Skip to content
Skip to main content
Logs, Records & Provider Evidence Technical Explainer

What is a DNS log?

A DNS log records a resolver's observation of name-lookup requests and responses. A query can show that a system sought information about a domain; it does not prove a deliberate visit or later connection.

Many processes generate lookups

Browsers, applications, email, adverts, updates, security tools and malware can query names. Cached answers may enable later connections without another query, while encrypted DNS, VPNs and external resolvers can bypass the observed service.

Establish resolver and client path

Preserve name, query type, response, source, resolver, client ID and time. Determine whether source identifies the endpoint, a forwarder or shared address, and record retention and zone.

Correlate proxy, firewall, endpoint, browser and server events and use DHCP or authentication to attribute the client. Keep lookup, connection, content access and user intent separate.

The point to remember

A DNS record proves an observed name-resolution event; downstream records prove connection, content and user action.

Reference: LOG-022Logs, Records & Provider Evidence