dnstop
« Back to VersTracker
Description:
Console tool to analyze DNS traffic
Type: Formula  |  Latest Version: 20140915@0  |  Tracked Since: Dec 17, 2025
Links: Homepage  |  formulae.brew.sh
Category: Networking
Tags: dns networking monitoring traffic-analysis security
Install: brew install dnstop
About:
dnstop is a command-line utility that monitors DNS traffic on a network interface and presents real-time statistics in an interactive console display. It parses live packet captures to report query types, domains, clients, and servers, helping identify network anomalies and performance bottlenecks. The tool is invaluable for network administrators needing immediate visibility into DNS activity without complex setup.
Key Features:
  • Real-time DNS traffic monitoring and analysis
  • Interactive console interface with sortable columns
  • Detailed statistics on query types, domains, and response codes
  • Support for both IPv4 and IPv6 traffic
  • Low overhead packet capture operation
Use Cases:
  • Troubleshooting DNS resolution issues and latency in enterprise networks
  • Monitoring for suspicious DNS queries indicating malware or data exfiltration
Alternatives:
  • tcpdump – More versatile packet sniffer but lacks dnstop's DNS-specific analysis and visualization
  • tshark – Powerful CLI Wireshark with DNS filters, but heavier and less focused for quick DNS stats
License: BSD-3-Clause
Bottles available for: arm64_tahoe, arm64_sequoia, arm64_sonoma, arm64_ventura, arm64_monterey, arm64_big_sur, sonoma, ventura, monterey, big_sur, catalina, arm64_linux, x86_64_linux
Version History
Detected Version Rev Change Commit
Sep 14, 2025 7:58pm 0 VERSION_BUMP 7fbdbd82