DNS Configuration
DNS (Domain Name System) is responsible for resolving domain names to IP addresses. This article covers how to configure DNS resolution on CentOS / AlmaLinux / Rocky Linux, as well as commonly used DNS troubleshooting tools.
/etc/resolv.conf
Section titled “/etc/resolv.conf”/etc/resolv.conf is the DNS resolver configuration file on Linux systems. All DNS queries on the system ultimately rely on it.
cat /etc/resolv.confTypical contents:
# Generated by NetworkManagernameserver 8.8.8.8nameserver 8.8.4.4search example.comnameserver— Specifies the DNS server address; up to 3 can be listedsearch— DNS search domain; when querying a hostname without a domain suffix, this domain is automatically appended
Configuring DNS via NetworkManager
Section titled “Configuring DNS via NetworkManager”Setting DNS Servers
Section titled “Setting DNS Servers”sudo nmcli connection modify ens33 ipv4.dns "223.5.5.5 119.29.29.29"sudo nmcli connection up ens33Appending DNS Servers
Section titled “Appending DNS Servers”Use the + prefix to append to the existing DNS list:
sudo nmcli connection modify ens33 +ipv4.dns "8.8.8.8"sudo nmcli connection up ens33Removing a DNS Server
Section titled “Removing a DNS Server”sudo nmcli connection modify ens33 -ipv4.dns "8.8.8.8"sudo nmcli connection up ens33Configuring DNS Search Domains
Section titled “Configuring DNS Search Domains”After setting search domains, short hostnames will automatically have the domain suffix appended. For example, with the search domain set to example.com, ping web01 will automatically try web01.example.com.
sudo nmcli connection modify ens33 ipv4.dns-search "example.com internal.local"sudo nmcli connection up ens33Ignoring DHCP-Provided DNS
Section titled “Ignoring DHCP-Provided DNS”In DHCP mode, the server automatically provides DNS addresses. If you want to use only manually configured DNS servers:
sudo nmcli connection modify ens33 ipv4.ignore-auto-dns yessudo nmcli connection up ens33To restore using DHCP-provided DNS:
sudo nmcli connection modify ens33 ipv4.ignore-auto-dns nosudo nmcli connection up ens33Viewing the Currently Active DNS Configuration
Section titled “Viewing the Currently Active DNS Configuration”nmcli connection show ens33 | grep -i dnscat /etc/resolv.confThe /etc/hosts File
Section titled “The /etc/hosts File”/etc/hosts is a local static name resolution file that takes priority over DNS queries. It is suitable for:
- Domain name mapping in local development environments
- Providing basic name resolution when DNS is unavailable
- Blocking specific domain names
cat /etc/hostsDefault contents:
127.0.0.1 localhost localhost.localdomain::1 localhost localhost.localdomainAdding Custom Host Mappings
Section titled “Adding Custom Host Mappings”echo '192.168.1.50 dbserver.example.com dbserver' | sudo tee -a /etc/hostsThe format is: IP_address FQDN short_alias
sudo tee -a /etc/hosts > /dev/null <<'EOF'192.168.1.51 web01.example.com web01192.168.1.52 web02.example.com web02192.168.1.53 cache.example.com cacheEOFResolution Order
Section titled “Resolution Order”The system’s name resolution order is controlled by /etc/nsswitch.conf:
grep ^hosts /etc/nsswitch.confThe output is typically:
hosts: files dns myhostnameThis means the system checks in order: /etc/hosts file -> DNS servers -> local hostname.
DNS Query Tools
Section titled “DNS Query Tools”Using dig
Section titled “Using dig”dig is the most powerful DNS query tool, included in the bind-utils package.
sudo dnf install bind-utilsdig example.comdig +short example.comdig example.com MXdig example.com NSdig @8.8.8.8 example.comdig +trace example.comdig -x 8.8.8.8Using nslookup
Section titled “Using nslookup”nslookup is also included in bind-utils and has simpler usage:
nslookup example.comnslookup example.com 8.8.8.8nslookup -type=MX example.comUsing host
Section titled “Using host”The host command provides concise query results:
host example.comhost -t MX example.comDNS Troubleshooting Steps
Section titled “DNS Troubleshooting Steps”When encountering DNS resolution issues, follow these steps to diagnose:
Step 1: Verify DNS Configuration
Section titled “Step 1: Verify DNS Configuration”cat /etc/resolv.confStep 2: Test DNS Server Connectivity
Section titled “Step 2: Test DNS Server Connectivity”ping -c 3 8.8.8.8Step 3: Test DNS Resolution
Section titled “Step 3: Test DNS Resolution”dig @8.8.8.8 example.com +shortStep 4: Compare Results from Different DNS Servers
Section titled “Step 4: Compare Results from Different DNS Servers”dig @223.5.5.5 example.com +shortdig @8.8.8.8 example.com +shortdig @119.29.29.29 example.com +shortStep 5: Check the Local Cache (if systemd-resolved is enabled)
Section titled “Step 5: Check the Local Cache (if systemd-resolved is enabled)”In some configurations, the system may have DNS caching enabled:
systemctl status systemd-resolvedsudo resolvectl flush-cachesCommon Public DNS Servers
Section titled “Common Public DNS Servers”| Provider | Primary DNS | Secondary DNS |
|---|---|---|
| Alibaba Cloud (AliDNS) | 223.5.5.5 | 223.6.6.6 |
| Tencent (DNSPod) | 119.29.29.29 | 119.28.28.28 |
| 8.8.8.8 | 8.8.4.4 | |
| Cloudflare | 1.1.1.1 | 1.0.0.1 |
Configuration example:
sudo nmcli connection modify ens33 ipv4.dns "223.5.5.5 223.6.6.6"sudo nmcli connection up ens33