man.dig.html revision 3acf5eb97cebc2ba868e6ac4a4e01e6d1be0c892
a23fd118e437af0a7877dd313db8fdaa3537c675yl<!--
a23fd118e437af0a7877dd313db8fdaa3537c675yl - Copyright (C) 2004-2010 Internet Systems Consortium, Inc. ("ISC")
a23fd118e437af0a7877dd313db8fdaa3537c675yl - Copyright (C) 2000-2003 Internet Software Consortium.
a23fd118e437af0a7877dd313db8fdaa3537c675yl -
a23fd118e437af0a7877dd313db8fdaa3537c675yl - Permission to use, copy, modify, and/or distribute this software for any
a23fd118e437af0a7877dd313db8fdaa3537c675yl - purpose with or without fee is hereby granted, provided that the above
a23fd118e437af0a7877dd313db8fdaa3537c675yl - copyright notice and this permission notice appear in all copies.
a23fd118e437af0a7877dd313db8fdaa3537c675yl -
a23fd118e437af0a7877dd313db8fdaa3537c675yl - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
a23fd118e437af0a7877dd313db8fdaa3537c675yl - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
a23fd118e437af0a7877dd313db8fdaa3537c675yl - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
a23fd118e437af0a7877dd313db8fdaa3537c675yl - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
a23fd118e437af0a7877dd313db8fdaa3537c675yl - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
a23fd118e437af0a7877dd313db8fdaa3537c675yl - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
a23fd118e437af0a7877dd313db8fdaa3537c675yl - PERFORMANCE OF THIS SOFTWARE.
a23fd118e437af0a7877dd313db8fdaa3537c675yl-->
a23fd118e437af0a7877dd313db8fdaa3537c675yl<!-- $Id: man.dig.html,v 1.150 2010/08/17 01:15:28 tbox Exp $ -->
a23fd118e437af0a7877dd313db8fdaa3537c675yl<html>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<head>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
8347601bcb0a439f6e50fc36b4039a73d08700e1yl<title>dig</title>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
a23fd118e437af0a7877dd313db8fdaa3537c675yl<link rel="start" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
a23fd118e437af0a7877dd313db8fdaa3537c675yl<link rel="up" href="Bv9ARM.ch10.html" title="Manual pages">
a23fd118e437af0a7877dd313db8fdaa3537c675yl<link rel="prev" href="Bv9ARM.ch10.html" title="Manual pages">
a23fd118e437af0a7877dd313db8fdaa3537c675yl<link rel="next" href="man.host.html" title="host">
a23fd118e437af0a7877dd313db8fdaa3537c675yl</head>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
a23fd118e437af0a7877dd313db8fdaa3537c675yl<div class="navheader">
a23fd118e437af0a7877dd313db8fdaa3537c675yl<table width="100%" summary="Navigation header">
a23fd118e437af0a7877dd313db8fdaa3537c675yl<tr><th colspan="3" align="center">dig</th></tr>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<tr>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<td width="20%" align="left">
a23fd118e437af0a7877dd313db8fdaa3537c675yl<a accesskey="p" href="Bv9ARM.ch10.html">Prev</a>�</td>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<th width="60%" align="center">Manual pages</th>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<td width="20%" align="right">�<a accesskey="n" href="man.host.html">Next</a>
a23fd118e437af0a7877dd313db8fdaa3537c675yl</td>
a23fd118e437af0a7877dd313db8fdaa3537c675yl</tr>
a23fd118e437af0a7877dd313db8fdaa3537c675yl</table>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<hr>
a23fd118e437af0a7877dd313db8fdaa3537c675yl</div>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<div class="refentry" lang="en">
a23fd118e437af0a7877dd313db8fdaa3537c675yl<a name="man.dig"></a><div class="titlepage"></div>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<div class="refnamediv">
a23fd118e437af0a7877dd313db8fdaa3537c675yl<h2>Name</h2>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<p>dig &#8212; DNS lookup utility</p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl</div>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<div class="refsynopsisdiv">
a23fd118e437af0a7877dd313db8fdaa3537c675yl<h2>Synopsis</h2>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<div class="cmdsynopsis"><p><code class="command">dig</code> [@server] [<code class="option">-b <em class="replaceable"><code>address</code></em></code>] [<code class="option">-c <em class="replaceable"><code>class</code></em></code>] [<code class="option">-f <em class="replaceable"><code>filename</code></em></code>] [<code class="option">-k <em class="replaceable"><code>filename</code></em></code>] [<code class="option">-m</code>] [<code class="option">-p <em class="replaceable"><code>port#</code></em></code>] [<code class="option">-q <em class="replaceable"><code>name</code></em></code>] [<code class="option">-t <em class="replaceable"><code>type</code></em></code>] [<code class="option">-x <em class="replaceable"><code>addr</code></em></code>] [<code class="option">-y <em class="replaceable"><code>[<span class="optional">hmac:</span>]name:key</code></em></code>] [<code class="option">-4</code>] [<code class="option">-6</code>] [name] [type] [class] [queryopt...]</p></div>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<div class="cmdsynopsis"><p><code class="command">dig</code> [<code class="option">-h</code>]</p></div>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<div class="cmdsynopsis"><p><code class="command">dig</code> [global-queryopt...] [query...]</p></div>
a23fd118e437af0a7877dd313db8fdaa3537c675yl</div>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<div class="refsect1" lang="en">
a23fd118e437af0a7877dd313db8fdaa3537c675yl<a name="id2608683"></a><h2>DESCRIPTION</h2>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<p><span><strong class="command">dig</strong></span>
a23fd118e437af0a7877dd313db8fdaa3537c675yl (domain information groper) is a flexible tool
a23fd118e437af0a7877dd313db8fdaa3537c675yl for interrogating DNS name servers. It performs DNS lookups and
a23fd118e437af0a7877dd313db8fdaa3537c675yl displays the answers that are returned from the name server(s) that
a23fd118e437af0a7877dd313db8fdaa3537c675yl were queried. Most DNS administrators use <span><strong class="command">dig</strong></span> to
a23fd118e437af0a7877dd313db8fdaa3537c675yl troubleshoot DNS problems because of its flexibility, ease of use and
a23fd118e437af0a7877dd313db8fdaa3537c675yl clarity of output. Other lookup tools tend to have less functionality
a23fd118e437af0a7877dd313db8fdaa3537c675yl than <span><strong class="command">dig</strong></span>.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl Although <span><strong class="command">dig</strong></span> is normally used with
a23fd118e437af0a7877dd313db8fdaa3537c675yl command-line
a23fd118e437af0a7877dd313db8fdaa3537c675yl arguments, it also has a batch mode of operation for reading lookup
a23fd118e437af0a7877dd313db8fdaa3537c675yl requests from a file. A brief summary of its command-line arguments
a23fd118e437af0a7877dd313db8fdaa3537c675yl and options is printed when the <code class="option">-h</code> option is given.
a23fd118e437af0a7877dd313db8fdaa3537c675yl Unlike earlier versions, the BIND 9 implementation of
a23fd118e437af0a7877dd313db8fdaa3537c675yl <span><strong class="command">dig</strong></span> allows multiple lookups to be issued
a23fd118e437af0a7877dd313db8fdaa3537c675yl from the
a23fd118e437af0a7877dd313db8fdaa3537c675yl command line.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl Unless it is told to query a specific name server,
a23fd118e437af0a7877dd313db8fdaa3537c675yl <span><strong class="command">dig</strong></span> will try each of the servers listed
a23fd118e437af0a7877dd313db8fdaa3537c675yl in
a23fd118e437af0a7877dd313db8fdaa3537c675yl <code class="filename">/etc/resolv.conf</code>.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl When no command line arguments or options are given,
a23fd118e437af0a7877dd313db8fdaa3537c675yl <span><strong class="command">dig</strong></span> will perform an NS query for "." (the root).
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl It is possible to set per-user defaults for <span><strong class="command">dig</strong></span> via
a23fd118e437af0a7877dd313db8fdaa3537c675yl <code class="filename">${HOME}/.digrc</code>. This file is read and
a23fd118e437af0a7877dd313db8fdaa3537c675yl any options in it
a23fd118e437af0a7877dd313db8fdaa3537c675yl are applied before the command line arguments.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl The IN and CH class names overlap with the IN and CH top level
a23fd118e437af0a7877dd313db8fdaa3537c675yl domains names. Either use the <code class="option">-t</code> and
a23fd118e437af0a7877dd313db8fdaa3537c675yl <code class="option">-c</code> options to specify the type and class,
a23fd118e437af0a7877dd313db8fdaa3537c675yl use the <code class="option">-q</code> the specify the domain name, or
a23fd118e437af0a7877dd313db8fdaa3537c675yl use "IN." and "CH." when looking up these top level domains.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl</div>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<div class="refsect1" lang="en">
a23fd118e437af0a7877dd313db8fdaa3537c675yl<a name="id2608778"></a><h2>SIMPLE USAGE</h2>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl A typical invocation of <span><strong class="command">dig</strong></span> looks like:
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<pre class="programlisting"> dig @server name type </pre>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl where:
a23fd118e437af0a7877dd313db8fdaa3537c675yl
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p>
8347601bcb0a439f6e50fc36b4039a73d08700e1yl<div class="variablelist"><dl>
8347601bcb0a439f6e50fc36b4039a73d08700e1yl<dt><span class="term"><code class="constant">server</code></span></dt>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dd><p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl is the name or IP address of the name server to query. This can
a23fd118e437af0a7877dd313db8fdaa3537c675yl be an IPv4
a23fd118e437af0a7877dd313db8fdaa3537c675yl address in dotted-decimal notation or an IPv6
8347601bcb0a439f6e50fc36b4039a73d08700e1yl address in colon-delimited notation. When the supplied
8347601bcb0a439f6e50fc36b4039a73d08700e1yl <em class="parameter"><code>server</code></em> argument is a
8347601bcb0a439f6e50fc36b4039a73d08700e1yl hostname,
8347601bcb0a439f6e50fc36b4039a73d08700e1yl <span><strong class="command">dig</strong></span> resolves that name before
a23fd118e437af0a7877dd313db8fdaa3537c675yl querying that name
a23fd118e437af0a7877dd313db8fdaa3537c675yl server. If no <em class="parameter"><code>server</code></em>
a23fd118e437af0a7877dd313db8fdaa3537c675yl argument is provided,
8347601bcb0a439f6e50fc36b4039a73d08700e1yl <span><strong class="command">dig</strong></span> consults <code class="filename">/etc/resolv.conf</code>
8347601bcb0a439f6e50fc36b4039a73d08700e1yl and queries the name servers listed there. The reply from the
8347601bcb0a439f6e50fc36b4039a73d08700e1yl name
a23fd118e437af0a7877dd313db8fdaa3537c675yl server that responds is displayed.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p></dd>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dt><span class="term"><code class="constant">name</code></span></dt>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dd><p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl is the name of the resource record that is to be looked up.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p></dd>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dt><span class="term"><code class="constant">type</code></span></dt>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dd><p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl indicates what type of query is required &#8212;
a23fd118e437af0a7877dd313db8fdaa3537c675yl ANY, A, MX, SIG, etc.
