DNS Isn’t Just UDP — And This Is Why It Matters @ChrisGreer
DNS Isn’t Just UDP — And This Is Why It Matters  @ChrisGreer
Uploaded February 2026 | Updated September 2026, 43 minutes ago
DNS is often thought of as “UDP only”, except in large zone transfers and other one-offs. Some IT engineers even block TCP communications in DNS environments, but then start having problems.

In this video, part 2 of the How DNS Works series, we break down when DNS uses UDP, when it switches to TCP even on the client end, and why it matters.

👉 Next up: a full recursive DNS lookup, step by step.

Download the pcap here 👉 github.com/packetpioneer/youtube/blob/main/dns_over_tcp.pcapng

RFC's mentioned in the video:
datatracker.ietf.org/doc/html/rfc5966
datatracker.ietf.org/doc/html/rfc1123

// Get Wireshark Certified //
Check out the official training course
📘 GET TRAINING: packetschool.teachable.com/l/pdp/official-wireshark-certified-analyst?coupon_code=PACKETHEAD50
🔗 Learn more: wireshark.org/certifications
Hands-On Lab Prep for the WCA - wiresharklabs.org

00:00 Does DNS use TCP?
01:05 What do the RFC's Say?
02:20 When DNS uses TCP
03:15 Let's generate some DNS over TCP
05:43 Hands On with DNS in Wireshark
DNS Isn’t Just UDP — And This Is Why It MattersCheck out this button!Quick Tip - Analyzing Endpoints in Wireshark3 Things to Look For in EVERY TCP HandshakeHow TCP Works - Bytes in FlightHow TCP Sequence Numbers Work - TCP Deep Dive // Hands-On Case StudyFree Wireshark Sessions - Sharkfest 26How TCP Works - Acknowledgment NumbersIntro to Wireshark Tutorial // Lesson 4 // Where do we capture network traffic? How?How TCP Works - Sequence NumbersMALWARE Analysis with Wireshark // TRICKBOT InfectionWhat happens when a client connects?
Chris Greer |

DNS Isn’t Just UDP — And This Is Why It Matters

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER