finds.dev← search

// the find

jvns/dnspeep

★ 1,382 · Rust · MIT · updated Aug 2024

spy on the DNS queries your computer is making

dnspeep is a small Rust CLI that sniffs DNS queries off the wire with libpcap and prints each query lined up with its response, CNAME chains included. It's for developers debugging what a machine is actually resolving — telemetry endpoints, CDN redirects, background phone-home traffic — without wiring up a full tcpdump/wireshark workflow.

Pairs request and response on a single readable line instead of making you correlate raw packet dumps by hand, and explicitly flags queries that never got a response within a second rather than just going silent on them. The whole implementation is one src/main.rs, so you can read the entire thing in a few minutes and know exactly what it does. Ships as a single binary with prebuilt releases plus an AUR package, so install is trivial on the platforms it supports.

UDP-only — no TCP DNS support, so truncated or forced-TCP responses (large CNAME chains, DNSSEC) just won't appear. Blind to DNS-over-HTTPS and DNS-over-TLS entirely, which is a real gap now that Firefox and Chrome default to DoH for a lot of users — the exact traffic you'd want to inspect. The author labels it experimental and unmaintained with known correctness bugs, last pushed August 2024, no tests in the repo. Parsing is limited to whatever record types the dns-message-parser crate covers, so unusual RR types silently fail to show.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →