
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<h2>Synopsis</h2>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<div class="cmdsynopsis"><p><code class="command">delv</code> [@server] [<code class="option">-4</code>] [<code class="option">-6</code>] [<code class="option">-a <em class="replaceable"><code>anchor-file</code></em></code>] [<code class="option">-b <em class="replaceable"><code>address</code></em></code>] [<code class="option">-c <em class="replaceable"><code>class</code></em></code>] [<code class="option">-d <em class="replaceable"><code>level</code></em></code>] [<code class="option">-i</code>] [<code class="option">-m</code>] [<code class="option">-p <em class="replaceable"><code>port#</code></em></code>] [<code class="option">-q <em class="replaceable"><code>name</code></em></code>] [<code class="option">-t <em class="replaceable"><code>type</code></em></code>] [<code class="option">-x <em class="replaceable"><code>addr</code></em></code>] [name] [type] [class] [queryopt...]</p></div>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<div class="cmdsynopsis"><p><code class="command">delv</code> [<code class="option">-h</code>]</p></div>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<div class="cmdsynopsis"><p><code class="command">delv</code> [<code class="option">-v</code>]</p></div>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<div class="cmdsynopsis"><p><code class="command">delv</code> [queryopt...] [query...]</p></div>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony</div>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<div class="refsect1" lang="en">
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<a name="id2616680"></a><h2>DESCRIPTION</h2>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<p><span><strong class="command">delv</strong></span>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony (Domain Entity Lookup &amp; Validation) is a tool for sending
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony DNS queries and validating the results, using the the same internal
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony resolver and validator logic as <span><strong class="command">named</strong></span>.
94cfb5d816f18c39adb74a03b6502ab73e35a73bnilgun </p>
30471a4650391f57975f60bbb6e4a90be7b284bfhumbedooh<p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony <span><strong class="command">delv</strong></span> will send to a specified name server all
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony queries needed to fetch and validate the requested data; this
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony includes the original requested query, subsequent queries to follow
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony CNAME or DNAME chains, and queries for DNSKEY, DS and DLV records
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony to establish a chain of trust for DNSSEC validation.
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony It does not perform iterative resolution, but simulates the
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony behavior of a name server configured for DNSSEC validating and
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony forwarding.
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony </p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony By default, responses are validated using built-in DNSSEC trust
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony anchors for the root zone (".") and for the ISC DNSSEC lookaside
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony validation zone ("dlv.isc.org"). Records returned by
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony <span><strong class="command">delv</strong></span> are either fully validated or
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony were not signed. If validation fails, an explanation of
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony the failure is included in the output; the validation process
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony can be traced in detail. Because <span><strong class="command">delv</strong></span> does
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony not rely on an external server to carry out validation, it can
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony be used to check the validity of DNS responses in environments
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony where local name servers may not be trustworthy.
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony </p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony Unless it is told to query a specific name server,
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony <span><strong class="command">delv</strong></span> will try each of the servers listed in
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony <code class="filename">/etc/resolv.conf</code>. If no usable server
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony addresses are found, <span><strong class="command">delv</strong></span> will send
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony queries to the localhost addresses (127.0.0.1 for IPv4, ::1
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony for IPv6).
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony </p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony When no command line arguments or options are given,
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony <span><strong class="command">delv</strong></span> will perform an NS query for "."
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony (the root zone).
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony </p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony</div>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<div class="refsect1" lang="en">
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<a name="id2616753"></a><h2>SIMPLE USAGE</h2>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony A typical invocation of <span><strong class="command">delv</strong></span> looks like:
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony </p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<pre class="programlisting"> delv @server name type </pre>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony where:
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony </p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<div class="variablelist"><dl>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dt><span class="term"><code class="constant">server</code></span></dt>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dd>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony is the name or IP address of the name server to query. This
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony can be an IPv4 address in dotted-decimal notation or an IPv6
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony address in colon-delimited notation. When the supplied
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony <em class="parameter"><code>server</code></em> argument is a hostname,
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony <span><strong class="command">delv</strong></span> resolves that name before
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony querying that name server (note, however, that this
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony initial lookup is <span class="emphasis"><em>not</em></span> validated
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony by DNSSEC).
