Updated to support DNS over TLS

This commit is contained in:
Discsearcher
2026-08-12 10:28:03 -04:00
parent c65f574c1d
commit 08e97a046d
+27 -9
View File
@@ -102,24 +102,42 @@ def perform_query(full_domain, ns, record_type, timeout):
# Add EDNS0 extension for better compatibility (like dig does) # Add EDNS0 extension for better compatibility (like dig does)
q.use_edns(edns=0, ednsflags=0, payload=4096) q.use_edns(edns=0, ednsflags=0, payload=4096)
# Try TCP first for better compatibility with some servers # Try UDP first
try: try:
r = query.tcp(q, ns, timeout=timeout)
if args.verbose:
print(f"[DEBUG] TCP Response: Answer={len(r.answer)} RRsets, TC flag: {bool(r.flags & flags.TC)}", file=sys.stderr)
except Exception as e:
# Fall back to UDP if TCP fails
if args.verbose:
print(f"[DEBUG] TCP failed ({e}), trying UDP...", file=sys.stderr)
r = query.udp(q, ns, timeout=timeout) r = query.udp(q, ns, timeout=timeout)
if args.verbose:
print(f"[DEBUG] UDP Response: Answer={len(r.answer)} RRsets, TC flag: {bool(r.flags & flags.TC)}", file=sys.stderr)
# If UDP returns truncated, retry with TCP # If UDP returns truncated, retry with TCP
if r.flags & flags.TC: if r.flags & flags.TC:
if args.verbose: if args.verbose:
print(f"[DEBUG] UDP Response truncated (TC flag set), retrying with TCP...", file=sys.stderr) print(f"[DEBUG] UDP Response truncated (TC flag set), retrying with TCP...", file=sys.stderr)
try:
r = query.tcp(q, ns, timeout=timeout)
if args.verbose:
print(f"[DEBUG] TCP Response: Answer={len(r.answer)} RRsets, TC flag: {bool(r.flags & flags.TC)}", file=sys.stderr)
except Exception as tcp_error:
# Fall back to TLS if TCP fails
if args.verbose:
print(f"[DEBUG] TCP failed ({tcp_error}), trying TLS...", file=sys.stderr)
r = query.tls(q, ns, timeout=timeout)
if args.verbose:
print(f"[DEBUG] TLS Response: Answer={len(r.answer)} RRsets, TC flag: {bool(r.flags & flags.TC)}", file=sys.stderr)
except Exception as udp_error:
# Fall back to TCP if UDP fails
if args.verbose:
print(f"[DEBUG] UDP failed ({udp_error}), trying TCP...", file=sys.stderr)
try:
r = query.tcp(q, ns, timeout=timeout) r = query.tcp(q, ns, timeout=timeout)
if args.verbose: if args.verbose:
print(f"[DEBUG] TCP Retry Response: Answer={len(r.answer)} RRsets, TC flag: {bool(r.flags & flags.TC)}", file=sys.stderr) print(f"[DEBUG] TCP Response: Answer={len(r.answer)} RRsets, TC flag: {bool(r.flags & flags.TC)}", file=sys.stderr)
except Exception as tcp_error:
# Fall back to TLS if TCP fails
if args.verbose:
print(f"[DEBUG] TCP failed ({tcp_error}), trying TLS...", file=sys.stderr)
r = query.tls(q, ns, timeout=timeout)
if args.verbose:
print(f"[DEBUG] TLS Response: Answer={len(r.answer)} RRsets, TC flag: {bool(r.flags & flags.TC)}", file=sys.stderr)
# Verbose debugging # Verbose debugging
if args.verbose: if args.verbose: