Skip to content

How to See Which Domains Your iPhone Looks Up (DNS Query Log)

Turn on DNS Capture in HTTPS Capture to log every DNS query your iPhone makes, with answers, response codes and timing, and choose the DNS servers it uses.

2 min readHTTPS Capture

Every time an app connects to a server, it usually asks DNS for the address first. A DNS query log therefore shows quickly which services an app contacts, including analytics and ad domains. It also helps you find lookups that fail with NXDOMAIN or that respond slowly. iOS has no built-in DNS log. HTTPS Capture can record one on the iPhone, next to your HTTP traffic.

Turn on DNS Capture

  1. Open Settings in HTTPS Capture.
  2. In the Capture section, turn on DNS Capture.
  3. Optional: tap DNS Servers to choose which servers answer your queries.
  4. Restart capture (stop, then start) so the new DNS setting takes effect.

While DNS Capture is on, the iPhone’s DNS lookups go to the servers you chose, through HTTPS Capture’s tunnel. Each query and its answer are recorded as they pass.

Read the DNS log

DNS lookups appear in the same timeline as HTTP requests, marked with a green DNS badge. Each row shows:

  • the domain name and the record type, such as A, AAAA or HTTPS
  • the result: NOERROR, NXDOMAIN (domain does not exist), SERVFAIL, or TIMEOUT
  • the DNS server that answered

Open a row for full details: the question, flags, response time, every answer with its TTL, EDNS information, and a hex dump of the raw packets. Tap an answer to copy it, or use Copy Query Name / Copy Summary.

Use the search box to find a domain, and the Rules → URL Filter whitelist or blacklist to limit which domains are logged.

Choose your DNS servers

Under DNS Servers you can pick a preset, such as Google (8.8.8.8), Cloudflare (1.1.1.1), AliDNS, DNSPod, 114 DNS or Baidu, or enter up to three IPv4 addresses yourself. Comparing lookup times between providers is a quick way to see which DNS is fastest on your network.

What it cannot see

DNS Capture records classic, unencrypted DNS on UDP port 53. These lookups are not visible:

  • encrypted DNS set by a DNS configuration profile, which may take priority
  • iCloud Private Relay lookups
  • apps that use their own DNS-over-HTTPS. You will often still see those HTTPS requests in the HTTP list.
  • multicast lookups for local devices (mDNS / Bonjour)

Privacy

Like everything in HTTPS Capture, DNS records stay on your iPhone. DNS records are not included when you export a HAR file, because HAR only describes HTTP traffic.

HTTPS Capture

Capture and decrypt HTTPS traffic on iPhone

App Store

Ready to try it?

HTTPS Capture · Capture and decrypt HTTPS traffic on iPhone

Free on the App Store