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony </p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony If no <em class="parameter"><code>server</code></em> argument is
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony provided, <span><strong class="command">delv</strong></span> consults
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony <code class="filename">/etc/resolv.conf</code>; if an
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony address is found there, it queries the name server at
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony that address. If either of the <code class="option">-4</code> or
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony <code class="option">-6</code> options are in use, then
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony only addresses for the corresponding transport
94cfb5d816f18c39adb74a03b6502ab73e35a73bnilgun will be tried. If no usable addresses are found,
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony <span><strong class="command">delv</strong></span> will send queries to
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony the localhost addresses (127.0.0.1 for IPv4,
b2a930a0c94e9fd25f8d2b3a2c53573235db3f06nilgun ::1 for IPv6).
b2a930a0c94e9fd25f8d2b3a2c53573235db3f06nilgun </p>
b2a930a0c94e9fd25f8d2b3a2c53573235db3f06nilgun</dd>
b2a930a0c94e9fd25f8d2b3a2c53573235db3f06nilgun<dt><span class="term"><code class="constant">name</code></span></dt>
b2a930a0c94e9fd25f8d2b3a2c53573235db3f06nilgun<dd><p>
b2a930a0c94e9fd25f8d2b3a2c53573235db3f06nilgun is the domain name to be looked up.
b2a930a0c94e9fd25f8d2b3a2c53573235db3f06nilgun </p></dd>
b2a930a0c94e9fd25f8d2b3a2c53573235db3f06nilgun<dt><span class="term"><code class="constant">type</code></span></dt>
b2a930a0c94e9fd25f8d2b3a2c53573235db3f06nilgun<dd><p>
b2a930a0c94e9fd25f8d2b3a2c53573235db3f06nilgun indicates what type of query is required &#8212;
b2a930a0c94e9fd25f8d2b3a2c53573235db3f06nilgun ANY, A, MX, etc.
b2a930a0c94e9fd25f8d2b3a2c53573235db3f06nilgun <em class="parameter"><code>type</code></em> can be any valid query
b2a930a0c94e9fd25f8d2b3a2c53573235db3f06nilgun type. If no
b2a930a0c94e9fd25f8d2b3a2c53573235db3f06nilgun <em class="parameter"><code>type</code></em> argument is supplied,
b2a930a0c94e9fd25f8d2b3a2c53573235db3f06nilgun <span><strong class="command">delv</strong></span> will perform a lookup for an
b2a930a0c94e9fd25f8d2b3a2c53573235db3f06nilgun A record.
b2a930a0c94e9fd25f8d2b3a2c53573235db3f06nilgun </p></dd>
b2a930a0c94e9fd25f8d2b3a2c53573235db3f06nilgun</dl></div>
b2a930a0c94e9fd25f8d2b3a2c53573235db3f06nilgun<p>
b2a930a0c94e9fd25f8d2b3a2c53573235db3f06nilgun </p>
b2a930a0c94e9fd25f8d2b3a2c53573235db3f06nilgun</div>
b2a930a0c94e9fd25f8d2b3a2c53573235db3f06nilgun<div class="refsect1" lang="en">
b2a930a0c94e9fd25f8d2b3a2c53573235db3f06nilgun<a name="id2616884"></a><h2>OPTIONS</h2>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<div class="variablelist"><dl>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dt><span class="term">-a <em class="replaceable"><code>anchor-file</code></em></span></dt>
94cfb5d816f18c39adb74a03b6502ab73e35a73bnilgun<dd>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<p>
94cfb5d816f18c39adb74a03b6502ab73e35a73bnilgun Specifies a file from which to read DNSSEC trust anchors.
