What can DNS query logs actually show?¶
A DNS query log records part of the process used to find information about a domain. Its value depends heavily on where the log was created.
First identify the observation point¶
| Log source | Apparent client may be |
|---|---|
| Device or application | The local device or process making the request |
| Workplace resolver | A private IP address or managed device on the network |
| Provider or public resolver | A public connection or another forwarding resolver |
| Authoritative DNS server | Usually the recursive resolver, not the original device |
If you are not sure which system produced the log, establish that before interpreting the client address.
Fields the log may contain¶
Preserve the original record and look for:
- date, time and time zone;
- apparent client IP address;
- requested name;
- query type;
- response code;
- answer returned; and
- resolver or server identity.
A and AAAA queries ask for IPv4 and IPv6 addresses. Other query types can request mail servers, aliases, name servers and other information.
An NXDOMAIN response usually means the responding DNS system considered the requested name not to exist. Other failure responses may show a temporary problem, refusal or inability to obtain an answer.
Read one representative log entry¶
DNS products use different formats, but a resolver log might contain a row like this:
2026-09-05T14:32:18Z client=10.20.5.14 qname=files.example qtype=A rcode=NOERROR answer=198.51.100.44 resolver=dns-02
| Field | Reading | Evidential use |
|---|---|---|
| Timestamp | 2026-09-05T14:32:18Z | Places the query at 14:32:18 UTC, subject to the source clock and logging behaviour |
client | 10.20.5.14 | Identifies the apparent client at this resolver; DHCP or device records may be needed to resolve the private address |
qname and qtype | files.example, A | Shows the exact name and that an IPv4 answer was requested |
rcode | NOERROR | Shows that the DNS response did not report an error; it does not by itself prove an address was returned |
answer | 198.51.100.44 | Shows the address recorded in this product's answer field |
resolver | dns-02 | Identifies the observation point whose configuration and coverage need to be understood |
Preserve the original row and its field definitions. A normal response code, an answer field and a later connection are related but separate facts.
Join the client address to the network¶
A private client address may need to be matched with DHCP, Wi-Fi or device records. A public address may represent a household, workplace, mobile connection, VPN or other shared network. At an authoritative server, it may identify only the resolver.
Check the coverage¶
Find out whether logging was enabled, how long records were kept and whether queries were sampled. Caching, encrypted DNS or another resolver may mean relevant activity is absent from the log being examined.
Use the log to move the enquiry forward¶
A good DNS record can establish that the logging system received a request for a name at a particular time and, if recorded, what answer it returned. Combine it with connection, browser, application or platform records to show what happened after the lookup.
Operational takeaway
Read a DNS log from its observation point outward: identify the recorder, client, name, type, response and answer, then use network and application records to show what followed.