dig
CLI DNS lookup utility for authoritative and recursive inspection of mail-related records.
Overview
CLI DNS lookup utility for authoritative and recursive inspection of mail-related records.
Vendor: ISC / system utility
Primary purpose
Query DNS directly so you can verify SPF, DKIM, DMARC, MX, and PTR publications.
Best for
- Operators confirming what authoritative DNS actually serves
- Debugging propagation and record syntax issues
Common use cases
- Confirm SPF TXT at the organizational domain
- Check DKIM selector TXT before enabling signing
- Compare authoritative vs recursive answers after a change
Advantages
- Precise, scriptable, and available on most operator workstations
- No third-party trust boundary for the query itself
Limitations
- Does not interpret DMARC policy for you
- Easy to query the wrong resolver and misread cache
When not to use it
- You need a guided UI explanation of authentication results
- You are uncomfortable with a terminal
Pricing
Free with your OS or BIND tools package.
Official website
Inputs and outputs
Typical inputs
- Domain name
- Record type
- Optional @nameserver
Typical outputs
- Raw DNS answers
- Status codes
Privacy notes
- Review each vendor’s data handling before uploading production lists or message content.
Related learning
Related problems
- CNAME at zone apex
- HELO / EHLO problems
- Inconsistent authoritative answers
- Incorrect MX target
- Missing glue records
- MX record missing
- NXDOMAIN for expected name
- Reverse DNS mismatch
- Stale DNS cache after change
- Wrong TTL for cutover
- Broken SPF include
- Forwarded email fails SPF
- Incorrect IP authorization
- Invalid SPF mechanism
- Multiple SPF records
- SPF passes but DMARC fails
- SPF PermError
- SPF record missing
- SPF TempError
- Too many DNS lookups