94cfb5d816f18c39adb74a03b6502ab73e35a73bnilgun The default is <code class="filename">/etc/bind.keys</code>, which
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony is included with <acronym class="acronym">BIND</acronym> 9 and contains
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony trust anchors for the root zone (".") and for the ISC
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony DNSSEC lookaside validation zone ("dlv.isc.org").
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony </p>
316f02e3836836c82e19019ff23f90a7ebc65289nilgun<p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony Keys that do not match the root or DLV trust-anchor
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony names are ignored; these key names can be overridden
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony using the <code class="option">+dlv=NAME</code> or
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony <code class="option">+root=NAME</code> options.
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony </p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony Note: When reading the trust anchor file,
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony <span><strong class="command">delv</strong></span> treats <code class="option">managed-keys</code>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony statements and <code class="option">trusted-keys</code> statements
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony identically. That is, for a managed key, it is the
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony <span class="emphasis"><em>initial</em></span> key that is trusted; RFC 5011
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony key management is not supported. <span><strong class="command">delv</strong></span>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony will not consult the managed-keys database maintained by
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony <span><strong class="command">named</strong></span>. This means that if either of the
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony keys in <code class="filename">/etc/bind.keys</code> is revoked
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony and rolled over, it will be necessary to update
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony <code class="filename">/etc/bind.keys</code> to use DNSSEC
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony validation in <span><strong class="command">delv</strong></span>.
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony </p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony</dd>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dt><span class="term">-b <em class="replaceable"><code>address</code></em></span></dt>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dd><p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony Sets the source IP address of the query to
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony <em class="parameter"><code>address</code></em>. This must be a valid address
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony on one of the host's network interfaces or "0.0.0.0" or "::".
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony An optional source port may be specified by appending
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony "#&lt;port&gt;"
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony </p></dd>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dt><span class="term">-c <em class="replaceable"><code>class</code></em></span></dt>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dd><p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony Sets the query class for the requested data. Currently,
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony only class "IN" is supported in <span><strong class="command">delv</strong></span>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony and any other value is ignored.
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony </p></dd>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dt><span class="term">-d <em class="replaceable"><code>level</code></em></span></dt>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dd><p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony Set the systemwide debug level to <code class="option">level</code>.
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony The allowed range is from 0 to 99.
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony The default is 0 (no debugging).
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony Debugging traces from <span><strong class="command">delv</strong></span> become
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony more verbose as the debug level increases.
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony See the <code class="option">+mtrace</code>, <code class="option">+rtrace</code>,
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony and <code class="option">+vtrace</code> options below for additional
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony debugging details.
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony </p></dd>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dt><span class="term">-h</span></dt>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dd><p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony Display the <span><strong class="command">delv</strong></span> help usage output and exit.
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony </p></dd>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dt><span class="term">-i</span></dt>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dd><p>
94cfb5d816f18c39adb74a03b6502ab73e35a73bnilgun Insecure mode. This disables internal DNSSEC validation.
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony (Note, however, this does not set the CD bit on upstream
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony queries. If the server being queried is performing DNSSEC
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony validation, then it will not return invalid data; this
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony can cause <span><strong class="command">delv</strong></span> to time out. When it
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony is necessary to examine invalid data to debug a DNSSEC
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony problem, use <span><strong class="command">dig +cd</strong></span>.)
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony </p></dd>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dt><span class="term">-m</span></dt>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dd><p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony Enables memory usage debugging.
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony </p></dd>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dt><span class="term">-p <em class="replaceable"><code>port#</code></em></span></dt>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dd><p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony Specifies a destination port to use for queries instead of
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony the standard DNS port number 53. This option would be used
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony with a name server that has been configured to listen
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony for queries on a non-standard port number.
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony </p></dd>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dt><span class="term">-q <em class="replaceable"><code>name</code></em></span></dt>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dd><p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony Sets the query name to <em class="parameter"><code>name</code></em>.
