mdig fires several DNS questions at one name server without waiting for each answer to come back. This guide covers single lookups, batch files and reverse lookups with it, using BIND 9.18.39 from Ubuntu package bind9-dnsutils 1:9.18.39-0ubuntu0.24.04.7, installed on this machine.
Allow about fifteen minutes. You need a shell, the bind9-dnsutils package, and a reachable DNS server. The examples use Cloudflare's resolver at 1.1.1.1; substitute a resolver you are authorised to query if that is unsuitable. These commands only send DNS queries: they do not change local resolver configuration or server data, and need no elevated privileges.
Confirm which executable will run and record its version:
$ command -v mdig
/usr/bin/mdig
$ mdig -v
mDiG 9.18.39-0ubuntu0.24.04.7-Ubuntu
$ dpkg-query -W -f='${Package} ${Version}\n' bind9-dnsutils
bind9-dnsutils 1:9.18.39-0ubuntu0.24.04.7
mdig is a multiple-query version of dig. Unlike dig, it does not take the resolver from /etc/resolv.conf: @server is required. The server can be an IPv4 address, IPv6 address or hostname, and a hostname is resolved before it is used as the DNS server.
Checkpoint: if command -v finds nothing, install or enable the package through your normal system-management process. Do not use sudo just to run a lookup.
Put global options before the query name. +short keeps the answer readable, while -t A is a local option for this query:
$ mdig @1.1.1.1 +short example.com -t A
172.66.147.243
104.20.23.154
The addresses can change; what you are checking is that the command exits successfully and prints one or more IPv4 addresses, not these exact values. Check the exit status when scripting:
$ printf 'exit status: %s\n' "$?"
exit status: 0
The default query class is IN and the default type is A. Ask for -t AAAA when you want IPv6 addresses. Local options apply to the next query on the command line, so keep each query's type beside its name.
For ordinary command-line work, place several query names after the server. mdig sends the requests without waiting for each response, and prints responses in arrival order, which may differ from the order you wrote:
$ mdig @1.1.1.1 +short example.com A example.com AAAA
172.66.147.243
104.20.23.154
2606:4700:3030::6815:189a
2606:4700:3033::ac43:93f4
Do not use the output order to match answers to requests in a script. For unambiguous machine processing, run one query per invocation, or keep enough of the normal output to identify each question and parse it with a DNS-aware tool. The short form is convenient for a quick check, but it strips out that context.
Global options have a positional trap: they must come before the query name. This is wrong:
$ mdig @1.1.1.1 example.com +short
Ignored late global option: +short
Use mdig @1.1.1.1 +short example.com instead. The warning is easy to miss in a longer pipeline, and the output then falls back to the verbose format.
Create a plain-text file with one query per line. This only changes a temporary file in your current directory, so no elevated privilege is needed:
$ batch_file=$(mktemp)
$ printf '%s\n' 'example.com A' 'example.com AAAA' > "$batch_file"
$ mdig @1.1.1.1 +short -f "$batch_file"
172.66.147.243
104.20.23.154
2606:4700:3030::6815:189a
2606:4700:3033::ac43:93f4
$ rm -- "$batch_file"
Batch entries use the same query shape as the command line. -f reads the file and sends its requests in a pipeline. Keep the file under your control: it decides which names you ask a server to resolve, and a large or repeated list can create unnecessary traffic.
Use a normal file name when you need to keep the input for review:
$ mdig @1.1.1.1 +short -f dns-queries.txt
There is no undo for a lookup. If the file contains a mistake, edit or remove it before the next run. The command never modifies the DNS records it reads.
Use -x to map an address back to a name. mdig builds the appropriate reverse-DNS name and switches the query type to PTR:
$ mdig @1.1.1.1 +short -x 1.1.1.1
one.one.one.one.
IPv6 addresses are converted to the nibble format under ip6.arpa automatically. A missing answer is not necessarily a command failure: many addresses have no PTR record, and a PTR record is controlled by the address owner.
DNS queries use UDP by default. To test a resolver over TCP, make +tcp a global option before the query:
$ mdig @1.1.1.1 +tcp +short example.com
172.66.147.243
104.20.23.154
Use -4 or -6 to test transport through one address family. Use -p PORT only for a DNS service deliberately listening on a non-standard port; it will not make an ordinary resolver listen there.
For diagnosis, drop +short and read the status, flags and sections in the full response:
$ mdig @1.1.1.1 example.com A
;; Got answer:
;; ->HEADER<- opcode: QUERY, status: NOERROR, id: ...
;; flags: qr rd ra; QUERY: 1, ANSWER: ...
The identifier and answer count vary. NOERROR means the server completed the DNS request, not that the name has an answer; NXDOMAIN means the server reports that the name does not exist. A timeout or connection error means the selected server could not be queried from this host: try a permitted resolver, check routing and firewall policy, and do not infer that the DNS record is absent.
mdig -v identifies the installed BIND version you are relying on.@server.