What is a DNS log?¶
A DNS log records a resolver's observation of name-lookup requests and responses. A query can show that a system sought information about a domain; it does not prove a deliberate visit or later connection.
Many processes generate lookups¶
Browsers, applications, email, adverts, updates, security tools and malware can query names. Cached answers may enable later connections without another query, while encrypted DNS, VPNs and external resolvers can bypass the observed service.
Establish resolver and client path¶
Preserve name, query type, response, source, resolver, client ID and time. Determine whether source identifies the endpoint, a forwarder or shared address, and record retention and zone.
Correlate proxy, firewall, endpoint, browser and server events and use DHCP or authentication to attribute the client. Keep lookup, connection, content access and user intent separate.
The point to remember
A DNS record proves an observed name-resolution event; downstream records prove connection, content and user action.