DNS Message Parser

Paste a DNS protocol message as a hex string or base64url and decode the 12-byte header — transaction id, query/response, opcode, the AA/TC/RD/RA/AD/CD flags, the RCODE, and the section counts — plus the question and the answer, authority, and additional resource records. Domain names are decompressed (0xC0 pointers followed), and A, AAAA, NS, CNAME, PTR, MX, TXT, SOA, SRV, CAA, and OPT/EDNS0 records are decoded to readable values. Accepts the base64url form used by DNS-over-HTTPS. Runs in your browser; nothing is uploaded.

Decoded message

About this tool

DNS Message Parser decodes a raw DNS protocol message (the RFC 1035 wire format) — given as a hex string or base64url — into its header, question, and resource-record sections.

Every DNS query and response is a single message that starts with a fixed 12-byte header, followed by four counted sections.

The header

Records

The question names what was asked (a domain name, a QTYPE such as A or MX, and a QCLASS, usually IN). The answer, authority, and additional sections carry resource records. Domain names are decompressed — the message-compression pointers (0xC0…) that DNS uses to avoid repeating a suffix are followed back to their target, so you always see the full name.

Common record types are decoded to readable values:

Any unrecognized type falls back to a hex dump of its RDATA so nothing is hidden.

Where to get the bytes

A DNS message is the payload of a UDP/TCP packet (or, for DNS-over-HTTPS, the body or the base64url ?dns= parameter). In Wireshark, expand the Domain Name System layer and copy the bytes (right-click → Copy → …as a Hex Stream), or take them from a tcpdump capture or a DoH request. Hex input may use spaces, colons, dashes, dots, commas, or a leading 0x; base64url is auto-detected.

Common uses

FAQ

What input formats does the parser accept?

Hex or base64url, auto-detected. Hex may be separated by spaces, colons, dashes, dots, or commas and may carry a leading 0x — so a Wireshark "Copy as Hex Stream" or a colon-separated dump both paste straight in. Base64url is the exact form used in a DNS-over-HTTPS GET ?dns= parameter.

What if a record type isn't recognized?

Well-known types (A, AAAA, NS, CNAME, PTR, DNAME, MX, TXT, SPF, SOA, SRV, CAA, OPT/EDNS0) are decoded to readable values. Any other type falls back to a raw hex dump of its RDATA, so unusual or private-use records are still fully visible instead of being dropped.

How are truncated or corrupt messages handled?

The parser reports a precise error — e.g. a name or RDATA that "runs past end of message", an invalid hex digit, or a compression pointer that targets beyond the message. Compression-pointer loops are detected by capping the label count, so a malicious message can't hang the tool.

Does it follow DNS name compression?

Yes. The 0xC0… compression pointers that DNS uses to avoid repeating a domain suffix are followed back to their target, so every name in the output is shown in full rather than as a pointer offset.

Developer & Automation Access

Run it from the terminal

Same engine as this page, headless — via the gizza CLI:

gizza tool dns-message-parser "1234 8180 0001 0001 0000 0000 ...  or a base64url ?dns= value"

New to the CLI? Get gizza →

Open it by URL

Pre-fill and auto-run this tool with query parameters — the names match the API/CLI:

https://gizza.ai/tools/dns-message-parser/?message=1234%208180%200001%200001%200000%200000%20...%20%20or%20a%20base64url%20%3Fdns%3D%20value

Machine-readable descriptor: tool.json — title + parameters JSON Schema for agents.