This article is in a list format that may be better presented using prose.You can help by converting this article to prose, if appropriate. Editing help is available.(March 2014)
This article or section contains close paraphrasing of one or more non-free copyrighted sources. Ideas in this article should be expressed in an original manner. More details may be available on the talk page.(March 2014)
Dnsmasq is a lightweight server designed to provide DNS, DHCP and TFTP services to a small-scale network. It can serve the names of local machines which are not in the global DNS. The DHCP server integrates with the DNS server and allows machines with DHCP-allocated addresses to appear in the DNS with names configured either in each host or in a central configuration file. Dnsmasq supports static and dynamic DHCP leases and BOOTP for network booting of diskless machines.
The developers of Dnsmasq targeted home networks using NAT and connected to the Internet via a modem, cable-modem or ADSL connection, but the system would function well in any small network where low resource-use and ease of configuration are important.
Simple DNS configuration of machines behind the firewall, independent of the details of an ISP's DNS servers
Clients which try to do DNS lookups while a modem-link to the Internet is down will time out immediately.
Dnsmasq will serve names from the /etc/hosts file (or an alternate). The names of local machines provided in this way become addressable without having to maintain /etc/hosts on each machine.
The integrated DHCP server supports static and dynamic DHCP leases and multiple networks and IP address ranges. It works across BOOTP relays and supports DHCP options including RFC 3397 DNS search lists.
Machines configured via DHCP have their names automatically included in the DNS. Each machine can specify details, or the Dnsmasq config file can associate a name with a MAC address centrally.
Dnsmasq caches Internet addresses (A records and AAAA records) and address-to-name mappings (PTR records), reducing the load on upstream servers and improving performance (especially on modem connections).
Users can configure Dnsmasq to automatically pick up the addresses of its upstream nameservers from PPP or DHCP configuration. It will automatically reload this information if it changes. This facility helps maintainers of Linux firewall-distributions to automate DNS configuration.
On IPv6-enabled boxes, Dnsmasq can both talk to upstream servers via IPv6 and offer DNS service via IPv6. On dual-stack (IPv4 and IPv6) boxes it talks both protocols and can even act as IPv6-to-IPv4 or IPv4-to-IPv6 forwarder.
Users can configure Dnsmasq to send queries for certain domains to upstream servers handling only those domains. This makes integration with private DNS systems easy.
Dnsmasq supports MX records and can return MX records for any or all local machines.
Dnsmasq also supports NAPTR records which allows the use of regular-expression-based rewriting of domain names which can then be used as URIs, further domain names to lookups, etc.
Some Internet service-providers rewrite the NXDOMAIN (domain does not exist) responses from DNS servers. This forces web browsers to a search page whenever a user attempts to browse to a domain that does not exist. Dnsmasq can filter these "bogus nxdomain" records out, preventing this potentially unwanted behavior.
Dnsmasq is able to perform DNSSEC validation and caching as of version 2.69, when compiled with support for DNSSEC enabled; some bugs stil exist in this version and there is a newer version.