如何查看DNS通配符A记录下产生查询请求的子域名?
Great question—dealing with wildcard DNS query visibility when your provider only shows aggregated *.example.com logs is super frustrating, especially when you can’t lean on web server logs for extra context. Here are practical, actionable ways to get the granular subdomain data you need:
1. Deploy a Local DNS Forwarder with Detailed Logging
Set up a lightweight DNS forwarder (like dnsmasq or BIND) that routes queries for your domain to your third-party DNS host, but logs every single request locally. This works if you can control the DNS settings for the network/devices sending queries.
- Install dnsmasq: Use your package manager—
sudo apt install dnsmasq(Debian/Ubuntu) orbrew install dnsmasq(macOS). - Configure logging & forwarding: Edit the dnsmasq config file (usually
/etc/dnsmasq.conf):# Forward all example.com queries to your third-party DNS IP address=/example.com/1.2.3.4 # Enable query logging log-queries # Set a log file location log-facility=/var/log/dnsmasq.log - Point your devices to this forwarder: Update your network’s DNS settings to use the IP of the machine running dnsmasq.
- Analyze logs: Filter and count subdomains with simple shell commands:
# View all example.com queries grep example.com /var/log/dnsmasq.log # Count unique subdomains awk '/example.com/ {print $6}' /var/log/dnsmasq.log | sort | uniq -c | sort -nr
2. Spin Up a DNS Sinkhole to Log Queries
If you need to monitor public-facing wildcard queries (and can temporarily adjust your DNS records), create a simple DNS server that logs every incoming query and returns a dummy response. This lets you capture exact subdomain names from any source on the internet.
Here’s a quick Python script using dnslib (install first with pip install dnslib):
from dnslib import DNSRecord, RR, QTYPE, A import socket def log_and_reply(data, addr): request = DNSRecord.parse(data) queried_subdomain = str(request.q.qname) print(f"Query received: {queried_subdomain} from {addr[0]}") # Send a dummy response (you can use your server IP instead of 0.0.0.0) reply = DNSRecord(DNSRecord.header(request.header.id, qr=1, aa=1, ra=1), q=request.q) reply.add_answer(RR(request.q.qname, QTYPE.A, rdata=A("0.0.0.0"), ttl=300)) sock.sendto(reply.pack(), addr) # Bind to UDP port 53 (requires root/admin privileges) sock = socket.socket(socket.AF_INET, socket.SOCK_DGRAM) sock.bind(("0.0.0.0", 53)) print("Listening for DNS queries on port 53...") while True: data, addr = sock.recvfrom(512) log_and_reply(data, addr)
- Run the script on a server with a public IP, make sure UDP port 53 is open in your firewall.
- Update your third-party DNS’s wildcard record to point to this server’s IP. All queries will hit your sinkhole and get logged.
3. Check for Advanced Logging in Your DNS Provider
Don’t sleep on this first—many third-party DNS hosts (even some free ones) offer granular query logs but hide them behind advanced settings or paid tiers.
- Look for sections like DNS Analytics, Query Logs, or Raw Logs in your provider’s dashboard.
- Some providers let you export raw query data via API or download logs as CSV files, which include exact subdomain names.
4. Capture DNS Traffic with Packet Sniffing
If you can monitor network traffic (either internal or at your edge), use tools like tcpdump or Wireshark to capture DNS queries sent to your third-party DNS server.
For example, with tcpdump:
# Capture all DNS traffic to your third-party DNS IP sudo tcpdump -i any udp port 53 and host 1.2.3.4 # Filter only example.com queries sudo tcpdump -i any udp port 53 and host 1.2.3.4 | grep example.com
For public traffic, you might need to use your cloud provider’s traffic mirroring feature or configure your edge firewall to log DNS requests.
内容的提问来源于stack exchange,提问作者user2034347