a23fd118e437af0a7877dd313db8fdaa3537c675yl <em class="parameter"><code>type</code></em> can be any valid query
a23fd118e437af0a7877dd313db8fdaa3537c675yl type. If no
a23fd118e437af0a7877dd313db8fdaa3537c675yl <em class="parameter"><code>type</code></em> argument is supplied,
a23fd118e437af0a7877dd313db8fdaa3537c675yl <span><strong class="command">dig</strong></span> will perform a lookup for an
a23fd118e437af0a7877dd313db8fdaa3537c675yl A record.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p></dd>
a23fd118e437af0a7877dd313db8fdaa3537c675yl</dl></div>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl</div>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<div class="refsect1" lang="en">
a23fd118e437af0a7877dd313db8fdaa3537c675yl<a name="id2609094"></a><h2>OPTIONS</h2>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl The <code class="option">-b</code> option sets the source IP address of the query
a23fd118e437af0a7877dd313db8fdaa3537c675yl to <em class="parameter"><code>address</code></em>. This must be a valid
a23fd118e437af0a7877dd313db8fdaa3537c675yl address on
a23fd118e437af0a7877dd313db8fdaa3537c675yl one of the host's network interfaces or "0.0.0.0" or "::". An optional
a23fd118e437af0a7877dd313db8fdaa3537c675yl port
a23fd118e437af0a7877dd313db8fdaa3537c675yl may be specified by appending "#&lt;port&gt;"
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl The default query class (IN for internet) is overridden by the
a23fd118e437af0a7877dd313db8fdaa3537c675yl <code class="option">-c</code> option. <em class="parameter"><code>class</code></em> is
a23fd118e437af0a7877dd313db8fdaa3537c675yl any valid
a23fd118e437af0a7877dd313db8fdaa3537c675yl class, such as HS for Hesiod records or CH for Chaosnet records.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl The <code class="option">-f</code> option makes <span><strong class="command">dig </strong></span>
a23fd118e437af0a7877dd313db8fdaa3537c675yl operate
a23fd118e437af0a7877dd313db8fdaa3537c675yl in batch mode by reading a list of lookup requests to process from the
a23fd118e437af0a7877dd313db8fdaa3537c675yl file <em class="parameter"><code>filename</code></em>. The file contains a
a23fd118e437af0a7877dd313db8fdaa3537c675yl number of
a23fd118e437af0a7877dd313db8fdaa3537c675yl queries, one per line. Each entry in the file should be organized in
a23fd118e437af0a7877dd313db8fdaa3537c675yl the same way they would be presented as queries to
a23fd118e437af0a7877dd313db8fdaa3537c675yl <span><strong class="command">dig</strong></span> using the command-line interface.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl The <code class="option">-m</code> option enables memory usage debugging.
a23fd118e437af0a7877dd313db8fdaa3537c675yl
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl If a non-standard port number is to be queried, the
a23fd118e437af0a7877dd313db8fdaa3537c675yl <code class="option">-p</code> option is used. <em class="parameter"><code>port#</code></em> is
a23fd118e437af0a7877dd313db8fdaa3537c675yl the port number that <span><strong class="command">dig</strong></span> will send its
a23fd118e437af0a7877dd313db8fdaa3537c675yl queries
a23fd118e437af0a7877dd313db8fdaa3537c675yl instead of the standard DNS port number 53. This option would be used
a23fd118e437af0a7877dd313db8fdaa3537c675yl to test a name server that has been configured to listen for queries
a23fd118e437af0a7877dd313db8fdaa3537c675yl on a non-standard port number.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl The <code class="option">-4</code> option forces <span><strong class="command">dig</strong></span>
a23fd118e437af0a7877dd313db8fdaa3537c675yl to only
a23fd118e437af0a7877dd313db8fdaa3537c675yl use IPv4 query transport. The <code class="option">-6</code> option forces
a23fd118e437af0a7877dd313db8fdaa3537c675yl <span><strong class="command">dig</strong></span> to only use IPv6 query transport.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl The <code class="option">-t</code> option sets the query type to
a23fd118e437af0a7877dd313db8fdaa3537c675yl <em class="parameter"><code>type</code></em>. It can be any valid query type
a23fd118e437af0a7877dd313db8fdaa3537c675yl which is
a23fd118e437af0a7877dd313db8fdaa3537c675yl supported in BIND 9. The default query type is "A", unless the
a23fd118e437af0a7877dd313db8fdaa3537c675yl <code class="option">-x</code> option is supplied to indicate a reverse lookup.
a23fd118e437af0a7877dd313db8fdaa3537c675yl A zone transfer can be requested by specifying a type of AXFR. When
a23fd118e437af0a7877dd313db8fdaa3537c675yl an incremental zone transfer (IXFR) is required,
a23fd118e437af0a7877dd313db8fdaa3537c675yl <em class="parameter"><code>type</code></em> is set to <code class="literal">ixfr=N</code>.
a23fd118e437af0a7877dd313db8fdaa3537c675yl The incremental zone transfer will contain the changes made to the zone
a23fd118e437af0a7877dd313db8fdaa3537c675yl since the serial number in the zone's SOA record was
a23fd118e437af0a7877dd313db8fdaa3537c675yl <em class="parameter"><code>N</code></em>.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl The <code class="option">-q</code> option sets the query name to
a23fd118e437af0a7877dd313db8fdaa3537c675yl <em class="parameter"><code>name</code></em>. This useful do distinguish the
a23fd118e437af0a7877dd313db8fdaa3537c675yl <em class="parameter"><code>name</code></em> from other arguments.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl Reverse lookups &#8212; mapping addresses to names &#8212; are simplified by the
a23fd118e437af0a7877dd313db8fdaa3537c675yl <code class="option">-x</code> option. <em class="parameter"><code>addr</code></em> is
a23fd118e437af0a7877dd313db8fdaa3537c675yl an IPv4
a23fd118e437af0a7877dd313db8fdaa3537c675yl address in dotted-decimal notation, or a colon-delimited IPv6 address.
a23fd118e437af0a7877dd313db8fdaa3537c675yl When this option is used, there is no need to provide the
a23fd118e437af0a7877dd313db8fdaa3537c675yl <em class="parameter"><code>name</code></em>, <em class="parameter"><code>class</code></em> and
a23fd118e437af0a7877dd313db8fdaa3537c675yl <em class="parameter"><code>type</code></em> arguments. <span><strong class="command">dig</strong></span>
a23fd118e437af0a7877dd313db8fdaa3537c675yl automatically performs a lookup for a name like
a23fd118e437af0a7877dd313db8fdaa3537c675yl <code class="literal">11.12.13.10.in-addr.arpa</code> and sets the
a23fd118e437af0a7877dd313db8fdaa3537c675yl query type and
a23fd118e437af0a7877dd313db8fdaa3537c675yl class to PTR and IN respectively. By default, IPv6 addresses are
a23fd118e437af0a7877dd313db8fdaa3537c675yl looked up using nibble format under the IP6.ARPA domain.
