I would like to redo a MX spoofing project from recursor over to dnsdist, thanks to the new SpoofRawAction function.

Is there a tool that shows me the wire format for a specific response which I can adept? Or do I need to know the structure of the DNS packet and get it out of a tcpdump?

A hint into the right direction would be highly appreciated.


