The essentials
Quick reference
One focused task per row. Jump to the related section for complete, working examples.
| Use | Syntax | Examples |
|---|---|---|
| Resolve through NSS | getent ahosts example.com | View examples |
| Inspect hosts lookup order | grep -E '^[[:space:]]*hosts:' /etc/nsswitch.conf | View examples |
| Identify resolv.conf owner | readlink -f /etc/resolv.conf | View examples |
| Show resolver directives | grep -E \
'^[[:space:]]*(nameserver|search|domain|options)[[:space:]]' \
/etc/resolv.conf | View examples |
| Query an A record | dig example.com A +noall +answer | View examples |
| Query an AAAA record | dig example.com AAAA +noall +answer | View examples |
| Query one DNS server | dig @192.0.2.53 example.com A +noall +answer +comments | View examples |
| Run a reverse lookup | dig -x 192.0.2.25 +noall +answer | View examples |
| Retry DNS over TCP | dig +tcp @192.0.2.53 example.com A | View examples |
| Trace delegation | dig +trace www.example.com | View examples |
| Show effective DNS policy | resolvectl status | View examples |
| Query through systemd-resolved | resolvectl query example.com | View examples |
| Inspect resolver statistics | resolvectl statistics | View examples |
| Bypass the local cache | resolvectl --cache=no query example.com | View examples |
| Flush resolved caches | sudo resolvectl flush-caches | View examples |
| Request DNSSEC records | dig example.com A +dnssec +multi | View examples |
| Show per-link domains | resolvectl domain | View examples |
| Set transient split DNS | sudo resolvectl domain tun0 '~corp.example' | View examples |
| Set a per-link DNS server | sudo resolvectl dns tun0 192.0.2.53 | View examples |
| Revert transient link DNS | sudo resolvectl revert tun0 | View examples |
Linux name resolution is a pipeline rather than one command. Applications commonly use the C library and Name Service Switch, which may consult files, systemd-resolved, DNS, or another source; dig queries DNS independently. Start with the same lookup path as the failing application, then inspect resolver policy and query a known server only when you need to isolate a layer. Commands that alter per-link DNS or flush caches need privilege and can interrupt production resolution, so capture the current state first.
Step by step
Detailed examples
Test the application's resolution path first
getent ahosts calls the NSS-backed address lookup path used by many dynamically linked applications. That path can honor /etc/hosts and modules such as myhostname, resolve, or dns in the order and with the actions configured on the hosts line in /etc/nsswitch.conf. A successful dig query alongside a failed getent query therefore points toward NSS, a local resolver service, search policy, or application-specific behavior rather than authoritative DNS. NSS details are libc- and distribution-dependent: musl, containers, statically linked binaries, browsers, and language runtimes may use a different path.
getent ahosts example.com
grep -E '^[[:space:]]*hosts:' /etc/nsswitch.conf 93.184.216.34 STREAM example.com
93.184.216.34 DGRAM
93.184.216.34 RAW
hosts: files systemd dnsDetermine who manages resolver configuration
/etc/resolv.conf is an interface consumed by the libc stub resolver and DNS tools, but NetworkManager, systemd-resolved, resolvconf, a DHCP client, or an administrator may own its contents. Inspect the symlink target before editing it. On systemd-resolved hosts, 127.0.0.53 commonly identifies the local stub, while a generated file under /run may expose upstream servers. Search suffixes can expand single-label names and ndots can change query order, latency, and information exposure. Direct edits to a generated file are usually overwritten; persistent configuration belongs in the active network manager.
readlink -f /etc/resolv.conf
grep -E '^[[:space:]]*(nameserver|search|domain|options)[[:space:]]' /etc/resolv.conf /run/systemd/resolve/stub-resolv.conf
nameserver 127.0.0.53
options edns0 trust-ad
search corp.exampleAsk focused DNS record questions with dig
dig talks DNS and does not reproduce the full NSS application path. Specify the record type and use documentation addresses for examples. An @server argument isolates one server, but that server name is resolved before the query if it is not already an IP address. Compare response status, flags, authority, and the responding SERVER line rather than relying only on +short output. NXDOMAIN means the queried name does not exist, while NOERROR with an empty answer can mean the name exists but lacks that record type. Reverse DNS is a PTR query and does not establish forward ownership or trust.
dig example.com A +noall +answer
dig example.com AAAA +noall +answer
dig @192.0.2.53 example.com A +noall +answer +comments
dig -x 192.0.2.25 +noall +answer example.com. 300 IN A 93.184.216.34
example.com. 300 IN AAAA 2001:db8::34
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 24001
example.com. 300 IN A 93.184.216.34
25.2.0.192.in-addr.arpa. 300 IN PTR host.example.Separate delegation problems from transport failures
A normal recursive query hides the delegation walk. dig +trace starts at a root server and follows referrals, making it useful for parent-zone NS and glue mistakes, but it sends queries to multiple Internet authorities and can fail on networks that block direct DNS. DNS ordinarily starts over UDP and retries over TCP when a response is truncated; testing +tcp can reveal firewalls that permit UDP 53 but block TCP 53. Both commands generate network traffic and should be approved before use on restricted production networks.
dig +trace www.example.com
dig +tcp @192.0.2.53 example.com A . 518400 IN NS a.root-servers.net.
com. 172800 IN NS a.gtld-servers.net.
example.com. 86400 IN NS ns1.example.net.
;; SERVER: 192.0.2.53#53(192.0.2.53) (TCP)Inspect systemd-resolved's effective decision
When systemd-resolved is active, resolvectl status shows global and per-link settings that a stub resolv.conf cannot express. resolvectl query reports the selected interface, protocol, and whether the answer was authenticated. Authenticated can also describe trusted local data such as /etc/hosts, so interpret it with the reported source. resolvectl commands and fields are versioned systemd features and may be absent on older releases or systems using another resolver. A container may also see a different resolver service and namespace than its host.
resolvectl status
resolvectl query example.com Global
Protocols: -LLMNR -mDNS +DNSOverTLS DNSSEC=yes/supported
Link 3 (tun0)
DNS Servers: 192.0.2.53
DNS Domain: ~corp.example
example.com: 93.184.216.34 -- link: eth0
-- Information acquired via protocol DNS in 24.8ms.
-- Data is authenticated: yesTreat caching and DNSSEC as separate diagnostic dimensions
TTL-valid cache entries are expected and can make repeated tests differ from upstream state. Prefer a one-query cache bypass when supported; flushing the whole cache requires privilege, affects every local client, and temporarily increases upstream traffic. dig +dnssec requests DNSSEC records by setting the DO bit, but the presence of RRSIG data or an AD flag received from a recursive resolver is not the same as independently validating the chain. With systemd-resolved, use query authentication state and statistics together with configured DNSSEC mode. Private split-horizon zones may need correct signing or a narrowly scoped negative trust anchor; weakening validation globally hides genuine failures.
resolvectl statistics
resolvectl --cache=no query example.com
dig example.com A +dnssec +multi
sudo resolvectl flush-caches Transactions
Current Transactions: 0
Cache
Current Cache Size: 42
DNSSEC Verdicts
Secure: 318
example.com: 93.184.216.34 -- link: eth0
;; flags: qr rd ra ad; QUERY: 1, ANSWER: 2Route private suffixes without hijacking all DNS
systemd-resolved route-only domains begin with a tilde. Assigning ~corp.example and the corporate DNS server to a VPN link sends matching names there without appending the suffix to single-label queries. The special ~. domain makes a link preferred for all otherwise unmatched DNS traffic and should be used deliberately. resolvectl dns and domain changes are transient, privileged, and can immediately break resolution if the interface or server is wrong. Record resolvectl status before changing anything, keep an existing privileged session available, and use revert to remove all transient resolver properties for that link. For persistence, configure NetworkManager, systemd-networkd, or the actual link manager instead.
resolvectl domain
sudo resolvectl dns tun0 192.0.2.53
sudo resolvectl domain tun0 '~corp.example'
resolvectl query host.corp.example
sudo resolvectl revert tun0 Global:
Link 3 (tun0): ~corp.example
host.corp.example: 192.0.2.80 -- link: tun0
-- Information acquired via protocol DNS in 18.1ms.Sources and further reading
References
Authoritative documentation used to verify and expand this cheat sheet.
- systemd projectresolvectl — Resolver Inspection and Configurationfreedesktop.org
- systemd projectresolved.conf — Network Name Resolution Configurationfreedesktop.org
- Internet Systems Consortiumdig — DNS Lookup Utilitybind9.readthedocs.io
- Linux man-pages projectresolv.conf(5) — Resolver Configuration Fileman7.org
- Linux man-pages projectnsswitch.conf(5) — Name Service Switch Configurationman7.org
- Linux man-pages projectgetent(1) — Query Name Service Switch Databasesman7.org
Help us improve
Found a typo or missing example?
Tell us what would make this cheat sheet clearer, more complete, or more useful.