a23fd118e437af0a7877dd313db8fdaa3537c675yl To use the older RFC1886 method using the IP6.INT domain
a23fd118e437af0a7877dd313db8fdaa3537c675yl specify the <code class="option">-i</code> option. Bit string labels (RFC2874)
a23fd118e437af0a7877dd313db8fdaa3537c675yl are now experimental and are not attempted.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl To sign the DNS queries sent by <span><strong class="command">dig</strong></span> and
a23fd118e437af0a7877dd313db8fdaa3537c675yl their
a23fd118e437af0a7877dd313db8fdaa3537c675yl responses using transaction signatures (TSIG), specify a TSIG key file
a23fd118e437af0a7877dd313db8fdaa3537c675yl using the <code class="option">-k</code> option. You can also specify the TSIG
a23fd118e437af0a7877dd313db8fdaa3537c675yl key itself on the command line using the <code class="option">-y</code> option;
a23fd118e437af0a7877dd313db8fdaa3537c675yl <em class="parameter"><code>hmac</code></em> is the type of the TSIG, default HMAC-MD5,
a23fd118e437af0a7877dd313db8fdaa3537c675yl <em class="parameter"><code>name</code></em> is the name of the TSIG key and
a23fd118e437af0a7877dd313db8fdaa3537c675yl <em class="parameter"><code>key</code></em> is the actual key. The key is a
a23fd118e437af0a7877dd313db8fdaa3537c675yl base-64
a23fd118e437af0a7877dd313db8fdaa3537c675yl encoded string, typically generated by
a23fd118e437af0a7877dd313db8fdaa3537c675yl <span class="citerefentry"><span class="refentrytitle">dnssec-keygen</span>(8)</span>.
a23fd118e437af0a7877dd313db8fdaa3537c675yl
a23fd118e437af0a7877dd313db8fdaa3537c675yl Caution should be taken when using the <code class="option">-y</code> option on
a23fd118e437af0a7877dd313db8fdaa3537c675yl multi-user systems as the key can be visible in the output from
a23fd118e437af0a7877dd313db8fdaa3537c675yl <span class="citerefentry"><span class="refentrytitle">ps</span>(1)</span>
a23fd118e437af0a7877dd313db8fdaa3537c675yl or in the shell's history file. When
a23fd118e437af0a7877dd313db8fdaa3537c675yl using TSIG authentication with <span><strong class="command">dig</strong></span>, the name
a23fd118e437af0a7877dd313db8fdaa3537c675yl server that is queried needs to know the key and algorithm that is
a23fd118e437af0a7877dd313db8fdaa3537c675yl being used. In BIND, this is done by providing appropriate
a23fd118e437af0a7877dd313db8fdaa3537c675yl <span><strong class="command">key</strong></span> and <span><strong class="command">server</strong></span> statements in
a23fd118e437af0a7877dd313db8fdaa3537c675yl <code class="filename">named.conf</code>.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl</div>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<div class="refsect1" lang="en">
a23fd118e437af0a7877dd313db8fdaa3537c675yl<a name="id2661114"></a><h2>QUERY OPTIONS</h2>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<p><span><strong class="command">dig</strong></span>
a23fd118e437af0a7877dd313db8fdaa3537c675yl provides a number of query options which affect
a23fd118e437af0a7877dd313db8fdaa3537c675yl the way in which lookups are made and the results displayed. Some of
a23fd118e437af0a7877dd313db8fdaa3537c675yl these set or reset flag bits in the query header, some determine which
a23fd118e437af0a7877dd313db8fdaa3537c675yl sections of the answer get printed, and others determine the timeout
a23fd118e437af0a7877dd313db8fdaa3537c675yl and retry strategies.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl Each query option is identified by a keyword preceded by a plus sign
a23fd118e437af0a7877dd313db8fdaa3537c675yl (<code class="literal">+</code>). Some keywords set or reset an
a23fd118e437af0a7877dd313db8fdaa3537c675yl option. These may be preceded
a23fd118e437af0a7877dd313db8fdaa3537c675yl by the string <code class="literal">no</code> to negate the meaning of
a23fd118e437af0a7877dd313db8fdaa3537c675yl that keyword. Other
a23fd118e437af0a7877dd313db8fdaa3537c675yl keywords assign values to options like the timeout interval. They
a23fd118e437af0a7877dd313db8fdaa3537c675yl have the form <code class="option">+keyword=value</code>.
a23fd118e437af0a7877dd313db8fdaa3537c675yl The query options are:
a23fd118e437af0a7877dd313db8fdaa3537c675yl
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<div class="variablelist"><dl>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dt><span class="term"><code class="option">+[no]tcp</code></span></dt>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dd><p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl Use [do not use] TCP when querying name servers. The default
a23fd118e437af0a7877dd313db8fdaa3537c675yl behavior is to use UDP unless an AXFR or IXFR query is
a23fd118e437af0a7877dd313db8fdaa3537c675yl requested, in
a23fd118e437af0a7877dd313db8fdaa3537c675yl which case a TCP connection is used.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p></dd>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dt><span class="term"><code class="option">+[no]vc</code></span></dt>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dd><p>
8347601bcb0a439f6e50fc36b4039a73d08700e1yl Use [do not use] TCP when querying name servers. This alternate
a23fd118e437af0a7877dd313db8fdaa3537c675yl syntax to <em class="parameter"><code>+[no]tcp</code></em> is
a23fd118e437af0a7877dd313db8fdaa3537c675yl provided for backwards
a23fd118e437af0a7877dd313db8fdaa3537c675yl compatibility. The "vc" stands for "virtual circuit".
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p></dd>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dt><span class="term"><code class="option">+[no]ignore</code></span></dt>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dd><p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl Ignore truncation in UDP responses instead of retrying with TCP.
a23fd118e437af0a7877dd313db8fdaa3537c675yl By
8347601bcb0a439f6e50fc36b4039a73d08700e1yl default, TCP retries are performed.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p></dd>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dt><span class="term"><code class="option">+domain=somename</code></span></dt>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dd><p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl Set the search list to contain the single domain
8347601bcb0a439f6e50fc36b4039a73d08700e1yl <em class="parameter"><code>somename</code></em>, as if specified in
a23fd118e437af0a7877dd313db8fdaa3537c675yl a
a23fd118e437af0a7877dd313db8fdaa3537c675yl <span><strong class="command">domain</strong></span> directive in
a23fd118e437af0a7877dd313db8fdaa3537c675yl <code class="filename">/etc/resolv.conf</code>, and enable
a23fd118e437af0a7877dd313db8fdaa3537c675yl search list
a23fd118e437af0a7877dd313db8fdaa3537c675yl processing as if the <em class="parameter"><code>+search</code></em>
a23fd118e437af0a7877dd313db8fdaa3537c675yl option were given.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p></dd>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dt><span class="term"><code class="option">+[no]search</code></span></dt>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dd><p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl Use [do not use] the search list defined by the searchlist or
a23fd118e437af0a7877dd313db8fdaa3537c675yl domain
a23fd118e437af0a7877dd313db8fdaa3537c675yl directive in <code class="filename">resolv.conf</code> (if
a23fd118e437af0a7877dd313db8fdaa3537c675yl any).
