Linux, FreeBSD, Juniper, Cisco / Network security articles and troubleshooting guides

It is currently Tue Oct 03, 2023 4:05 pm

Message body:
Enter your message here, it may contain no more than 60000 characters. 

:D :) ;) :( :o :shock: :? 8-) :lol: :x :P :oops: :cry: :evil: :twisted: :roll: :!: :?: :idea: :arrow: :| :mrgreen: :geek: :ugeek:
Font size:
Font colour
BBCode is ON
[img] is ON
[flash] is OFF
[url] is ON
Smilies are ON
Disable BBCode
Disable smilies
Do not automatically parse URLs
Confirmation code
Confirmation code:
In an effort to prevent automatic submissions, we require that you enter both of the words displayed into the text field underneath.

Topic review - Unix reverse dns lookup - using dig command - PTR dns record type
Author Message
Post subject: Re: Unix reverse dns lookup - using dig command - PTR dns record type  |  Post Posted: Tue Jan 13, 2015 4:48 am
It is not mandatory that an IP address is the A record for the reverse lookup record for an IP address. Example:
Reverse lookup for IP have a PTR record of "". But the A record for "" could not exist or it point to a different IP address (due to lack of efficient DNS records management or some other reason).

For best practices and where possible it is recommended that the IP address to be the A record for it's PTR record.
Post subject: Unix reverse dns lookup - using dig command - PTR dns record type  |  Post Posted: Mon Jan 12, 2015 5:43 pm
DIG is a unix dns lookup utility available in most of the distributions, Linux and FreeBSD included. Either in the package distributions or in the base systems.

For a list of dns records, best source is wiki "List of DNS record types" The main and most used DNS record types are:
- dns SOA record: it defines the start of authority for specific domain.
- dns A record: it points a human readable domain name (example: to a machine readable IPv4 address (example:
- dns AAAA record: it has the same significance as A record type, but it points to an IPv6 address.
- dns MX record: it maps a domain name to a list of mail transfer agents for that specific domain
- dns PTR record: it is used for reverse DNS lookups. It returns a human readable FQDN assigned to an IP address. Example: IP is mapped to ""

This tutorial shows how to perform reverse DNS lookup for an IPv4 address using dig command, but before a little about Reverse DNS lookup quoted from wikipedia: Reverse DNS lookup
Reverse DNS lookup
From Wikipedia, the free encyclopedia
"Reverse DNS" redirects here. For other uses, see Reverse DNS (disambiguation).
In computer networking, reverse DNS lookup or reverse DNS resolution (rDNS) is the determination of a domain name that is associated with a given IP address using the Domain Name System (DNS) of the Internet.

Computer networks use the Domain Name System to determine the IP address associated with a domain name. This process is also known as forward DNS resolution. Reverse DNS lookup is the inverse process, the resolution of an IP address to its designated domain name.

The reverse DNS database of the Internet is rooted in the Address and Routing Parameter Area (arpa) top-level domain of the Internet. IPv4 uses the domain and the domain is delegated for IPv6. The process of reverse resolving an IP address uses the pointer DNS record type (PTR record).

Informational RFCs (RFC 1033, RFC 1912 Section 2.1) specify that "Every Internet-reachable host should have a name" and that such names match with a reverse pointer record, but it is not a requirement of standards governing operation of the DNS itself.

Now that we know what the reverse DNS lookup database is and what are the domains allocated for reverse lookups for IPv4 and IPv6 here are two examples of doing this with dig command:
1. dig dns reverse lookup using -x option (from "man dig": -x option is supplied to indicate a reverse lookup):
$  dig +short -x

2. dig dns lookup using domain assigned for IPv4 reverse lookups.
$ dig +short ptr                      

One ting to note here is that the PTR lookup query argument is the IP address starting at 4th byte and ending at 1st byte followed by the "" keyword which is ipv4 domain followed by a dot.
Jump to:  
cronNews News Site map Site map SitemapIndex SitemapIndex RSS Feed RSS Feed Channel list Channel list

Delete all board cookies | The team | All times are UTC - 5 hours [ DST ]