-
ExploreDNS v1.0.0
Stablereleased this
2026-07-07 12:19:08 +00:00 | 9 commits to main since this releaseFirst stable release. ExploreDNS is a self-contained Go reimplementation of
James Ponder's classic dnstraverse
(the engine behind dns.squish.net): it walks the DNS delegation tree from the
root down and, instead of stopping at the first answer, explores every
resolution path a real iterative resolver could take — reporting each
outcome with the probability that a real-world query would end up there, so
broken delegations, lame referrals, and missing glue surface even when a
domain "mostly works".Highlights
Faithful dnstraverse traversal semantics. The engine was verified against
live runs of the original Ruby engine across answered, NXDOMAIN, null-MX,
CNAME-restart, and glueless-delegation domains, with matching results:- Strictly non-recursive (RD=0) queries at every delegation step
- Per-nameserver and per-IP branching with probability split 1/n at each
fan-out; aggregated outcomes always sum to 100% - Bailiwick-aware response caching — out-of-bailiwick records are discarded,
lame referrals are detected and reported - Glueless NS resolution via sub-traversals from the branch cache (never the
local resolver), withno glueand loop dead-ends carrying their
probability into the results - CNAME chains followed in-message; out-of-zone targets restart from the
deepest cached zone with full-chain loop detection - Fast mode (default) memoizes completed subtrees (
completed earlier);
--fast=falsere-walks every branch independently - EDNS0 with automatic 512-byte fallback, UDP→TCP retry on truncation, and a
per-run packet cache so no server is asked the same question twice
CLI. dnstraverse-style output: refid-numbered progress lines, a
Results:section of aggregated outcomes with probabilities and dig-style
records,Summary Results:grouped by status and answer content, optional
server/version listing, JSON output (--json) as a single deterministic
document, colour only on a TTY.Web interface. The same engine behind a browser SPA and JSON REST API:
async jobs, live progress over Server-Sent Events (with refid and status per
event), aggregated results with probabilities, and a one-hour job retention
window.Deployment. Safe to expose publicly by default — hard per-traversal
timeout (EXPLOREDNS_JOB_TIMEOUT, 5m), concurrent-job cap
(EXPLOREDNS_MAX_JOBS, 8), CORS off unlessEXPLOREDNS_CORS_ORIGINis set.
Ships withfly.tomland a tag-triggered deploy workflow; the reference
deployment runs on Fly.io with machines in Sydney and Virginia.Install
go install gitea.hansenits.com.au/hits/ExploreDNS/cmd/exploredns@v1.0.0 go install gitea.hansenits.com.au/hits/ExploreDNS/cmd/server@v1.0.0Downloads