Back to updates
New releaseJul 21, 2026

dnsdiag v2.9.4

DNS Measurement, Troubleshooting and Security Auditing Toolset

Share

PyPI PyPI Downloads Downloads PyPI Docker Pulls GitHub stars

DNS Measurement, Troubleshooting and Security Auditing Toolset

Have you ever wondered if your ISP is intercepting your DNS traffic)? Have you noticed any unusual behavior in your DNS responses, or been redirected to the wrong address and suspected something might be off with your DNS? We offer a suite of tools to perform basic audits on your DNS requests and responses, helping you ensure your DNS is functioning as expected.

With dnsping, you can measure the response time of any DNS server for arbitrary queries. Similar to the regular ping utility, dnsping offers comparable functionality for DNS requests, helping you monitor server responsiveness.

You can also trace the route of your DNS request to its destination using dnstraceroute, verifying that it isn't being redirected or intercepted. By comparing DNS queries sent to the same server, dnstraceroute allows you to observe any differences in the paths taken, alerting you to possible issues.

dnseval assesses multiple DNS resolvers to help you choose the best DNS resolver for your network. While using your own DNS resolver is recommended to avoid reliance on third-party DNS resolvers, dnseval can assist in selecting the optimal DNS resolver when needed. It lets you compare DNS servers based on performance (latency) and reliability (packet loss), giving you a comprehensive view for informed decision-making.

Installation

There are several ways to use this toolset, though we recommend running it directly from the source code for optimal flexibility and control.

Source Code

  1. Check out the git repository and install dependencies:
git clone https://github.com/farrokhi/dnsdiag.git
cd dnsdiag
pip3 install -r requirements.txt
  1. You can alternatively install the package using pip:
pip3 install dnsdiag

uv is a fast Python package manager that can run tools directly without installation:

# Run dnsping directly without installation
uvx --from dnsdiag dnsping google.com

# Run with specific options
uvx --from dnsdiag dnsping -c 5 --tls -s 8.8.8.8 example.com

# Run dnstraceroute
uvx --from dnsdiag dnstraceroute cloudflare.com

# Run dnseval
uvx --from dnsdiag dnseval -f public-servers.txt github.com

To install dnsdiag persistently:

# Install dnsdiag tools
uv tool install dnsdiag

# Upgrade to the latest version
uv tool upgrade dnsdiag

Binary Package

From time to time, binary packages will be released for Windows, Mac OS X and Linux. You can grab the latest release from releases page.

Supported Platforms

Pre-built binaries are available for:

  • Linux (x86_64, ARM64)
  • macOS (Intel, Apple Silicon)
  • Windows (x86_64)

Windows ARM64 is not currently supported due to build dependencies requiring native compilation toolchains that are not readily available. If you're using Windows on ARM, you can run dnsdiag using Windows Subsystem for Linux (WSL2) or install directly from source.

Docker

If you prefer not to install dnsdiag on your local machine, you can use the Docker image to run the tools in a containerized environment. For example:

docker run --network host -it --rm farrokhi/dnsdiag dnsping.py

dnsping

dnsping allows you to "ping" a DNS resolver by sending an arbitrary DNS query multiple times. For a full list of supported command-line options, use --help. Here are a few key flags:

  • Use --tcp, --tls, --doh, --quic or --http3 to select the transport protocol (default is UDP). These options are mutually exclusive; only one protocol can be specified per command.
  • Use --flags to display response flags, including EDNS flags, for each response.
  • Use --dnssec to request DNSSEC validation, if available.
  • Extended DNS Error messages (RFC 8914) are automatically displayed when present.
  • Use --nsid to display the Name Server Identifier (NSID) if available (RFC 5001).
  • Use --ecs to include EDNS Client Subnet information for geographic routing optimization.
  • Use --cookie to display DNS cookies (RFC 7873) when present in responses.
./dnsping.py -c 5 --dnssec --flags --tls -t AAAA -s 8.8.8.8 brokendnssec.net
dnsping.py DNS: 8.8.8.8:853, hostname: brokendnssec.net, proto: TLS, class: IN, type: AAAA, flags: [RD]
75  bytes from 8.8.8.8: seq=1   time=73.703 ms  SERVFAIL [QR RD RA -- DO] [EDE:10("For brokendnssec.net/soa")]
75  bytes from 8.8.8.8: seq=2   time=69.523 ms  SERVFAIL [QR RD RA -- DO] [EDE:10("For brokendnssec.net/soa")]
75  bytes from 8.8.8.8: seq=3   time=58.058 ms  SERVFAIL [QR RD RA -- DO] [EDE:10("For brokendnssec.net/soa")]
75  bytes from 8.8.8.8: seq=4   time=54.235 ms  SERVFAIL [QR RD RA -- DO] [EDE:10("For brokendnssec.net/soa")]
75  bytes from 8.8.8.8: seq=5   time=57.806 ms  SERVFAIL [QR RD RA -- DO] [EDE:10("For brokendnssec.net/soa")]

--- 8.8.8.8 dnsping statistics ---
5 requests transmitted, 5 responses received, 0% lost
min=54.235 ms, avg=22.665 ms, max=69.523 ms, stddev=38.202 ms

dnsping also provides statistics such as minimum, maximum, and average response times, along with jitter (standard deviation) and packet loss.

Here are a few interesting use cases for dnsping:

  • Comparing response times across different transport protocols (e.g., UDP vs. DoH).
  • Evaluating the reliability of your DNS server by measuring jitter and packet loss.
  • Measuring response times with DNSSEC enabled using the --dnssec flag.
  • Testing EDNS Client Subnet behavior for geolocation-aware responses:
./dnsping.py -c 3 --ecs 203.0.113.0/24 -s 94.140.14.14 google.com
dnsping.py DNS: 94.140.14.14:53, hostname: google.com, proto: UDP, class: IN, type: A, flags: [RD]
66  bytes from 94.140.14.14: seq=1   time=31.407 ms  NOERROR [ECS:203.0.113.0/24/24]
66  bytes from 94.140.14.14: seq=2   time=29.156 ms  NOERROR [ECS:203.0.113.0/24/24]
66  bytes from 94.140.14.14: seq=3   time=30.892 ms  NOERROR [ECS:203.0.113.0/24/24]

--- 94.140.14.14 dnsping statistics ---
3 requests transmitted, 3 responses received, 0% lost
min=29.156 ms, avg=30.485 ms, max=31.407 ms, stddev=1.176 ms
  • Identifying DNS servers using the NSID option:
./dnsping.py -c 2 --nsid -s 8.8.8.8 google.com
dnsping.py DNS: 8.8.8.8:53, hostname: google.com, proto: UDP, class: IN, type: A, flags: [RD]
68  bytes from 8.8.8.8: seq=1   time=36.399 ms  NOERROR [NSID:gpdns-ams]
68  bytes from 8.8.8.8: seq=2   time=32.156 ms  NOERROR [NSID:gpdns-ams]

--- 8.8.8.8 dnsping statistics ---
2 requests transmitted, 2 responses received, 0% lost
min=32.156 ms, avg=34.278 ms, max=36.399 ms, stddev=2.122 ms
  • Testing DNS cookies for enhanced security and cache optimization:
./dnsping.py -c 2 --cookie -s anyns.pch.net quad9.net

Categories