a23fd118e437af0a7877dd313db8fdaa3537c675yl The search list is not used by default.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p></dd>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dt><span class="term"><code class="option">+[no]showsearch</code></span></dt>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dd><p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl Perform [do not perform] a search showing intermediate
a23fd118e437af0a7877dd313db8fdaa3537c675yl results.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p></dd>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dt><span class="term"><code class="option">+[no]defname</code></span></dt>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dd><p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl Deprecated, treated as a synonym for <em class="parameter"><code>+[no]search</code></em>
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p></dd>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dt><span class="term"><code class="option">+[no]aaonly</code></span></dt>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dd><p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl Sets the "aa" flag in the query.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p></dd>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dt><span class="term"><code class="option">+[no]aaflag</code></span></dt>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dd><p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl A synonym for <em class="parameter"><code>+[no]aaonly</code></em>.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p></dd>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dt><span class="term"><code class="option">+[no]adflag</code></span></dt>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dd><p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl Set [do not set] the AD (authentic data) bit in the
a23fd118e437af0a7877dd313db8fdaa3537c675yl query. This requests the server to return whether
a23fd118e437af0a7877dd313db8fdaa3537c675yl all of the answer and authority sections have all
a23fd118e437af0a7877dd313db8fdaa3537c675yl been validated as secure according to the security
a23fd118e437af0a7877dd313db8fdaa3537c675yl policy of the server. AD=1 indicates that all records
8347601bcb0a439f6e50fc36b4039a73d08700e1yl have been validated as secure and the answer is not
a23fd118e437af0a7877dd313db8fdaa3537c675yl from a OPT-OUT range. AD=0 indicate that some part
a23fd118e437af0a7877dd313db8fdaa3537c675yl of the answer was insecure or not validated.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p></dd>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dt><span class="term"><code class="option">+[no]cdflag</code></span></dt>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dd><p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl Set [do not set] the CD (checking disabled) bit in the query.
a23fd118e437af0a7877dd313db8fdaa3537c675yl This
a23fd118e437af0a7877dd313db8fdaa3537c675yl requests the server to not perform DNSSEC validation of
a23fd118e437af0a7877dd313db8fdaa3537c675yl responses.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p></dd>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dt><span class="term"><code class="option">+[no]cl</code></span></dt>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dd><p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl Display [do not display] the CLASS when printing the record.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p></dd>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dt><span class="term"><code class="option">+[no]ttlid</code></span></dt>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dd><p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl Display [do not display] the TTL when printing the record.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p></dd>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dt><span class="term"><code class="option">+[no]recurse</code></span></dt>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dd><p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl Toggle the setting of the RD (recursion desired) bit in the
a23fd118e437af0a7877dd313db8fdaa3537c675yl query.
a23fd118e437af0a7877dd313db8fdaa3537c675yl This bit is set by default, which means <span><strong class="command">dig</strong></span>
a23fd118e437af0a7877dd313db8fdaa3537c675yl normally sends recursive queries. Recursion is automatically
8347601bcb0a439f6e50fc36b4039a73d08700e1yl disabled
a23fd118e437af0a7877dd313db8fdaa3537c675yl when the <em class="parameter"><code>+nssearch</code></em> or
a23fd118e437af0a7877dd313db8fdaa3537c675yl <em class="parameter"><code>+trace</code></em> query options are
a23fd118e437af0a7877dd313db8fdaa3537c675yl used.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p></dd>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dt><span class="term"><code class="option">+[no]nssearch</code></span></dt>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dd><p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl When this option is set, <span><strong class="command">dig</strong></span>
a23fd118e437af0a7877dd313db8fdaa3537c675yl attempts to find the
a23fd118e437af0a7877dd313db8fdaa3537c675yl authoritative name servers for the zone containing the name
a23fd118e437af0a7877dd313db8fdaa3537c675yl being
a23fd118e437af0a7877dd313db8fdaa3537c675yl looked up and display the SOA record that each name server has
a23fd118e437af0a7877dd313db8fdaa3537c675yl for the
a23fd118e437af0a7877dd313db8fdaa3537c675yl zone.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p></dd>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dt><span class="term"><code class="option">+[no]trace</code></span></dt>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dd><p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl Toggle tracing of the delegation path from the root name servers
a23fd118e437af0a7877dd313db8fdaa3537c675yl for
a23fd118e437af0a7877dd313db8fdaa3537c675yl the name being looked up. Tracing is disabled by default. When
a23fd118e437af0a7877dd313db8fdaa3537c675yl tracing is enabled, <span><strong class="command">dig</strong></span> makes
a23fd118e437af0a7877dd313db8fdaa3537c675yl iterative queries to
a23fd118e437af0a7877dd313db8fdaa3537c675yl resolve the name being looked up. It will follow referrals from
a23fd118e437af0a7877dd313db8fdaa3537c675yl the
a23fd118e437af0a7877dd313db8fdaa3537c675yl root servers, showing the answer from each server that was used
a23fd118e437af0a7877dd313db8fdaa3537c675yl to
a23fd118e437af0a7877dd313db8fdaa3537c675yl resolve the lookup.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p></dd>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dt><span class="term"><code class="option">+[no]cmd</code></span></dt>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dd><p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl Toggles the printing of the initial comment in the output
a23fd118e437af0a7877dd313db8fdaa3537c675yl identifying
a23fd118e437af0a7877dd313db8fdaa3537c675yl the version of <span><strong class="command">dig</strong></span> and the query
a23fd118e437af0a7877dd313db8fdaa3537c675yl options that have
a23fd118e437af0a7877dd313db8fdaa3537c675yl been applied. This comment is printed by default.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p></dd>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dt><span class="term"><code class="option">+[no]short</code></span></dt>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dd><p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl Provide a terse answer. The default is to print the answer in a
a23fd118e437af0a7877dd313db8fdaa3537c675yl verbose form.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p></dd>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dt><span class="term"><code class="option">+[no]identify</code></span></dt>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dd><p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl Show [or do not show] the IP address and port number that
a23fd118e437af0a7877dd313db8fdaa3537c675yl supplied the
a23fd118e437af0a7877dd313db8fdaa3537c675yl answer when the <em class="parameter"><code>+short</code></em> option
a23fd118e437af0a7877dd313db8fdaa3537c675yl is enabled. If
a23fd118e437af0a7877dd313db8fdaa3537c675yl short form answers are requested, the default is not to show the
a23fd118e437af0a7877dd313db8fdaa3537c675yl source address and port number of the server that provided the
a23fd118e437af0a7877dd313db8fdaa3537c675yl answer.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p></dd>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dt><span class="term"><code class="option">+[no]comments</code></span></dt>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dd><p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl Toggle the display of comment lines in the output. The default
a23fd118e437af0a7877dd313db8fdaa3537c675yl is to
a23fd118e437af0a7877dd313db8fdaa3537c675yl print comments.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p></dd>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dt><span class="term"><code class="option">+[no]stats</code></span></dt>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dd><p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl This query option toggles the printing of statistics: when the
a23fd118e437af0a7877dd313db8fdaa3537c675yl query
a23fd118e437af0a7877dd313db8fdaa3537c675yl was made, the size of the reply and so on. The default
a23fd118e437af0a7877dd313db8fdaa3537c675yl behavior is
a23fd118e437af0a7877dd313db8fdaa3537c675yl to print the query statistics.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p></dd>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dt><span class="term"><code class="option">+[no]qr</code></span></dt>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dd><p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl Print [do not print] the query as it is sent.
a23fd118e437af0a7877dd313db8fdaa3537c675yl By default, the query is not printed.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p></dd>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dt><span class="term"><code class="option">+[no]question</code></span></dt>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dd><p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl Print [do not print] the question section of a query when an
a23fd118e437af0a7877dd313db8fdaa3537c675yl answer is
a23fd118e437af0a7877dd313db8fdaa3537c675yl returned. The default is to print the question section as a
a23fd118e437af0a7877dd313db8fdaa3537c675yl comment.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p></dd>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dt><span class="term"><code class="option">+[no]answer</code></span></dt>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dd><p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl Display [do not display] the answer section of a reply. The
a23fd118e437af0a7877dd313db8fdaa3537c675yl default
a23fd118e437af0a7877dd313db8fdaa3537c675yl is to display it.
8347601bcb0a439f6e50fc36b4039a73d08700e1yl </p></dd>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dt><span class="term"><code class="option">+[no]authority</code></span></dt>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dd><p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl Display [do not display] the authority section of a reply. The
a23fd118e437af0a7877dd313db8fdaa3537c675yl default is to display it.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p></dd>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dt><span class="term"><code class="option">+[no]additional</code></span></dt>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dd><p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl Display [do not display] the additional section of a reply.
a23fd118e437af0a7877dd313db8fdaa3537c675yl The default is to display it.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p></dd>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dt><span class="term"><code class="option">+[no]all</code></span></dt>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dd><p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl Set or clear all display flags.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p></dd>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dt><span class="term"><code class="option">+time=T</code></span></dt>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dd><p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl
a23fd118e437af0a7877dd313db8fdaa3537c675yl Sets the timeout for a query to
a23fd118e437af0a7877dd313db8fdaa3537c675yl <em class="parameter"><code>T</code></em> seconds. The default
a23fd118e437af0a7877dd313db8fdaa3537c675yl timeout is 5 seconds.
a23fd118e437af0a7877dd313db8fdaa3537c675yl An attempt to set <em class="parameter"><code>T</code></em> to less
a23fd118e437af0a7877dd313db8fdaa3537c675yl than 1 will result
a23fd118e437af0a7877dd313db8fdaa3537c675yl in a query timeout of 1 second being applied.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p></dd>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dt><span class="term"><code class="option">+tries=T</code></span></dt>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dd><p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl Sets the number of times to try UDP queries to server to
a23fd118e437af0a7877dd313db8fdaa3537c675yl <em class="parameter"><code>T</code></em> instead of the default, 3.
a23fd118e437af0a7877dd313db8fdaa3537c675yl If
a23fd118e437af0a7877dd313db8fdaa3537c675yl <em class="parameter"><code>T</code></em> is less than or equal to
a23fd118e437af0a7877dd313db8fdaa3537c675yl zero, the number of
a23fd118e437af0a7877dd313db8fdaa3537c675yl tries is silently rounded up to 1.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p></dd>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dt><span class="term"><code class="option">+retry=T</code></span></dt>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dd><p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl Sets the number of times to retry UDP queries to server to
a23fd118e437af0a7877dd313db8fdaa3537c675yl <em class="parameter"><code>T</code></em> instead of the default, 2.
a23fd118e437af0a7877dd313db8fdaa3537c675yl Unlike
a23fd118e437af0a7877dd313db8fdaa3537c675yl <em class="parameter"><code>+tries</code></em>, this does not include
a23fd118e437af0a7877dd313db8fdaa3537c675yl the initial
a23fd118e437af0a7877dd313db8fdaa3537c675yl query.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p></dd>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dt><span class="term"><code class="option">+ndots=D</code></span></dt>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dd><p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl Set the number of dots that have to appear in
a23fd118e437af0a7877dd313db8fdaa3537c675yl <em class="parameter"><code>name</code></em> to <em class="parameter"><code>D</code></em> for it to be
a23fd118e437af0a7877dd313db8fdaa3537c675yl considered absolute. The default value is that defined using
a23fd118e437af0a7877dd313db8fdaa3537c675yl the
a23fd118e437af0a7877dd313db8fdaa3537c675yl ndots statement in <code class="filename">/etc/resolv.conf</code>, or 1 if no
a23fd118e437af0a7877dd313db8fdaa3537c675yl ndots statement is present. Names with fewer dots are
a23fd118e437af0a7877dd313db8fdaa3537c675yl interpreted as
a23fd118e437af0a7877dd313db8fdaa3537c675yl relative names and will be searched for in the domains listed in
a23fd118e437af0a7877dd313db8fdaa3537c675yl the
a23fd118e437af0a7877dd313db8fdaa3537c675yl <code class="option">search</code> or <code class="option">domain</code> directive in
a23fd118e437af0a7877dd313db8fdaa3537c675yl <code class="filename">/etc/resolv.conf</code>.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p></dd>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dt><span class="term"><code class="option">+bufsize=B</code></span></dt>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dd><p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl Set the UDP message buffer size advertised using EDNS0 to
a23fd118e437af0a7877dd313db8fdaa3537c675yl <em class="parameter"><code>B</code></em> bytes. The maximum and minimum sizes
a23fd118e437af0a7877dd313db8fdaa3537c675yl of this buffer are 65535 and 0 respectively. Values outside
a23fd118e437af0a7877dd313db8fdaa3537c675yl this range are rounded up or down appropriately.
