Make dig and nslookup DNSSEC aware?

Havard Eidnes he at uninett.no
Wed May 22 14:57:05 UTC 2024


> Sorry if this has already been hashed through, but I cannot
> find anything in the archive.  Is there any chance someone can
> make dig and nslookup DNSSEC aware and force it to use DoT or
> DoH ports - TCP 443 or 853 only?

Not sure about that.  However, the "kdig" utility from the "knot"
name server is able to do DoT and DoH (the latter only if
configured to use libnghttp2), and in my case that was the
shorter path to the goal of having a CLI tool to do DoT and DoH
testing.

Regards,

- Håvard



More information about the bind-users mailing list