You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

编写Bash脚本实现域名A记录解析及主机名IP批量解析

Hey there! Let's break down how to solve your Bash scripting needs step by step—whether you're fetching all A records for a domain, batch-resolving hostnames to IPs, or generating commands to block those IPs with APF.


1. Fetch All A Record IPs for a Domain with dig

You actually can grab all A records for a domain using dig with simple flags—here are the most useful variations:

# Get only the raw IP addresses (clean, script-friendly output)
dig +short yourtargetdomain.com A

# Get formatted, human-readable A record responses (great for debugging)
dig yourtargetdomain.com A +noall +answer
  • The +short flag strips out all extra metadata and returns just the IPs.
  • +noall +answer filters out non-essential output and only shows the actual DNS answer section.

2. Batch Resolve a List of Hostnames to IPs

If you have a list of hostnames (say, in a file called hosts.txt with one hostname per line), you can use either dig or getent to convert them en masse.

Using dig in a Loop

This method gives you granular control over each hostname's resolution:

while read -r hostname; do
    # Fetch all A record IPs for the current hostname
    resolved_ips=$(dig +short "$hostname" A)
    # Print or process the IPs (customize this part as needed)
    echo "$hostname → $resolved_ips"
done < hosts.txt

For a more concise one-liner, use xargs:

cat hosts.txt | xargs -I {} dig +short {} A

Using getent for System-Wide Resolution

getent leverages your system's default name resolution stack (including /etc/hosts and configured DNS servers), making it a reliable alternative:

# Resolve all hostnames and extract only unique IP addresses
getent hosts $(cat hosts.txt) | awk '{print $1}' | sort -u
  • getent hosts outputs lines like 192.168.1.1 examplehost
  • awk '{print $1}' extracts just the IP column
  • sort -u removes duplicate IPs to avoid redundant blocks

3. Generate Executable APF Block Commands (or Update Deny Files)

Since you want output that can be run directly to add hosts to APF's deny list, here are two practical approaches:

Option 1: Generate Runable apf -d Commands

This outputs commands you can copy-paste or save to a script for execution:

while read -r hostname; do
    resolved_ips=$(dig +short "$hostname" A)
    # Only process if IPs were successfully resolved
    if [ -n "$resolved_ips" ]; then
        for ip in $resolved_ips; do
            echo "apf -d $ip # Block IP from hostname: $hostname"
        done
    fi
done < hosts.txt

Save this output to block_ips.sh, make it executable with chmod +x block_ips.sh, then run it to apply the blocks.

Option 2: Directly Append IPs to APF's Deny File

If you want to skip manual execution and write straight to APF's deny rules file (typically /etc/apf/deny_hosts.rules):

# Resolve all hostnames, get unique IPs, append to deny file
while read -r hostname; do
    dig +short "$hostname" A
done < hosts.txt | sort -u >> /etc/apf/deny_hosts.rules

# Restart APF to apply the new rules
apf -r

Note: You may need to run this with sudo if you don't have write permissions to the APF config directory.


Bonus: Handle Failed Resolutions

To log hostnames that couldn't be resolved (instead of silently skipping them), add error tracking:

while read -r hostname; do
    resolved_ips=$(dig +short "$hostname" A)
    if [ -n "$resolved_ips" ]; then
        echo "$resolved_ips" >> resolved_ips.txt
    else
        echo "$(date): Failed to resolve hostname: $hostname" >> resolution_errors.log
    fi
done < hosts.txt

内容的提问来源于stack exchange,提问作者Vituvo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 09:29:09