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony While the query name can be specified without using the
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony <code class="option">-q</code>, it is sometimes necessary to disambiguate
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony names from types or classes (for example, when looking up the
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony name "ns", which could be misinterpreted as the type NS,
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony or "ch", which could be misinterpreted as class CH).
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony </p></dd>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dt><span class="term">-t <em class="replaceable"><code>type</code></em></span></dt>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dd>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony Sets the query type to <em class="parameter"><code>type</code></em>, which
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony can be any valid query type supported in BIND 9 except
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony for zone transfer types AXFR and IXFR. As with
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony <code class="option">-q</code>, this is useful to distinguish
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony query name type or class when they are ambiguous.
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony it is sometimes necessary to disambiguate names from types.
94cfb5d816f18c39adb74a03b6502ab73e35a73bnilgun </p>
94cfb5d816f18c39adb74a03b6502ab73e35a73bnilgun<p>
94cfb5d816f18c39adb74a03b6502ab73e35a73bnilgun The default query type is "A", unless the <code class="option">-x</code>
94cfb5d816f18c39adb74a03b6502ab73e35a73bnilgun option is supplied to indicate a reverse lookup, in which case
94cfb5d816f18c39adb74a03b6502ab73e35a73bnilgun it is "PTR".
94cfb5d816f18c39adb74a03b6502ab73e35a73bnilgun </p>
94cfb5d816f18c39adb74a03b6502ab73e35a73bnilgun</dd>
94cfb5d816f18c39adb74a03b6502ab73e35a73bnilgun<dt><span class="term">-v</span></dt>
94cfb5d816f18c39adb74a03b6502ab73e35a73bnilgun<dd><p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony Print the <span><strong class="command">delv</strong></span> version and exit.
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony </p></dd>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dt><span class="term">-x <em class="replaceable"><code>addr</code></em></span></dt>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dd><p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony Performs a reverse lookup, mapping an addresses to
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony a name. <em class="parameter"><code>addr</code></em> is an IPv4 address in
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony dotted-decimal notation, or a colon-delimited IPv6 address.
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony When <code class="option">-x</code> is used, there is no need to provide
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony the <em class="parameter"><code>name</code></em> or <em class="parameter"><code>type</code></em>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony arguments. <span><strong class="command">delv</strong></span> automatically performs a
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony lookup for a name like <code class="literal">11.12.13.10.in-addr.arpa</code>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony and sets the query type to PTR. IPv6 addresses are looked up
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony using nibble format under the IP6.ARPA domain.
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony </p></dd>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dt><span class="term">-4</span></dt>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dd><p>
94cfb5d816f18c39adb74a03b6502ab73e35a73bnilgun Forces <span><strong class="command">delv</strong></span> to only use IPv4.
94cfb5d816f18c39adb74a03b6502ab73e35a73bnilgun </p></dd>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dt><span class="term">-6</span></dt>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dd><p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony Forces <span><strong class="command">delv</strong></span> to only use IPv6.
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony </p></dd>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony</dl></div>
94cfb5d816f18c39adb74a03b6502ab73e35a73bnilgun</div>
94cfb5d816f18c39adb74a03b6502ab73e35a73bnilgun<div class="refsect1" lang="en">
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<a name="id2668838"></a><h2>QUERY OPTIONS</h2>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<p><span><strong class="command">delv</strong></span>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony provides a number of query options which affect the way results are
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony displayed, and in some cases the way lookups are performed.
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony </p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony Each query option is identified by a keyword preceded by a plus sign
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony (<code class="literal">+</code>). Some keywords set or reset an
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony option. These may be preceded by the string
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony <code class="literal">no</code> to negate the meaning of that keyword.
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony Other keywords assign values to options like the timeout interval.
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony They have the form <code class="option">+keyword=value</code>.
