Tools
The isitdns dig tool
Run dig from your browser at isitdns.net/dig: pick a name, a record type and a resolver, then read the answer. Every answer also prints the dig command, so you can paste the same query into your own terminal.
Asks a resolver to name the node that answered.
dig @8.8.8.8 example.isitdns.net A +nsid; <<>> DiG 9.20.11-0ubuntu0.2-Ubuntu <<>> @8.8.8.8 example.isitdns.net A +nsid
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: , id: 4595
NOERRORThe server had no complaint about the question.
;; flags: ; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
qrThis message is the answer coming back, not the question going out.
rdYou asked this server to go and find the answer for you.
raThis server says it is willing to go and find answers for you.
adThis server says it checked the signatures, and they held up.
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 512
; NSID: 67 70 64 6e 73 2d 61 74 6c ("gpdns-atl")
;; QUESTION SECTION:
;example.isitdns.net. IN
AYou asked for the IPv4 address this name points at.
;; ANSWER SECTION:
example.isitdns.net. IN A 192.0.2.1
300How many seconds this answer can be reused before asking again. From a cache it is the time left, so it counts down.
;; : 46 msec
Query timeHow long this one lookup took, start to finish.
;; SERVER: 8.8.8.8#53(8.8.8.8) (UDP)
;; WHEN: Mon Sep 14 17:42:31 CDT 2026
;; MSG SIZE rcvd: 77
GO NOERROR and an NSID line in the pseudosection
NO GO no NSID line: that resolver does not publish one
The controls#
| Control | What it does |
|---|---|
| Name | the name to look up; . alone is the root |
| Type | the record type: the common ones and the DNSSEC ones (every type) |
| Resolver | one public resolver; Tier 1 to compare Cloudflare, Google, Quad9 and AdGuard side by side; Custom for your own resolver's IP; Trace from root to walk the delegation |
| Transport | DoH (RFC 8484), DoT (RFC 7858), or Do53 over TCP or UDP (RFC 1035 section 4.2) |
| Connect via | IPv4, IPv6 or both, for DoT and Do53 |
| Flags | +dnssec, +cd, +subnet, +norec, +nsid change the query; +short changes only the display (dig-flags) |
Where the query runs from#
Not from your machine. DoH, DoT and TCP queries leave from Cloudflare's edge; UDP queries leave from the isitdns sink. Your own dig goes through your local path, where many routers and firewalls answer port 53 themselves. Run the same query both ways: if the answers differ, something on your path is changing your DNS (when-its-dns).
What it cannot do#
- Cloudflare's resolvers over DoT or TCP. A Cloudflare Worker cannot open a TCP socket to a Cloudflare address: "Outbound TCP sockets to Cloudflare IP ranges are blocked" (Cloudflare TCP sockets docs). 1.1.1.1 works over DoH and UDP.
- See your path. It shows what a clean path sees, not what your machine sees.
- Retry. One query per run: 8 s for DoH, 3.5 s for DoT and TCP, 4 s for UDP, then the error shows.
See also#
- dig-examples: guided queries to try
- dig-flags: what every flag does
- servfail: when the answer is
SERVFAIL - connection-timed-out: when nothing comes back
- when-its-dns: when the tool and your terminal disagree