isitdns? wiki/Tools/The isitdns dig tool
Tools

The isitdns dig tool

Run dig from your browser at isitdns.net/dig: pick a name, a record type and a resolver, then read the answer. Every answer also prints the dig command, so you can paste the same query into your own terminal.

run it right here; the full tool has every option

open in the full tool →

Asks a resolver to name the node that answered.

 dig @8.8.8.8 example.isitdns.net A +nsid
; <<>> DiG 9.20.11-0ubuntu0.2-Ubuntu <<>> @8.8.8.8 example.isitdns.net A +nsid
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status:
NOERRORThe server had no complaint about the question.
, id: 4595
;; flags:
qrThis message is the answer coming back, not the question going out.
rdYou asked this server to go and find the answer for you.
raThis server says it is willing to go and find answers for you.
adThis server says it checked the signatures, and they held up.
; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 512
; NSID: 67 70 64 6e 73 2d 61 74 6c ("gpdns-atl")
;; QUESTION SECTION:
;example.isitdns.net. IN
AYou asked for the IPv4 address this name points at.
;; ANSWER SECTION:
example.isitdns.net.
300How many seconds this answer can be reused before asking again. From a cache it is the time left, so it counts down.
IN A 192.0.2.1
;;
Query timeHow long this one lookup took, start to finish.
: 46 msec
;; SERVER: 8.8.8.8#53(8.8.8.8) (UDP)
;; WHEN: Mon Sep 14 17:42:31 CDT 2026
;; MSG SIZE rcvd: 77

GO NOERROR and an NSID line in the pseudosection

NO GO no NSID line: that resolver does not publish one

The controls#

ControlWhat it does
Namethe name to look up; . alone is the root
Typethe record type: the common ones and the DNSSEC ones (every type)
Resolverone public resolver; Tier 1 to compare Cloudflare, Google, Quad9 and AdGuard side by side; Custom for your own resolver's IP; Trace from root to walk the delegation
TransportDoH (RFC 8484), DoT (RFC 7858), or Do53 over TCP or UDP (RFC 1035 section 4.2)
Connect viaIPv4, IPv6 or both, for DoT and Do53
Flags+dnssec, +cd, +subnet, +norec, +nsid change the query; +short changes only the display (dig-flags)

Where the query runs from#

Not from your machine. DoH, DoT and TCP queries leave from Cloudflare's edge; UDP queries leave from the isitdns sink. Your own dig goes through your local path, where many routers and firewalls answer port 53 themselves. Run the same query both ways: if the answers differ, something on your path is changing your DNS (when-its-dns).

What it cannot do#

  • Cloudflare's resolvers over DoT or TCP. A Cloudflare Worker cannot open a TCP socket to a Cloudflare address: "Outbound TCP sockets to Cloudflare IP ranges are blocked" (Cloudflare TCP sockets docs). 1.1.1.1 works over DoH and UDP.
  • See your path. It shows what a clean path sees, not what your machine sees.
  • Retry. One query per run: 8 s for DoH, 3.5 s for DoT and TCP, 4 s for UDP, then the error shows.

See also#