Use nslookup to Check DNS Records and Name Servers
You will use nslookup to check ordinary host addresses, request a particular DNS record, query a chosen name server, and perform a reverse lookup. The examples use BIND 9.18.39 from Ubuntu package bind9-dnsutils. Allow about ten minutes if you already have a hostname to test. Everything here is read-only: no elevated privileges or DNS configuration changes are needed.
The route
Jump straight to the step you need, or tick off Done means at the end.
1. Check the installed command
First confirm that the shell will run the expected program. This is an ordinary command:
$ command -v nslookup
/usr/bin/nslookup
$ nslookup -version
nslookup 9.18.39-0ubuntu0.24.04.7-Ubuntu
$ dpkg-query -W -f='${Package} ${Version}\n' bind9-dnsutils
bind9-dnsutils 1:9.18.39-0ubuntu0.24.04.7
The resolver used for a normal lookup is selected from the system resolver configuration, normally through /etc/resolv.conf. On a system using systemd-resolved, that file may point at a local stub address such as 127.0.0.53. Seeing that address is not, by itself, a failed lookup.
2. Query a host with the system resolver
Give the hostname as the first argument for a non-interactive lookup:
$ nslookup example.com
A successful response includes the server used, followed by one or more Address: lines for the name. This version asks for both the default A and AAAA information when no alternative query type is selected, so an IPv4-only or IPv6-only result is also possible for a real domain.
Server: 127.0.0.53
Address: 127.0.0.53#53
Non-authoritative answer:
Name: example.com
Address: 172.66.147.243
Name: example.com
Address: 2606:4700:10::6814:179a
Addresses are live DNS data and can change. Treat the names and status labels as the useful part of this sample, not the particular IP values. Check the exit status when scripting:
$ nslookup example.com >/tmp/nslookup-output.txt
$ status=$?
$ printf 'nslookup exit status: %s\n' "$status"
nslookup exit status: 0
The installed manual documents exit status 0 when queries succeed and 1 when any query fails. The temporary file is optional and can be removed after inspection with rm -- /tmp/nslookup-output.txt; do not use a broad wildcard in a cleanup command.
3. Ask for one record type
Use -type= to stop the default A and AAAA behaviour and request one type. For example, inspect mail exchangers:
$ nslookup -type=mx example.com
Server: 127.0.0.53
Address: 127.0.0.53#53
Non-authoritative answer:
example.com mail exchanger = 0 .
The exact answer depends on the domain and can include several mail exchangers. Other useful values include a, aaaa, ns, txt and ptr. Use one query type at a time: the installed manual states that an alternative type replaces the default A-then-AAAA lookup rather than adding to it.
For a reverse lookup, request ptr and provide an IPv4 address:
$ nslookup -type=ptr 8.8.8.8
Server: 127.0.0.53
Address: 127.0.0.53#53
Non-authoritative answer:
8.8.8.8.in-addr.arpa name = dns.google.
A reverse result is controlled by the owner of the address block. It is not proof that the address belongs to a trustworthy service, and a missing PTR record is not proof that the address is unused.
4. Compare a different name server
The optional second argument selects the server for a non-interactive query. This lets you compare the local resolver with a server you are authorised to use:
$ nslookup -type=mx example.com 8.8.8.8
The first Server: block should identify the server you supplied. The query still asks that server for public DNS data; it does not make the server authoritative, and it does not bypass DNSSEC validation performed elsewhere in your resolver path.
Do not turn a troubleshooting check into a scan. Query names and servers that you have a legitimate reason to inspect, keep the request rate low, and follow the network owner's policy. No sudo is required for this command.
5. Use interactive mode for several related checks
Run nslookup with no arguments to enter interactive mode. The prompt is usually a greater-than sign:
$ nslookup
> server 8.8.8.8
Default server: 8.8.8.8
Address: 8.8.8.8#53
> set type=mx
> example.com
> set type=a
> example.com
> exit
server changes the current default server, while set type= changes the query type for later lookups. The output between the prompts is environment-dependent, so use the prompt sequence as the reproducible part. End the session with exit or an end-of-file character. Interactive settings disappear when that process exits; there is no configuration file to undo for this example.
6. Avoid search-list surprises
A name without a trailing dot can be qualified using the search list. That is convenient for local names but can produce a different query from the one you intended. An absolute DNS name ends with a dot:
$ nslookup host.example.com.
$ nslookup host.example.com
The first command explicitly asks for host.example.com.. The second may try names formed with the configured search list when the request contains a dot but does not end in a dot. If results look unexpected, compare the absolute form and inspect the resolver configuration:
$ sed -n '1,80p' /etc/resolv.conf
Reading that file is unprivileged. Do not edit it as part of this check: on many systems it is generated by a network manager, and a manual change can be overwritten or disrupt other programs. The interactive set nosearch option can disable this search behaviour for the current session; set search restores the documented default.
7. Diagnose timeouts and failures
Use the installed program's state display when an interactive result is confusing:
$ nslookup
> set all
> exit
This prints frequently used settings, including the current server and host. The defaults include port 53, recursive queries, search enabled, and an initial timeout measured in seconds. A slow or unreachable server can be tested with a modest, explicit timeout:
$ nslookup -timeout=3 example.com 192.0.2.1
;; connection timed out; no servers could be reached
192.0.2.1 is reserved for documentation and is expected not to answer. This example may take a moment and should return a non-zero status. Do not use it as a production resolver. For a real server, confirm the address first and avoid lowering timeouts so far that a busy but healthy resolver is misdiagnosed.
"Non-authoritative answer" is normal when the responding server is a recursive resolver rather than the DNS server responsible for the domain. It does not mean the answer is invalid. If no server can be reached, check network connectivity, the resolver address in /etc/resolv.conf, firewall policy, and whether UDP or TCP DNS traffic is permitted.
Done means
- You can run a normal lookup and identify the resolver that answered it.
- You can request a single record type such as MX or PTR and recognise that live answers change.
- You can compare a permitted name server without changing system configuration.
- You can use a trailing dot and the interactive search setting when a search list causes ambiguity.
- You check the exit status and investigate the resolver path before treating a timeout as a DNS record problem.