Protocol · DNS

DNS PCAP Analysis

by My Network Consultant

From capture to clarity—diagnose resolver latency, failures, and tunneling with AI-powered insights.

Layer 7 (Application) Related: UDP, TCP, DoT, DoH, IP, ICMP Ports: 53/UDP, 53/TCP, 853/TCP (DoT), 443/HTTPS (DoH)

Overview

Domain Name System (DNS) translates names into IPs and is a common root cause of “the network is slow.” From a PCAP/PCAPNG you can identify resolver latency, cache behavior, truncation and TCP fallbacks, EDNS(0) negotiation, DNSSEC hints, and tunneling indicators (long labels, TXT/CNAME bursts, high-entropy queries). For encrypted transports like DoT/DoH, metadata—timing, endpoints, and ALPN—still reveals where problems start.

  • What you’ll see: query/response timing, status code trends (NOERROR/NXDOMAIN/SERVFAIL), retries/timeouts, TC flag and TCP fallbacks, EDNS(0) behavior, large answers/DNSSEC hints, tunneling signals
  • Best for: Performance analysis, NOC troubleshooting, SOC triage, incident response
  • Works with: UDP/TCP 53, DNS over TLS (853/TCP), DNS over HTTPS (443/TCP), local forwarders and public resolvers

What to look for

  • Latency & variance: query→response > 300 ms or high jitter → resolver/WAN issues,
  • NXDOMAIN/SERVFAIL spikes: misconfigurations, malicious lookups, or upstream resolver faults,
  • Truncation & fallbacks: TC bit set on UDP and follow-up TCP/53; common with DNSSEC/large answers,
  • EDNS(0) issues: negotiation failures, small UDP size causing repeated queries,
  • Tunneling indicators: long/high-entropy labels, many TXT/CNAME records, fixed-interval beacons,
  • DoT/DoH signals: handshake retries, ALPN negotiation, fallback from DoH to classic DNS,
  • Resolver choice: unusual egress to rare resolvers or country/ASN shifts.

Capture tips

  • Capture both UDP and TCP 53 to observe truncation and fallbacks.
  • Include ICMP (Packet Too Big/Frag Needed) for PMTUD symptoms on large answers.
  • For DoT/DoH, capture the TLS/HTTPS flows; provide keys only if policy allows deeper inspection.
  • Take a paired capture (client side and resolver) to localize where latency appears.
  • Use a focused time window that reproduces the issue and stays within the 10 MB demo limit.

Example walkthrough

  1. Browse to DNS.
  2. Chart query→response times by resolver and domain; spot variance and spikes.
  3. Inspect status codes (NXDOMAIN/SERVFAIL) for bursts; isolate domains responsible.
  4. Check TC flag on UDP and confirm TCP fallbacks for large/DNSSEC answers.
  5. Review EDNS(0) UDP size and retry patterns; adjust if repeated truncation occurs.
  6. Flag tunneling signals (long labels, TXT bursts); export evidence for the ticket.

DNS FAQ

Look for long, high-entropy subdomains, frequent TXT/CNAME queries, and fixed-interval beacons to rare domains. The analyzer flags these patterns automatically.

When the UDP response is too large (TC bit set), for DNSSEC records, and for zone transfers. You’ll see a UDP response with TC followed by a TCP/53 exchange for the same question.

NXDOMAIN spikes often mean typos, broken apps, or malicious lookups; SERVFAIL suggests resolver or upstream problems. Our charts help distinguish client errors from resolver faults.

Measure query→response time per resolver. Consistently high latency or variance points to WAN or upstream issues; correlate with retries, TC fallbacks, and EDNS(0) size.
We use cookies & process data
By using this site, you agree to our Terms and Privacy Policy. We process file uploads for network analysis only.