a23fd118e437af0a7877dd313db8fdaa3537c675yl Values other than zero will cause a EDNS query to be sent.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p></dd>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dt><span class="term"><code class="option">+edns=#</code></span></dt>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dd><p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl Specify the EDNS version to query with. Valid values
a23fd118e437af0a7877dd313db8fdaa3537c675yl are 0 to 255. Setting the EDNS version will cause a
a23fd118e437af0a7877dd313db8fdaa3537c675yl EDNS query to be sent. <code class="option">+noedns</code> clears the
a23fd118e437af0a7877dd313db8fdaa3537c675yl remembered EDNS version.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p></dd>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dt><span class="term"><code class="option">+[no]multiline</code></span></dt>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dd><p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl Print records like the SOA records in a verbose multi-line
a23fd118e437af0a7877dd313db8fdaa3537c675yl format with human-readable comments. The default is to print
a23fd118e437af0a7877dd313db8fdaa3537c675yl each record on a single line, to facilitate machine parsing
a23fd118e437af0a7877dd313db8fdaa3537c675yl of the <span><strong class="command">dig</strong></span> output.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p></dd>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dt><span class="term"><code class="option">+[no]onesoa</code></span></dt>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dd><p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl Print only one (starting) SOA record when performing
a23fd118e437af0a7877dd313db8fdaa3537c675yl an AXFR. The default is to print both the starting and
a23fd118e437af0a7877dd313db8fdaa3537c675yl ending SOA records.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p></dd>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dt><span class="term"><code class="option">+[no]fail</code></span></dt>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dd><p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl Do not try the next server if you receive a SERVFAIL. The
a23fd118e437af0a7877dd313db8fdaa3537c675yl default is
a23fd118e437af0a7877dd313db8fdaa3537c675yl to not try the next server which is the reverse of normal stub
a23fd118e437af0a7877dd313db8fdaa3537c675yl resolver
a23fd118e437af0a7877dd313db8fdaa3537c675yl behavior.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p></dd>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dt><span class="term"><code class="option">+[no]besteffort</code></span></dt>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dd><p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl Attempt to display the contents of messages which are malformed.
a23fd118e437af0a7877dd313db8fdaa3537c675yl The default is to not display malformed answers.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p></dd>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dt><span class="term"><code class="option">+[no]dnssec</code></span></dt>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dd><p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl Requests DNSSEC records be sent by setting the DNSSEC OK bit
a23fd118e437af0a7877dd313db8fdaa3537c675yl (DO)
a23fd118e437af0a7877dd313db8fdaa3537c675yl in the OPT record in the additional section of the query.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p></dd>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dt><span class="term"><code class="option">+[no]sigchase</code></span></dt>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dd><p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl Chase DNSSEC signature chains. Requires dig be compiled with
a23fd118e437af0a7877dd313db8fdaa3537c675yl -DDIG_SIGCHASE.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p></dd>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dt><span class="term"><code class="option">+trusted-key=####</code></span></dt>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dd>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl Specifies a file containing trusted keys to be used with
a23fd118e437af0a7877dd313db8fdaa3537c675yl <code class="option">+sigchase</code>. Each DNSKEY record must be
a23fd118e437af0a7877dd313db8fdaa3537c675yl on its own line.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl If not specified, <span><strong class="command">dig</strong></span> will look for
a23fd118e437af0a7877dd313db8fdaa3537c675yl <code class="filename">/etc/trusted-key.key</code> then
a23fd118e437af0a7877dd313db8fdaa3537c675yl <code class="filename">trusted-key.key</code> in the current directory.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl Requires dig be compiled with -DDIG_SIGCHASE.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl</dd>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dt><span class="term"><code class="option">+[no]topdown</code></span></dt>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dd><p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl When chasing DNSSEC signature chains perform a top-down
a23fd118e437af0a7877dd313db8fdaa3537c675yl validation.
a23fd118e437af0a7877dd313db8fdaa3537c675yl Requires dig be compiled with -DDIG_SIGCHASE.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p></dd>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dt><span class="term"><code class="option">+[no]nsid</code></span></dt>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<dd><p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl Include an EDNS name server ID request when sending a query.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p></dd>
a23fd118e437af0a7877dd313db8fdaa3537c675yl</dl></div>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl</div>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<div class="refsect1" lang="en">
a23fd118e437af0a7877dd313db8fdaa3537c675yl<a name="id2662197"></a><h2>MULTIPLE QUERIES</h2>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl The BIND 9 implementation of <span><strong class="command">dig </strong></span>
a23fd118e437af0a7877dd313db8fdaa3537c675yl supports
a23fd118e437af0a7877dd313db8fdaa3537c675yl specifying multiple queries on the command line (in addition to
a23fd118e437af0a7877dd313db8fdaa3537c675yl supporting the <code class="option">-f</code> batch file option). Each of those
a23fd118e437af0a7877dd313db8fdaa3537c675yl queries can be supplied with its own set of flags, options and query
a23fd118e437af0a7877dd313db8fdaa3537c675yl options.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl In this case, each <em class="parameter"><code>query</code></em> argument
a23fd118e437af0a7877dd313db8fdaa3537c675yl represent an
a23fd118e437af0a7877dd313db8fdaa3537c675yl individual query in the command-line syntax described above. Each
a23fd118e437af0a7877dd313db8fdaa3537c675yl consists of any of the standard options and flags, the name to be
a23fd118e437af0a7877dd313db8fdaa3537c675yl looked up, an optional query type and class and any query options that
a23fd118e437af0a7877dd313db8fdaa3537c675yl should be applied to that query.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl A global set of query options, which should be applied to all queries,
a23fd118e437af0a7877dd313db8fdaa3537c675yl can also be supplied. These global query options must precede the
a23fd118e437af0a7877dd313db8fdaa3537c675yl first tuple of name, class, type, options, flags, and query options
a23fd118e437af0a7877dd313db8fdaa3537c675yl supplied on the command line. Any global query options (except
a23fd118e437af0a7877dd313db8fdaa3537c675yl the <code class="option">+[no]cmd</code> option) can be
a23fd118e437af0a7877dd313db8fdaa3537c675yl overridden by a query-specific set of query options. For example:
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<pre class="programlisting">
a23fd118e437af0a7877dd313db8fdaa3537c675yldig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr
a23fd118e437af0a7877dd313db8fdaa3537c675yl</pre>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl shows how <span><strong class="command">dig</strong></span> could be used from the
a23fd118e437af0a7877dd313db8fdaa3537c675yl command line
a23fd118e437af0a7877dd313db8fdaa3537c675yl to make three lookups: an ANY query for <code class="literal">www.isc.org</code>, a
a23fd118e437af0a7877dd313db8fdaa3537c675yl reverse lookup of 127.0.0.1 and a query for the NS records of
a23fd118e437af0a7877dd313db8fdaa3537c675yl <code class="literal">isc.org</code>.