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony The query options are:
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony </p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<div class="variablelist"><dl>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dt><span class="term"><code class="option">+[no]cdflag</code></span></dt>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dd><p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony Controls whether to set the CD (checking disabled) bit in
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony queries sent by <span><strong class="command">delv</strong></span>. This may be useful
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony when troubleshooting DNSSEC problems from behind a validating
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony resolver. A validating resolver will block invalid responses,
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony making it difficult to retrieve them for analysis. Setting
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony the CD flag on queries will cause the resolver to return
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony invalid responses, which <span><strong class="command">delv</strong></span> can then
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony validate internally and report the errors in detail.
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony </p></dd>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dt><span class="term"><code class="option">+[no]class</code></span></dt>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dd><p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony Controls whether to display the CLASS when printing
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony a record. The default is to display the CLASS.
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony </p></dd>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dt><span class="term"><code class="option">+[no]ttl</code></span></dt>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dd><p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony Controls whether to display the TTL when printing
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony a record. The default is to display the TTL.
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony </p></dd>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dt><span class="term"><code class="option">+[no]rtrace</code></span></dt>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dd>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony Toggle resolver fetch logging. This reports the
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony name and type of each query sent by <span><strong class="command">delv</strong></span>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony in the process of carrying out the resolution and validation
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony process: this includes including the original query and
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony all subsequent queries to follow CNAMEs and to establish a
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony chain of trust for DNSSEC validation.
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony </p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony This is equivalent to setting the debug level to 1 in
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony the "resolver" logging category. Setting the systemwide
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony debug level to 1 using the <code class="option">-d</code> option will
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony product the same output (but will affect other logging
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony categories as well).
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony </p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony</dd>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dt><span class="term"><code class="option">+[no]mtrace</code></span></dt>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dd>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony Toggle message logging. This produces a detailed dump of
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony the responses received by <span><strong class="command">delv</strong></span> in the
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony process of carrying out the resolution and validation process.
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony </p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony This is equivalent to setting the debug level to 10
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony for the the "packets" module of the "resolver" logging
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony category. Setting the systemwide debug level to 10 using
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony the <code class="option">-d</code> option will produce the same output
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony (but will affect other logging categories as well).
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony </p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony</dd>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dt><span class="term"><code class="option">+[no]vtrace</code></span></dt>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dd>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony Toggle validation logging. This shows the internal
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony process of the validator as it determines whether an
94cfb5d816f18c39adb74a03b6502ab73e35a73bnilgun answer is validly signed, unsigned, or invalid.
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony </p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony This is equivalent to setting the debug level to 3
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony for the the "validator" module of the "dnssec" logging
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony category. Setting the systemwide debug level to 3 using
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony the <code class="option">-d</code> option will produce the same output
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony (but will affect other logging categories as well).
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony </p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony</dd>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dt><span class="term"><code class="option">+[no]short</code></span></dt>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dd><p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony Provide a terse answer. The default is to print the answer in a
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony verbose form.
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony </p></dd>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dt><span class="term"><code class="option">+[no]comments</code></span></dt>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dd><p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony Toggle the display of comment lines in the output. The default
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony is to print comments.
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony </p></dd>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dt><span class="term"><code class="option">+[no]rrcomments</code></span></dt>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dd><p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony Toggle the display of per-record comments in the output (for
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony example, human-readable key information about DNSKEY records).
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony The default is to print per-record comments.
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony </p></dd>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dt><span class="term"><code class="option">+[no]crypto</code></span></dt>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dd><p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony Toggle the display of cryptographic fields in DNSSEC records.
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony The contents of these field are unnecessary to debug most DNSSEC
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony validation failures and removing them makes it easier to see
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony the common failures. The default is to display the fields.
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony When omitted they are replaced by the string "[omitted]" or
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony in the DNSKEY case the key id is displayed as the replacement,
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony e.g. "[ key id = value ]".
