Skip to content

DNS Configuration

DNS (Domain Name System) is responsible for resolving domain names to IP addresses. This article covers how to configure DNS resolution on CentOS / AlmaLinux / Rocky Linux, as well as commonly used DNS troubleshooting tools.

/etc/resolv.conf is the DNS resolver configuration file on Linux systems. All DNS queries on the system ultimately rely on it.

View the current DNS configuration
cat /etc/resolv.conf

Typical contents:

# Generated by NetworkManager
nameserver 8.8.8.8
nameserver 8.8.4.4
search example.com
  • nameserver — Specifies the DNS server address; up to 3 can be listed
  • search — DNS search domain; when querying a hostname without a domain suffix, this domain is automatically appended
Configure DNS servers for a connection
sudo nmcli connection modify ens33 ipv4.dns "223.5.5.5 119.29.29.29"
sudo nmcli connection up ens33

Use the + prefix to append to the existing DNS list:

Append a DNS server
sudo nmcli connection modify ens33 +ipv4.dns "8.8.8.8"
sudo nmcli connection up ens33
Remove a specific DNS server from the list
sudo nmcli connection modify ens33 -ipv4.dns "8.8.8.8"
sudo nmcli connection up ens33

After setting search domains, short hostnames will automatically have the domain suffix appended. For example, with the search domain set to example.com, ping web01 will automatically try web01.example.com.

Set DNS search domains
sudo nmcli connection modify ens33 ipv4.dns-search "example.com internal.local"
sudo nmcli connection up ens33

In DHCP mode, the server automatically provides DNS addresses. If you want to use only manually configured DNS servers:

Ignore DNS servers provided by DHCP
sudo nmcli connection modify ens33 ipv4.ignore-auto-dns yes
sudo nmcli connection up ens33

To restore using DHCP-provided DNS:

Restore using DHCP-provided DNS
sudo nmcli connection modify ens33 ipv4.ignore-auto-dns no
sudo nmcli connection up ens33

Viewing the Currently Active DNS Configuration

Section titled “Viewing the Currently Active DNS Configuration”
Check DNS configured in nmcli
nmcli connection show ens33 | grep -i dns
View the actual resolv.conf in effect
cat /etc/resolv.conf

/etc/hosts is a local static name resolution file that takes priority over DNS queries. It is suitable for:

  • Domain name mapping in local development environments
  • Providing basic name resolution when DNS is unavailable
  • Blocking specific domain names
View the hosts file contents
cat /etc/hosts

Default contents:

127.0.0.1 localhost localhost.localdomain
::1 localhost localhost.localdomain
Add a hostname mapping
echo '192.168.1.50 dbserver.example.com dbserver' | sudo tee -a /etc/hosts

The format is: IP_address FQDN short_alias

Add multiple mappings
sudo tee -a /etc/hosts > /dev/null <<'EOF'
192.168.1.51 web01.example.com web01
192.168.1.52 web02.example.com web02
192.168.1.53 cache.example.com cache
EOF

The system’s name resolution order is controlled by /etc/nsswitch.conf:

View the name resolution order
grep ^hosts /etc/nsswitch.conf

The output is typically:

hosts: files dns myhostname

This means the system checks in order: /etc/hosts file -> DNS servers -> local hostname.

dig is the most powerful DNS query tool, included in the bind-utils package.

Install the dig tool
sudo dnf install bind-utils
Query A records for a domain
dig example.com
Show only concise results
dig +short example.com
Query MX records (mail servers)
dig example.com MX
Query NS records (name servers)
dig example.com NS
Query using a specific DNS server
dig @8.8.8.8 example.com
Trace the full DNS resolution path
dig +trace example.com
Reverse DNS lookup (IP to domain)
dig -x 8.8.8.8

nslookup is also included in bind-utils and has simpler usage:

Query a domain
nslookup example.com
Query using a specific DNS server
nslookup example.com 8.8.8.8
Query a specific record type
nslookup -type=MX example.com

The host command provides concise query results:

Simple domain query
host example.com
Query MX records
host -t MX example.com

When encountering DNS resolution issues, follow these steps to diagnose:

Check the DNS servers currently in use
cat /etc/resolv.conf
Test whether the DNS server is reachable
ping -c 3 8.8.8.8
Directly test whether DNS resolution works
dig @8.8.8.8 example.com +short

Step 4: Compare Results from Different DNS Servers

Section titled “Step 4: Compare Results from Different DNS Servers”
Compare resolution results from multiple DNS servers
dig @223.5.5.5 example.com +short
dig @8.8.8.8 example.com +short
dig @119.29.29.29 example.com +short

Step 5: Check the Local Cache (if systemd-resolved is enabled)

Section titled “Step 5: Check the Local Cache (if systemd-resolved is enabled)”

In some configurations, the system may have DNS caching enabled:

Check systemd-resolved status
systemctl status systemd-resolved
Flush the systemd-resolved cache
sudo resolvectl flush-caches
ProviderPrimary DNSSecondary DNS
Alibaba Cloud (AliDNS)223.5.5.5223.6.6.6
Tencent (DNSPod)119.29.29.29119.28.28.28
Google8.8.8.88.8.4.4
Cloudflare1.1.1.11.0.0.1

Configuration example:

Use Alibaba Cloud DNS
sudo nmcli connection modify ens33 ipv4.dns "223.5.5.5 223.6.6.6"
sudo nmcli connection up ens33