编写Bash脚本实现域名A记录解析及主机名IP批量解析
Hey there! Let's break down how to solve your Bash scripting needs step by step—whether you're fetching all A records for a domain, batch-resolving hostnames to IPs, or generating commands to block those IPs with APF.
dig You actually can grab all A records for a domain using dig with simple flags—here are the most useful variations:
# Get only the raw IP addresses (clean, script-friendly output) dig +short yourtargetdomain.com A # Get formatted, human-readable A record responses (great for debugging) dig yourtargetdomain.com A +noall +answer
- The
+shortflag strips out all extra metadata and returns just the IPs. +noall +answerfilters out non-essential output and only shows the actual DNS answer section.
If you have a list of hostnames (say, in a file called hosts.txt with one hostname per line), you can use either dig or getent to convert them en masse.
Using dig in a Loop
This method gives you granular control over each hostname's resolution:
while read -r hostname; do # Fetch all A record IPs for the current hostname resolved_ips=$(dig +short "$hostname" A) # Print or process the IPs (customize this part as needed) echo "$hostname → $resolved_ips" done < hosts.txt
For a more concise one-liner, use xargs:
cat hosts.txt | xargs -I {} dig +short {} A
Using getent for System-Wide Resolution
getent leverages your system's default name resolution stack (including /etc/hosts and configured DNS servers), making it a reliable alternative:
# Resolve all hostnames and extract only unique IP addresses getent hosts $(cat hosts.txt) | awk '{print $1}' | sort -u
getent hostsoutputs lines like192.168.1.1 examplehostawk '{print $1}'extracts just the IP columnsort -uremoves duplicate IPs to avoid redundant blocks
Since you want output that can be run directly to add hosts to APF's deny list, here are two practical approaches:
Option 1: Generate Runable apf -d Commands
This outputs commands you can copy-paste or save to a script for execution:
while read -r hostname; do resolved_ips=$(dig +short "$hostname" A) # Only process if IPs were successfully resolved if [ -n "$resolved_ips" ]; then for ip in $resolved_ips; do echo "apf -d $ip # Block IP from hostname: $hostname" done fi done < hosts.txt
Save this output to block_ips.sh, make it executable with chmod +x block_ips.sh, then run it to apply the blocks.
Option 2: Directly Append IPs to APF's Deny File
If you want to skip manual execution and write straight to APF's deny rules file (typically /etc/apf/deny_hosts.rules):
# Resolve all hostnames, get unique IPs, append to deny file while read -r hostname; do dig +short "$hostname" A done < hosts.txt | sort -u >> /etc/apf/deny_hosts.rules # Restart APF to apply the new rules apf -r
Note: You may need to run this with sudo if you don't have write permissions to the APF config directory.
To log hostnames that couldn't be resolved (instead of silently skipping them), add error tracking:
while read -r hostname; do resolved_ips=$(dig +short "$hostname" A) if [ -n "$resolved_ips" ]; then echo "$resolved_ips" >> resolved_ips.txt else echo "$(date): Failed to resolve hostname: $hostname" >> resolution_errors.log fi done < hosts.txt
内容的提问来源于stack exchange,提问作者Vituvo

