Chapter 25. Tools to analyse DNS traffic

DNS is highly mission critical, it is therefore necessary to be able to study and compare DNS traffic. Since version 2.9.18, PowerDNS comes with three tools to aid in analysis:

[Warning]Warning

As of 2.9.18 these tools are somewhat rough - they have no help messages for example. They do work though.

dnsreplay pcapfile [ipaddress] [port number]

This program takes recorded questions and answers and replays them to a specified nameserver and reporting afterwards which percentage of answers matched, were worse or better.

dnswasher pcapfile output

Anonymises recorded traffic, making sure it only contains DNS, and that the originating IP addresses of queries are stripped, which may allow you to send traces to our company or mailing list without violating obligations towards your customers or privacy laws.

dnsscope pcapfile

Calculates statistics without replaying traffic