Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

The BIND 9 host utility can look up a name through your configured resolver, request a specific DNS record, query a chosen server, perform reverse lookups, and check authoritative-server SOA data. These nine patterns show what to run and what each result can—and cannot—tell you. Exact answers depend on the DNS data at query time, the server you ask, and your local resolver configuration.

Before you run the examples

host is a command-line DNS lookup utility from BIND. The commands below follow the behavior described in the Debian unstable bind9-host 1:9.20.29-1 manual, dated 2026-09-11 and updated 2026-09-16, with relevant behavior corroborated by the BIND 9.21.20 manual. Other operating systems may ship different versions. Check man host or host -V on your system if an option behaves differently.

In the examples, example.com and the addresses are illustrative inputs, not reports of live DNS answers. Replace them with the name or address you need to investigate. The optional final argument to a command is a DNS server hostname or IP address; without it, host uses the configured name server or servers, as described by its manual with reference to /etc/resolv.conf.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

1. Look up a name with your configured resolver

host example.com

This is the quick first check when you want to see what the resolver configured on your machine returns for a domain. In the current documented BIND behavior, leaving out a record type triggers the default set of queries: A, AAAA, MX, and HTTPS. Do not assume that this command asks only for an IPv4 address.

The answer reflects the resolver and DNS data used for this lookup. It does not establish that another resolver, another network, or every record associated with the domain would return the same result. If you need to isolate one record type or compare servers, use the patterns below.

2. Ask for a particular record type

host -t MX example.com

The -t option selects the resource-record type to query. Substitute the type you need; examples include A, AAAA, NS, SOA, TXT, CNAME, and DNSKEY.

For example, MX requests mail-exchanger records rather than the broader default set. A DNS response tells you what the queried server returned for that name and type; by itself it does not confirm that an email service is reachable or correctly configured end to end.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

3. Check TXT data

host -t TXT example.com

Use this form to request TXT records for a name. It is useful when inspecting DNS-published text, but host reports DNS query information—it does not interpret the returned text or prove that a domain, email policy, or other service configuration is valid.

Be precise about the name you query. TXT data may be published at a subdomain rather than the domain apex, so use the exact DNS name associated with the record you are checking.

4. Query a specific DNS server

host example.com 192.0.2.53

The final argument directs the query to the specified name server instead of the server or servers in your local resolver configuration. You can identify that server by hostname or IP address. The documentation uses an optional server argument for this purpose; 192.0.2.53 here is only an example address.

Targeting a server helps distinguish a resolver-specific answer from an answer obtained through your default configuration. When comparing results, keep the queried DNS name and record type the same, and note which server answered. Different answers do not by themselves explain why the data differs; the servers may have different roles, cached data, or zone state.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

5. Perform a reverse DNS lookup

host 192.0.2.10

When the input is an IPv4 or IPv6 address, host treats it as a request for a PTR record: the reverse-DNS name associated with that address. The existence and content of a PTR answer depend on how reverse DNS is configured. An address need not have a PTR record, and a returned name does not independently verify that the host is operating or that forward DNS points back to the same address.

6. Compare SOA data across authoritative servers

host -C example.com

The -C option queries SOA records from the zone’s listed authoritative name servers. It is useful as an SOA consistency check: inspect the returned SOA information from those servers when investigating whether their zone-level data appears consistent.

This is not a comparison of every record in the zone, nor proof that all clients or resolver paths see identical answers. If the problem concerns a particular A, MX, TXT, or other record, query that record directly against the relevant servers as well.

7. Request a zone listing only when authorized

host -l example.com

The -l operation attempts a zone transfer and prints NS, PTR, and address records. The documented -l -a form requests all records. These commands are appropriate for zones you administer or are authorized to inspect—not as a general way to enumerate arbitrary domains.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Zone transfers are commonly restricted by server policy, so a failed request against a domain you do not control is not evidence that the domain’s DNS is broken. If you administer the zone and need a transfer, check that the server permits it for your requesting host and that you are querying the intended authoritative server.

8. Constrain the query transport to IPv4 or IPv6

host -4 example.com
host -6 example.com

The -4 and -6 flags constrain the query transport family. They do not select the DNS record type. To request an address record of a particular family, combine the transport choice with -t as appropriate—for example, host -4 -t A example.com or host -6 -t AAAA example.com.

This distinction matters when diagnosing a network path: choosing IPv4 transport is not the same operation as asking DNS for an IPv4 address record.

9. Set a wait timeout or ask without recursion

Set the wait timeout

host -W 3 example.com

-W sets the wait timeout in seconds; values below one second are treated as one second. The documented defaults are five seconds for UDP responses and ten seconds for TCP connections, and settings in /etc/resolv.conf can override them. A timeout changes how long the command waits; it does not make an unresponsive server answer or establish that a record does not exist.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Clear the recursion-desired bit

host -r example.com

-r requests a non-recursive response by clearing the recursion-desired bit. A server may return a referral rather than a final answer. Use this when investigating how a server responds without recursion, not as a substitute for an ordinary lookup through a recursive resolver.

How to compare lookup results without conflating them

A DNS comparison is meaningful only when you know what differed. For each result, record the exact DNS name, requested type, server queried, returned answer, and whether recursion was requested. A normal lookup through your configured resolver and a non-recursive query to a particular server answer different questions. Likewise, host -C compares SOA information across listed authoritative servers; it does not compare all records.

  • If one resolver returns an unexpected address, repeat the same name and type against the intended server.
  • If you are investigating a missing record, request its type explicitly with -t and verify the exact owner name.
  • If authoritative servers appear inconsistent, use -C for SOA data, then query the specific record at issue against the relevant servers.
  • If results vary between machines, compare their resolver configuration and the servers each one actually queried.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshooting common surprises

The plain command returns more than an address

That can be expected: current documented BIND behavior queries A, AAAA, MX, and HTTPS when no type is specified. Use -t A or another explicit type to narrow the request.

A lookup times out

A timeout means no usable response arrived within the applicable wait period; it does not prove the name is absent. Check the selected server and local resolver configuration, then retry with an appropriate -W value. The documented defaults are five seconds for UDP and ten seconds for TCP, subject to /etc/resolv.conf overrides.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A zone-listing request is refused or fails

-l requests a zone transfer, which the server may restrict. Run it only for a zone you are authorized to inspect; for an administered zone, confirm transfer permissions and the target server.

A reverse lookup has no useful name

The reverse query asks for PTR data, and reverse DNS configuration determines whether a PTR answer exists and what it contains. An address alone does not guarantee a PTR record.

The result differs from another machine or tool

Make the comparison controlled: use the same exact name and record type, identify each queried server, and note whether recursion was requested. Local resolver settings and BIND versions can also affect command behavior; consult the installed man host and host -V.

Or skip the browser setup

For website captures rather than DNS lookups, ScreenshotNeo offers a one-request screenshot API. Its API returns an image or PDF for a URL; it is a separate tool from host.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

See the ScreenshotNeo API documentation for request options. Cookie banners, newsletter popups, and chat widgets are removed before the shot; bot checks, blank pages, and failed loads are never billed. Its MCP server lets AI agents take screenshots. The Free plan includes 1,000 screenshots a month with no card, and paid plans start at $5 for 3,000. Sign up for ScreenshotNeo free.

Frequently Asked Questions

How can I check which version of `host` is installed?

Run host -V; consult man host for the options documented on that system.

Does a successful `host` response prove that a website or mail service works?

No. It reports DNS query information, not an end-to-end test of the service.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.