Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

DNS tool to find out how the dns queries are being resolved ?

Posted on 2012-08-29
4
Medium Priority
?
394 Views
Last Modified: 2012-12-29
Hi
Do anyone know of any tool which can give insight into dns queries being resolved ?
nslookup will give me the end result but now the recursive process or the other servers involved. what i want to see is all the server involved in the query including forwarders etc.
0
Comment
Question by:s_inderjit
4 Comments
 
LVL 7

Expert Comment

by:unfragmented
ID: 38348596
If you have an internal DNS server, run a packet capture (wireshark is free and awesome!) and filter out everything except DNS traffic.  This should show you all DNS transactions that occur over the network.
0
 
LVL 5

Expert Comment

by:dallensworth
ID: 38349972
You could use host command on a bsd or mac.  There are ports of the host command out there for windows OS.    Output is something like follows:  

Dans-MacBook-Air:~ admin$ host -a google.com
Trying "google.com"
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 36688
;; flags: qr rd ra; QUERY: 1, ANSWER: 21, AUTHORITY: 0, ADDITIONAL: 2

;; QUESTION SECTION:
;google.com.                  IN      ANY

;; ANSWER SECTION:
google.com.            77      IN      A      74.125.225.69
google.com.            77      IN      A      74.125.225.78
google.com.            77      IN      A      74.125.225.73
google.com.            77      IN      A      74.125.225.70
google.com.            77      IN      A      74.125.225.64
google.com.            77      IN      A      74.125.225.71
google.com.            77      IN      A      74.125.225.67
google.com.            77      IN      A      74.125.225.65
google.com.            77      IN      A      74.125.225.72
google.com.            77      IN      A      74.125.225.68
google.com.            77      IN      A      74.125.225.66
google.com.            5966      IN      NS      ns2.google.com.
google.com.            5966      IN      NS      ns3.google.com.
google.com.            5966      IN      NS      ns1.google.com.
google.com.            5966      IN      NS      ns4.google.com.
google.com.            88      IN      MX      50 alt4.aspmx.l.google.com.
google.com.            88      IN      MX      10 aspmx.l.google.com.
google.com.            88      IN      MX      20 alt1.aspmx.l.google.com.
google.com.            88      IN      MX      40 alt3.aspmx.l.google.com.
google.com.            88      IN      MX      30 alt2.aspmx.l.google.com.
google.com.            2686      IN      TXT      "v=spf1 include:_netblocks.google.com ip4:216.73.93.70/31 ip4:216.73.93.72/31 ~all"

;; ADDITIONAL SECTION:
ns2.google.com.            6336      IN      A      216.239.34.10
ns3.google.com.            6337      IN      A      216.239.36.10

Received 510 bytes from 10.100.2.88#53 in 100 ms
0
 

Author Comment

by:s_inderjit
ID: 38352580
thanks Unfragmented. I understand that i can capture traffic and filter dns traffic but i beleive their must be tool that can show you the dns traffic like tracert for network connectivity,
0
 
LVL 57

Accepted Solution

by:
giltjr earned 400 total points
ID: 38354366
How about turning on debug  or debug2 in nslookup?

nslookup
set d2
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This program is used to assist in finding and resolving common problems with wireless connections.
This applies to Dell but may also apply to other manufacturers as well. We ran across a few machines that just dropped recently it trust relationship with the server. After doing the basic removing and joining the domain again, it changed to No logo…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

564 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question