Overview
Domain Name System (DNS) translates names into IPs and is a common root cause of “the network is slow.” From a PCAP/PCAPNG you can identify resolver latency, cache behavior, truncation and TCP fallbacks, EDNS(0) negotiation, DNSSEC hints, and tunneling indicators (long labels, TXT/CNAME bursts, high-entropy queries). For encrypted transports like DoT/DoH, metadata—timing, endpoints, and ALPN—still reveals where problems start.
- What you’ll see: query/response timing, status code trends (NOERROR/NXDOMAIN/SERVFAIL), retries/timeouts, TC flag and TCP fallbacks, EDNS(0) behavior, large answers/DNSSEC hints, tunneling signals
- Best for: Performance analysis, NOC troubleshooting, SOC triage, incident response
- Works with: UDP/TCP 53, DNS over TLS (853/TCP), DNS over HTTPS (443/TCP), local forwarders and public resolvers
What to look for
- Latency & variance: query→response > 300 ms or high jitter → resolver/WAN issues,
- NXDOMAIN/SERVFAIL spikes: misconfigurations, malicious lookups, or upstream resolver faults,
- Truncation & fallbacks: TC bit set on UDP and follow-up TCP/53; common with DNSSEC/large answers,
- EDNS(0) issues: negotiation failures, small UDP size causing repeated queries,
- Tunneling indicators: long/high-entropy labels, many TXT/CNAME records, fixed-interval beacons,
- DoT/DoH signals: handshake retries, ALPN negotiation, fallback from DoH to classic DNS,
- Resolver choice: unusual egress to rare resolvers or country/ASN shifts.
Capture tips
- Capture both UDP and TCP 53 to observe truncation and fallbacks.
- Include ICMP (Packet Too Big/Frag Needed) for PMTUD symptoms on large answers.
- For DoT/DoH, capture the TLS/HTTPS flows; provide keys only if policy allows deeper inspection.
- Take a paired capture (client side and resolver) to localize where latency appears.
- Use a focused time window that reproduces the issue and stays within the 10 MB demo limit.
Example walkthrough
- Browse to DNS.
- Chart query→response times by resolver and domain; spot variance and spikes.
- Inspect status codes (NXDOMAIN/SERVFAIL) for bursts; isolate domains responsible.
- Check TC flag on UDP and confirm TCP fallbacks for large/DNSSEC answers.
- Review EDNS(0) UDP size and retry patterns; adjust if repeated truncation occurs.
- Flag tunneling signals (long labels, TXT bursts); export evidence for the ticket.
DNS FAQ
Look for long, high-entropy subdomains, frequent TXT/CNAME queries, and fixed-interval beacons to rare domains. The analyzer flags these patterns automatically.
When the UDP response is too large (TC bit set), for DNSSEC records, and for zone transfers. You’ll see a UDP response with TC followed by a TCP/53 exchange for the same question.
NXDOMAIN spikes often mean typos, broken apps, or malicious lookups; SERVFAIL suggests resolver or upstream problems. Our charts help distinguish client errors from resolver faults.
Measure query→response time per resolver. Consistently high latency or variance points to WAN or upstream issues; correlate with retries, TC fallbacks, and EDNS(0) size.