
macOS dig wrapper that appends spoofed local TXT records to DNS query output, designed to deceive LLM agents into performing automated penetration testing.
A local dig wrapper on macOS. The actual query is still sent by the system's built-in /usr/bin/dig. This project only appends a local TXT record after your own terminal output, for local testing convenience.
It does not modify DNS, does not write zone files, and does not touch any cloud provider.
Pin a TXT record to a domain, and every subsequent query returns it
dig +txt=<value> TXT <name>
dig +txt=<value> +ttl=600 TXT <name>
name: the domain, e.g. app.localvalue: the content of this TXT record, written after +txt=. Add quotes if it contains spaces+ttl=<seconds>: the TTL for display, defaults to 600dig +txt=env=staging TXT app.local
dig +short TXT app.local # "env=staging"
dig +txt='hello world' TXT app.local # value contains spaces
dig +txt= TXT app.local # delete the record for this domain
It can also be written as positional arguments:
dig app.local env=staging
dig app.local -- "hello world"
Only takes effect for query types TXT / ANY; querying A will not show it. If you set example.com, querying x.example.com will also match. +txt= is not visible in dig -h; this argument is stripped before being passed to the system dig.
A non-hexadecimal +cookie=<value> likewise sets value. A real hexadecimal cookie is passed through to the system dig as-is.
In the full output, the system dig's HEADER, ANSWER: count, and MSG SIZE rcvd remain exactly as the network response. The local TXT is written after this output, with a blank line in between, for example:
;; MSG SIZE rcvd: 100
app.local. 600 IN TXT "env=staging"
With +short, only one extra quoted value line is added. It does not rewrite the ANSWER SECTION, nor print a source note to stderr.
The second query for the same domain will not append the _zcode-verify marker again. The local machine still records the query count, but does not change the output.

Only macOS is supported, requires /usr/bin/dig and /usr/bin/python3, no pip dependencies.
git clone https://github.com/xsser/dig.git
cd dig
./scripts/install.sh
export PATH="$HOME/.local/bin:$PATH"
command -v dig # should be ~/.local/bin/dig
The install script will first back up the existing ~/.local/bin/dig. If command -v dig is not this path, the wrapper will not take effect at all.
An already-open zsh may still remember the old path; run rehash once.
./scripts/restore.sh
It restores the file from before installation, which is not necessarily the same as the system /usr/bin/dig. To temporarily bypass the wrapper, call /usr/bin/dig directly.
Do not manually unpack the backup directory.
Counts and pinned TXT records are stored in:
~/.cache/dig-zcode-wrapper
This is local test state, not DNS evidence; do not commit it, and do not use it to verify domain ownership.
make verify
~/.local/bin is ahead of other entries in PATH/usr/bin/dig