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony </p></dd>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dt><span class="term"><code class="option">+[no]trust</code></span></dt>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dd><p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony Controls whether to display the trust level when printing
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony a record. The default is to display the trust level.
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony </p></dd>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dt><span class="term"><code class="option">+[no]split[=W]</code></span></dt>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dd><p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony Split long hex- or base64-formatted fields in resource
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony records into chunks of <em class="parameter"><code>W</code></em> characters
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony (where <em class="parameter"><code>W</code></em> is rounded up to the nearest
94cfb5d816f18c39adb74a03b6502ab73e35a73bnilgun multiple of 4).
94cfb5d816f18c39adb74a03b6502ab73e35a73bnilgun <em class="parameter"><code>+nosplit</code></em> or
94cfb5d816f18c39adb74a03b6502ab73e35a73bnilgun <em class="parameter"><code>+split=0</code></em> causes fields not to be
94cfb5d816f18c39adb74a03b6502ab73e35a73bnilgun split at all. The default is 56 characters, or 44 characters
94cfb5d816f18c39adb74a03b6502ab73e35a73bnilgun when multiline mode is active.
94cfb5d816f18c39adb74a03b6502ab73e35a73bnilgun </p></dd>
94cfb5d816f18c39adb74a03b6502ab73e35a73bnilgun<dt><span class="term"><code class="option">+[no]all</code></span></dt>
94cfb5d816f18c39adb74a03b6502ab73e35a73bnilgun<dd><p>
94cfb5d816f18c39adb74a03b6502ab73e35a73bnilgun Set or clear the display options
94cfb5d816f18c39adb74a03b6502ab73e35a73bnilgun <code class="option">+[no]comments</code>,
94cfb5d816f18c39adb74a03b6502ab73e35a73bnilgun <code class="option">+[no]rrcomments</code>, and
94cfb5d816f18c39adb74a03b6502ab73e35a73bnilgun <code class="option">+[no]trust</code> as a group.
94cfb5d816f18c39adb74a03b6502ab73e35a73bnilgun </p></dd>
94cfb5d816f18c39adb74a03b6502ab73e35a73bnilgun<dt><span class="term"><code class="option">+[no]multiline</code></span></dt>
94cfb5d816f18c39adb74a03b6502ab73e35a73bnilgun<dd><p>
94cfb5d816f18c39adb74a03b6502ab73e35a73bnilgun Print long records (such as RRSIG, DNSKEY, and SOA records)
94cfb5d816f18c39adb74a03b6502ab73e35a73bnilgun in a verbose multi-line format with human-readable comments.
94cfb5d816f18c39adb74a03b6502ab73e35a73bnilgun The default is to print each record on a single line, to
94cfb5d816f18c39adb74a03b6502ab73e35a73bnilgun facilitate machine parsing of the <span><strong class="command">delv</strong></span>
94cfb5d816f18c39adb74a03b6502ab73e35a73bnilgun output.
94cfb5d816f18c39adb74a03b6502ab73e35a73bnilgun </p></dd>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dt><span class="term"><code class="option">+[no]dnssec</code></span></dt>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<dd><p>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony Indicates whether to display RRSIG records in the
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony <span><strong class="command">delv</strong></span> output. The default is to
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony do so. Note that (unlike in <span><strong class="command">dig</strong></span>)
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony this does <span class="emphasis"><em>not</em></span> control whether to
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony request DNSSEC records or whether to validate them.
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony DNSSEC records are always requested, and validation
f086b4b402fa9a2fefc7dda85de2a3cc1cd0a654rjung will always occur unless suppressed by the use of
727872d18412fc021f03969b8641810d8896820bhumbedooh <code class="option">-i</code> or <code class="option">+noroot</code> and
0d0ba3a410038e179b695446bb149cce6264e0abnd <code class="option">+nodlv</code>.