a23fd118e437af0a7877dd313db8fdaa3537c675yl
a23fd118e437af0a7877dd313db8fdaa3537c675yl A global query option of <em class="parameter"><code>+qr</code></em> is
a23fd118e437af0a7877dd313db8fdaa3537c675yl applied, so
a23fd118e437af0a7877dd313db8fdaa3537c675yl that <span><strong class="command">dig</strong></span> shows the initial query it made
a23fd118e437af0a7877dd313db8fdaa3537c675yl for each
a23fd118e437af0a7877dd313db8fdaa3537c675yl lookup. The final query has a local query option of
a23fd118e437af0a7877dd313db8fdaa3537c675yl <em class="parameter"><code>+noqr</code></em> which means that <span><strong class="command">dig</strong></span>
a23fd118e437af0a7877dd313db8fdaa3537c675yl will not print the initial query when it looks up the NS records for
a23fd118e437af0a7877dd313db8fdaa3537c675yl <code class="literal">isc.org</code>.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl</div>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<div class="refsect1" lang="en">
a23fd118e437af0a7877dd313db8fdaa3537c675yl<a name="id2662282"></a><h2>IDN SUPPORT</h2>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl If <span><strong class="command">dig</strong></span> has been built with IDN (internationalized
a23fd118e437af0a7877dd313db8fdaa3537c675yl domain name) support, it can accept and display non-ASCII domain names.
a23fd118e437af0a7877dd313db8fdaa3537c675yl <span><strong class="command">dig</strong></span> appropriately converts character encoding of
a23fd118e437af0a7877dd313db8fdaa3537c675yl domain name before sending a request to DNS server or displaying a
a23fd118e437af0a7877dd313db8fdaa3537c675yl reply from the server.
a23fd118e437af0a7877dd313db8fdaa3537c675yl If you'd like to turn off the IDN support for some reason, defines
a23fd118e437af0a7877dd313db8fdaa3537c675yl the <code class="envar">IDN_DISABLE</code> environment variable.
a23fd118e437af0a7877dd313db8fdaa3537c675yl The IDN support is disabled if the variable is set when
a23fd118e437af0a7877dd313db8fdaa3537c675yl <span><strong class="command">dig</strong></span> runs.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl</div>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<div class="refsect1" lang="en">
a23fd118e437af0a7877dd313db8fdaa3537c675yl<a name="id2662311"></a><h2>FILES</h2>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<p><code class="filename">/etc/resolv.conf</code>
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<p><code class="filename">${HOME}/.digrc</code>
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl</div>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<div class="refsect1" lang="en">
a23fd118e437af0a7877dd313db8fdaa3537c675yl<a name="id2662332"></a><h2>SEE ALSO</h2>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<p><span class="citerefentry"><span class="refentrytitle">host</span>(1)</span>,
a23fd118e437af0a7877dd313db8fdaa3537c675yl <span class="citerefentry"><span class="refentrytitle">named</span>(8)</span>,
8347601bcb0a439f6e50fc36b4039a73d08700e1yl <span class="citerefentry"><span class="refentrytitle">dnssec-keygen</span>(8)</span>,
a23fd118e437af0a7877dd313db8fdaa3537c675yl <em class="citetitle">RFC1035</em>.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl</div>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<div class="refsect1" lang="en">
a23fd118e437af0a7877dd313db8fdaa3537c675yl<a name="id2662370"></a><h2>BUGS</h2>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl There are probably too many query options.
a23fd118e437af0a7877dd313db8fdaa3537c675yl </p>
a23fd118e437af0a7877dd313db8fdaa3537c675yl</div>
a23fd118e437af0a7877dd313db8fdaa3537c675yl</div>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<div class="navfooter">
a23fd118e437af0a7877dd313db8fdaa3537c675yl<hr>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<table width="100%" summary="Navigation footer">
a23fd118e437af0a7877dd313db8fdaa3537c675yl<tr>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<td width="40%" align="left">
a23fd118e437af0a7877dd313db8fdaa3537c675yl<a accesskey="p" href="Bv9ARM.ch10.html">Prev</a>�</td>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<td width="20%" align="center"><a accesskey="u" href="Bv9ARM.ch10.html">Up</a></td>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<td width="40%" align="right">�<a accesskey="n" href="man.host.html">Next</a>
a23fd118e437af0a7877dd313db8fdaa3537c675yl</td>
a23fd118e437af0a7877dd313db8fdaa3537c675yl</tr>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<tr>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<td width="40%" align="left" valign="top">Manual pages�</td>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<td width="20%" align="center"><a accesskey="h" href="Bv9ARM.html">Home</a></td>
a23fd118e437af0a7877dd313db8fdaa3537c675yl<td width="40%" align="right" valign="top">�host</td>
a23fd118e437af0a7877dd313db8fdaa3537c675yl</tr>
a23fd118e437af0a7877dd313db8fdaa3537c675yl</table>
a23fd118e437af0a7877dd313db8fdaa3537c675yl</div>
a23fd118e437af0a7877dd313db8fdaa3537c675yl</body>
a23fd118e437af0a7877dd313db8fdaa3537c675yl</html>
a23fd118e437af0a7877dd313db8fdaa3537c675yl