Tim VanBenschoten

Code · Mac app · in progress

It Is Always DNS

A native Mac tool for working out DNS problems: what a name resolves to, from which server, and why, and whether your queries are going where you think they are.

When a site resolves differently than you expect, or you're not sure your DNS queries go where you think they do on a VPN, tools like dig give you scattered answers. It Is Always DNS puts them in one Mac app. The name comes from the running joke that DNS is always the cause.

Queries run through DNSKit, a resolver written in Swift with no dependencies, so the app never shells out to nslookup. A small Go server, leakd, handles leak tests by recording which resolvers actually ask about its test names.

  • Lookups that show what a name resolves to, from which server, and why.
  • Query a specific resolver, reverse lookups, and the DNSSEC DO bit with a raw hexdump.
  • Compare one query across several resolvers, or force TCP.
  • A live view of the Mac's DNS configuration.
  • A menu bar item next to the main window.
  • idns, a dig-style command line on the same engine.
Runs onmacOS 26
StatusEarly · build from source
EngineDNSKit · Swift, no dependencies
Command lineidns
Leak-test serverleakd · Go
Does the DNS leak test work yet?
Not in the app. The leakd server works end to end, but the app's Leak Test tab isn't connected to it yet. That's next.
Is there a command-line version?
Yes. idns is a dig-style front end to the same DNS engine.
Does it support DNS over HTTPS or TLS?
Not yet. Encrypted transports are on the roadmap.

← All projects