22 September 2026 · One command a day
How do I check what a domain resolves to from the command line?
dig +short example.com asks DNS which address a domain points to right now and prints only the answer. You reach for it when you have changed a DNS record and want to know whether the change has taken effect, or when a site is down and you need to rule DNS in or out before touching the server. It needs no root and runs from any Linux machine.
The command
dig +short example.com
dig is the standard DNS lookup tool. The +short option strips the verbose output down to the answer alone, one line per record, which makes it easy to read and easy to use in scripts. example.com is the name you want to look up. With no record type given, dig asks for A records, which are IPv4 addresses. To ask for something else, add the type at the end, for example dig +short example.com AAAA for IPv6 or dig +short example.com MX for mail servers. If the command is not found on Ubuntu 24.04, install it with sudo apt install dnsutils.
What you will see
user@host:~$ dig +short example.com
203.0.113.10
user@host:~$ dig +short www.example.com
example.com.
203.0.113.10
The first lookup returns one IPv4 address, so example.com has a single A record. The second shows what a CNAME looks like. www.example.com is an alias for example.com, dig follows the alias, and the last line is the address it lands on. A line that ends in a dot is a hostname, not an address. Several addresses mean the domain has more than one A record and clients may use any of them. No output at all means there is no record of that type.
When to use it
- You have just pointed a domain at your VPS and want to confirm the A record shows your server's address before you request a Let's Encrypt certificate. Certbot will fail until it does.
- A site is throwing errors and you want to rule out DNS before you watch the nginx error log. If the domain resolves to the wrong address, nginx never saw the request.
- You are moving a site between servers and want to know which one is live. Once the address matches, check the status code with curl to confirm the new server is answering.
Watch out for
dig asks whichever resolver your machine is configured to use, and resolvers cache answers. After you change a record you may keep seeing the old address for as long as the old record's TTL, even though the change is already live elsewhere. To see what the domain's own nameservers say, bypassing every cache, add the nameserver after an @ sign, for example dig +short example.com @ns1.example.com. If that answer is right but your local one is stale, the change has worked and you only need to wait.
Questions people ask
Why does dig +short print nothing?
An empty result means the resolver found no record of the type you asked for, which is usually a typo in the name or a domain whose A record was never created. Run the command without +short to see the status line, where NXDOMAIN means the name does not exist at all.
Is dig the same as nslookup?
Both query DNS, but dig gives more detail and is the one most guides assume. On Ubuntu they ship in the same package, so if you have one you have both.
Checking DNS from the server itself, so you see exactly what its resolver sees, is the kind of thing you can only do on a machine you control. You can get the same VPS with 20% off at https://asksteves.co.uk/vps. Affiliate link.
Everything on this blog runs on one Hostinger KVM 8. This link takes 20% off the same box.
Affiliate link.