tcpdump -i ens3 -nt -s 500 port domain
tcpdump -i ens3 -nt port 53 | grep dns.msftncsi.com
https://jaminzhang.github.io/dns/use-tcpdump-to-analyze-dns-communication/ https://cristom50.wordpress.com/2015/03/19/monitoring-dns-queries-with-tcpdump/