0

When I perform NSLOOKUP -q=a chinaa.cn I get the following result in WireShark:

enter image description here

Why did it FIRST look up the PTR of my ISP DNS before sending an A-request?
And why did the DNS server respond first with with No such name with .home-appended to it?

Kahn Kah
  • 144
  • 6

1 Answers1

4

NSLOOKUP first displays the IP address of the DNS server it sends the request to, along with its DNS name. If the DNS name is not already in the DNS cache, then it sends a PTR request to get the name.

enter image description here

longneck
  • 23,082
  • 4
  • 52
  • 86
  • 1
    And the reason it only does it intermittently is because it will be caching the response for the TTL. The answer to the second question will be because your DHCP server will be returning `.home` as a search path so it will checked first – hardillb Nov 01 '21 at 13:36