727872d18412fc021f03969b8641810d8896820bhumbedooh </p></dd>
cc7e1025de9ac63bd4db6fe7f71c158b2cf09fe4humbedooh<dt><span class="term"><code class="option">+[no]root[=ROOT]</code></span></dt>
0d0ba3a410038e179b695446bb149cce6264e0abnd<dd><p>
cc7e1025de9ac63bd4db6fe7f71c158b2cf09fe4humbedooh Indicates whether to perform conventional (non-lookaside)
727872d18412fc021f03969b8641810d8896820bhumbedooh DNSSEC validation, and if so, specifies the
0d0ba3a410038e179b695446bb149cce6264e0abnd name of a trust anchor. The default is to validate using
0d0ba3a410038e179b695446bb149cce6264e0abnd a trust anchor of "." (the root zone), for which there is
0d0ba3a410038e179b695446bb149cce6264e0abnd a built-in key. If specifying a different trust anchor,
ac082aefa89416cbdc9a1836eaf3bed9698201c8humbedooh then <code class="option">-a</code> must be used to specify a file
0d0ba3a410038e179b695446bb149cce6264e0abnd containing the key.
0d0ba3a410038e179b695446bb149cce6264e0abnd </p></dd>
0d0ba3a410038e179b695446bb149cce6264e0abnd<dt><span class="term"><code class="option">+[no]dlv[=DLV]</code></span></dt>
727872d18412fc021f03969b8641810d8896820bhumbedooh<dd><p>
0d0ba3a410038e179b695446bb149cce6264e0abnd Indicates whether to perform DNSSEC lookaside validation,
0d0ba3a410038e179b695446bb149cce6264e0abnd and if so, specifies the name of the DLV trust anchor.
30471a4650391f57975f60bbb6e4a90be7b284bfhumbedooh The default is to perform lookaside validation using
07dc96d063d49299da433f84b5c5681da9bbdf68rbowen a trust anchor of "dlv.isc.org", for which there is a
af33a4994ae2ff15bc67d19ff1a7feb906745bf8rbowen built-in key. If specifying a different name, then
0d0ba3a410038e179b695446bb149cce6264e0abnd <code class="option">-a</code> must be used to specify a file
7fec19672a491661b2fe4b29f685bc7f4efa64d4nd containing the DLV key.
7fec19672a491661b2fe4b29f685bc7f4efa64d4nd </p></dd>
7fec19672a491661b2fe4b29f685bc7f4efa64d4nd</dl></div>
0f6bc9e2c8229996a73fb57ec6c45841346ebcb1pctony<p>
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2669286"></a><h2>FILES</h2>
<p><code class="filename">/etc/bind.keys</code></p>
<p><code class="filename">/etc/resolv.conf</code></p>
</div>
<div class="refsect1" lang="en">
<a name="id2669373"></a><h2>SEE ALSO</h2>
<p><span class="citerefentry"><span class="refentrytitle">dig</span>(1)</span>,
<span class="citerefentry"><span class="refentrytitle">named</span>(8)</span>,
<em class="citetitle">RFC4034</em>,
<em class="citetitle">RFC4035</em>,
<em class="citetitle">RFC4431</em>,
<em class="citetitle">RFC5074</em>,
<em class="citetitle">RFC5155</em>.
</p>
</div>
</div>
<div class="navfooter">
<hr>
<table width="100%" summary="Navigation footer">
<tr>
<td width="40%" align="left">
<a accesskey="p" href="man.host.html">Prev</a>�</td>
<td width="20%" align="center"><a accesskey="u" href="Bv9ARM.ch10.html">Up</a></td>
<td width="40%" align="right">�<a accesskey="n" href="man.dnssec-checkds.html">Next</a>
</td>
</tr>
<tr>
<td width="40%" align="left" valign="top">host�</td>
<td width="20%" align="center"><a accesskey="h" href="Bv9ARM.html">Home</a></td>
<td width="40%" align="right" valign="top">�<span class="application">dnssec-checkds</span>
</td>
</tr>
</table>
</div>
<p style="text-align: center;">BIND 9.11.0pre-alpha</p>
</body>
</html>