Linux下DNS工作原理、命令及调试,浏览器URL请求流程与故障排查
Alright, let's break this down step by step—DNS is the backbone of how we navigate the web, and understanding its inner workings plus the Linux tools to debug it is essential for any sysadmin or developer. Let's dive in.
At its core, DNS (Domain Name System) translates human-readable domain names (like google.com) into machine-readable IP addresses (like 8.8.8.8). Here's how the process plays out on a Linux system:
- Local Cache Check: When you try to resolve a domain, Linux first checks its local DNS cache (managed by services like
systemd-resolvedornscd) to see if the IP is already stored. - Recursive Query to Local DNS Server: If the cache misses, your system sends a query to the DNS servers configured in
/etc/resolv.conf(usually your ISP's DNS or a public one like 8.8.8.8). - Iterative Resolution by Local DNS: If the local DNS server doesn't have the answer, it starts an iterative lookup:
- First, it queries a root domain server (there are 13 global root servers) to find the authoritative server for the top-level domain (TLD) like
.com. - Then it queries the TLD server to get the authoritative server for the specific domain (e.g.,
google.com). - Finally, it queries the authoritative server to get the IP address of the domain.
- First, it queries a root domain server (there are 13 global root servers) to find the authoritative server for the top-level domain (TLD) like
- Result Caching and Return: The local DNS server caches the result for future queries, then sends the IP back to your Linux system, which also caches it locally.
These are the commands you'll reach for daily to interact with DNS on Linux:
nslookup: A classic tool for basic DNS queries.- Example:
nslookup google.com(returns the IP of google.com) - Specify a DNS server:
nslookup google.com 8.8.8.8(uses Google's DNS instead of your default)
- Example:
dig: More powerful thannslookup, with detailed output.- Basic query:
dig google.com - Trace the full resolution path:
dig +trace google.com(shows every step from root to authoritative server) - Reverse DNS lookup:
dig -x 8.8.8.8(finds the domain associated with an IP)
- Basic query:
host: A simple tool for quick lookups.- Example:
host google.com(returns IPs) - Reverse lookup:
host 8.8.8.8
- Example:
resolvectl: For systems usingsystemd-resolved(most modern distros).- Check current DNS configuration:
resolvectl status - Query a domain:
resolvectl query google.com - Flush DNS cache:
resolvectl flush-caches
- Check current DNS configuration:
/etc/resolv.conf: The configuration file that tells Linux which DNS servers to use. Key fields:nameserver: The IP address of a DNS server (you can have multiple)search: Append these domains to short names (e.g.,search mycompany.commakesserverresolve toserver.mycompany.com)options: Settings liketimeout:2(wait 2 seconds for a response) orrotate(cycle through DNS servers)
When you need to dig deeper into DNS issues, these techniques will help:
- Trace the resolution path: Use
dig +trace <domain>to see exactly where the lookup fails (e.g., if root servers don't respond, or the authoritative server is down). - Inspect DNS traffic: Use
tcpdumpto capture DNS packets and analyze them:- Capture all DNS traffic:
tcpdump port 53 - Capture UDP DNS traffic on any interface:
tcpdump -i any udp port 53
- Capture all DNS traffic:
- Check DNS service status: If using
systemd-resolved, runsystemctl status systemd-resolvedto ensure it's running. For older systems withbind, usesystemctl status named. - Test DNS server responsiveness: Use
dig @<DNS-server-IP> <domain>to test if a specific DNS server is working (e.g.,dig @8.8.8.8 google.com).
When you type a URL like https://www.google.com into your browser, here's the full sequence of events:
- Browser Cache Check: The browser first checks its own cache to see if it has the IP for
www.google.com. - System DNS Cache Check: If the browser cache misses, it queries the system's DNS cache (managed by Linux's DNS services).
- Local DNS Server Query: If the system cache misses, the system sends a query to the DNS servers in
/etc/resolv.conf. - DNS Resolution: As explained earlier, the local DNS server performs iterative lookups to get the IP of
www.google.com. - TCP/TLS Handshake: The browser uses the IP to establish a TCP connection with Google's server. For HTTPS, it then performs a TLS handshake to encrypt the connection.
- HTTP Request: The browser sends an HTTP GET request to the server, asking for the content of
https://www.google.com. - Server Response: The server sends back an HTTP response with the HTML, CSS, and JavaScript files for the page.
- Page Rendering: The browser parses the response, downloads any additional resources (images, fonts), and renders the page for you to see.
Let's tackle common DNS issues and how to fix them:
1. Domain fails to resolve
- Test basic resolution: Run
dig <domain>ornslookup <domain>. If you get no answer, move to the next steps. - Check
/etc/resolv.conf: Ensure thenameserverentries are valid (e.g.,8.8.8.8or your ISP's DNS). If the file is a symlink (common withsystemd-resolved), verify the target file has correct entries. - Trace the lookup: Use
dig +trace <domain>to see where it fails. For example, if root servers don't respond, your network might be blocking DNS traffic. - Check firewall rules: Ensure your firewall (e.g.,
ufw,iptables) isn't blocking UDP/TCP port 53 (DNS uses UDP for most queries, TCP for large responses). - Verify DNS service status: Run
systemctl status systemd-resolvedto make sure the service is active and running.
2. DNS resolution is slow
- Test different DNS servers: Use
dig @8.8.8.8 <domain>anddig @<isp-dns-ip> <domain>to compare response times. The output showsQuery timeat the end. - Flush DNS cache: Stale cache entries can cause delays. Run
resolvectl flush-caches(systemd) ornscd -i hosts(nscd) to clear the cache. - Analyze DNS traffic: Use
tcpdump -tttt port 53to see how long each query takes. If responses are slow, your network or DNS server might be overloaded.
3. Resolution returns wrong IP
- Check
/etc/hosts: The/etc/hostsfile takes priority over DNS. Ensure there are no incorrect entries for the domain (e.g.,127.0.0.1 google.comwould redirect you to localhost). - Flush caches: Clear browser cache, system DNS cache, and local DNS server cache (if you control it).
- Test multiple DNS servers: Compare results from
dig @8.8.8.8 <domain>anddig @1.1.1.1 <domain>. If results differ, your local DNS might be compromised or using outdated records.
内容的提问来源于stack exchange,提问作者Veeresh Reddy

