Skip to content

DNS Recon

Enumerating a target's DNS to map domains, subdomains, and infrastructure.

Why It Matters

DNS is one of the richest passive sources in recon. Records reveal mail servers, subdomains, hosting providers, and sometimes internal naming, all without sending a packet to the target's own systems. A misconfigured server that allows a zone transfer can hand over the entire domain at once.

Reference

Approach

  • Query records with nslookup, dig, and dnsrecon
  • Brute force hostnames and enumerate subdomains with wordlists
  • Attempt zone transfers against each name server
  • Pull in OSINT and online DNS tools to corroborate
  • Keep traffic to the target's own name servers low; prefer passive sources first

nslookup

Query DNS for host, mail, and name server records.

nslookup targetorganization.com              # resolve A record
nslookup -type=CNAME targetorganization.com  # CNAME record
nslookup -query=mx example.com               # mail servers
nslookup -type=ns example.com                # name servers
nslookup -type=PTR 192.0.2.10                # reverse lookup

dig

More detailed output than nslookup, and the standard tool on Linux.

dig a example.com @nameserver     # A record from a specific name server
dig example.com MX +short         # mail servers, terse
dig example.com ANY               # all record types

dnsrecon

Kali reconnaissance tool for records, subdomain brute forcing, and zone transfers.

dnsrecon -d TARGET -D /usr/share/wordlists/dnsmap.txt -t std --xml output.xml

fierce

Locates non-contiguous IP space and hostnames for a domain: https://github.com/mschwager/fierce

Zone Transfers

A zone transfer (AXFR) copies a server's entire zone database. Only misconfigured servers allow it to arbitrary clients, but when they do it is the fastest possible enumeration.

dig @ns1.example.com example.com AXFR

On Windows, the same request through nslookup interactive mode:

nslookup
> set type=any
> ls -d example.com

How I Use It

I start with the record types that map infrastructure (NS, MX, A, TXT), then try an AXFR against every name server, since a single misconfigured one saves hours. Subdomain brute forcing and OSINT fill in the rest. I lean on the online tools below for passive data before touching the target's own servers.

Resources