Use host to Test DNS Answers Without Guessing
You will finish with a small set of repeatable DNS checks: resolve a name, perform a reverse lookup, ask for a particular record type, and compare answers from a chosen name server. The examples use BIND 9 host version 9.18.39-0ubuntu0.24.04.7-Ubuntu, provided here by bind9-host.
The route
Jump straight to the step you need, or tick off Done means at the end.
Allow about ten minutes. You need a shell and network access for public DNS examples. The commands are read-only. They do not edit DNS, restart a resolver or require elevated privileges. Your answer may differ from the examples because DNS is distributed and answers can change.
1. Check the installed command
Confirm which program is in your path and record its version:
$ command -v host
/usr/bin/host
$ host -V
host 9.18.39-0ubuntu0.24.04.7-Ubuntu
The local manpage is the contract for this installed build. If host is missing, install the distribution package that provides bind9-host using your normal package-management process. That is an administrative change, so do not add installation commands to a troubleshooting script unless the machine's change policy allows it.
Checkpoint: stop here if the version or path is not the one you intended to test. A shell alias, container image or different package can make two commands named host behave differently.
2. Resolve a name with the configured resolver
With just a name, host queries the name servers listed in /etc/resolv.conf:
$ host example.com
example.com has address 172.66.147.243
example.com has address 104.20.23.154
The addresses above are an example of the output shape, not a promise about today's answer. A successful lookup can return several A or AAAA records, and a DNS provider may change them. For a local check whose answer is stable on most Linux hosts, use:
$ host localhost
localhost has address 127.0.0.1
localhost has IPv6 address ::1
If the command says the name was not found, check the spelling first. If it times out, compare the resolver and network path before treating the result as evidence that the domain is absent.
3. Ask for one record type
Use -t when the question is specific. This avoids mistaking the command's default selection for a complete inventory:
$ host -t MX example.com
example.com mail is handled by 0 .
$ host -t NS example.com
example.com name server hera.ns.cloudflare.com.
example.com name server elliott.ns.cloudflare.com.
The installed command automatically looks for A, AAAA and MX records when no type is supplied. It can query recognised types such as CNAME, NS, SOA, TXT and DNSKEY. Use the exact type you need, then read the result as a DNS answer rather than as proof that every other type exists.
For an authoritative-zone health check, -C asks for SOA records from all listed authoritative servers. This sends more queries than an ordinary lookup and is best reserved for a domain you administer or have permission to inspect:
$ host -C example.com
Nameserver 172.64.35.228:
example.com has SOA record elliott.ns.cloudflare.com. dns.cloudflare.com. 2415729022 10000 2400 604800 1800
Nameserver 108.162.192.162:
example.com has SOA record elliott.ns.cloudflare.com. dns.cloudflare.com. 2415729022 10000 2400 604800 1800
The exact response depends on the zone. A refusal or timeout is a result to investigate, not a reason to retry indefinitely.
4. Reverse-resolve an address
Pass an IPv4 or IPv6 address as the name. host selects a PTR query automatically:
$ host 127.0.0.1
1.0.0.127.in-addr.arpa domain name pointer localhost.
$ host ::1
1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.ip6.arpa domain name pointer ip6-localhost.
1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.ip6.arpa domain name pointer ip6-loopback.
Reverse DNS is separate data from forward DNS. A forward lookup can succeed while the reverse lookup has no PTR record, and a PTR name is not proof that the address is trustworthy. For logs or access controls, treat it as a name to verify, not as authentication.
5. Compare a particular name server
Add a server name or address as the final argument when you need to remove the configured resolver from the comparison:
$ host -W 2 -t A example.com 1.1.1.1
Using domain server:
Name: 1.1.1.1
Address: 1.1.1.1#53
Aliases:
example.com has address 172.66.147.243
example.com has address 104.20.23.154
The final argument is a DNS server, not a destination web server. The normal DNS port is 53. Use -p only when your DNS service deliberately listens elsewhere, and verify that the network path permits the selected transport.
Use -W for a bounded wait. This example waits up to two seconds for a reply. The documented defaults are five seconds for UDP and ten seconds for TCP, with possible overrides from /etc/resolv.conf. Avoid -w in automation unless waiting forever is genuinely safe.
Checkpoint: run the same type query through both the configured resolver and the explicit server. Different answers can be caused by caching, split DNS, propagation or filtering. They are a prompt for further investigation, not immediate evidence that one server is broken.
6. Inspect resolver configuration before changing it
Read the two resolver files separately. Ordinary users can inspect them; editing them normally requires elevated privileges and may disrupt every program using DNS:
$ sed -n '1,120p' /etc/resolv.conf
$ sed -n '1,120p' /etc/host.conf
/etc/resolv.conf supplies name servers, search or domain settings, and options such as ndots, timeout and attempts. Those settings explain why a short name may be expanded or why a lookup waits longer than expected. host.conf is different: it configures parts of the glibc resolver library, not the DNS records themselves.
The supported host.conf directives in this manpage are multi, reorder and trim. For example, multi on makes the resolver library return all valid addresses for a host found in /etc/hosts, instead of only the first. It is off by default because large hosts files can make this slower. reorder on attempts to put local addresses first. trim removes configured local suffixes from DNS-derived hostnames.
Do not expect host.conf to control the order of all host lookups. The manpage identifies nsswitch.conf as the modern control for lookup order. Also note that host is a DNS lookup utility, while getent hosts NAME exercises the system's name-service configuration and is a better comparison when investigating /etc/hosts behaviour.
$ getent hosts localhost
::1 localhost ip6-localhost ip6-loopback
Environment variables can override parts of host.conf for a process. In particular, RESOLV_HOST_CONF selects another configuration file, while RESOLV_MULTI, RESOLV_REORDER and the trim-related variables adjust specific settings. Check the environment before blaming a file you have just read:
$ env | grep '^RESOLV_' || true
Do not export these variables globally as a quick fix. A wrapper, service unit or shell profile can make the behaviour hard to reproduce. If you must test an override, put it on one command line and record it with the result.
7. Use diagnostic options carefully
-r clears the recursion-desired flag. It is useful when testing an authoritative or forwarding server, but a recursive resolver may return a referral or no useful answer. -T forces TCP; ordinary queries use UDP, while queries that require TCP, such as zone transfers, select it automatically. -4 and -6 constrain the query transport to IPv4 or IPv6.
-v or -d prints debugging traces. The output is verbose and can include configuration details, so keep it out of routine logs if those logs are shared. The -l option requests a zone transfer and is not a harmless way to list a domain. Use it only with authorisation; a zone may refuse it, and a permitted transfer can reveal internal names.
Done means
- You confirmed the installed
hostversion and binary path. - You can distinguish forward, reverse and record-specific queries.
- You can compare the configured resolver with an explicit DNS server using a finite timeout.
- You inspected
/etc/resolv.confand/etc/host.confwithout changing them. - You know that a DNS answer is data to verify, not authentication, and that zone transfers require permission.