Skip to content

Enumeration - DNS

whois

whois example.com

nslookup

domain to ip

nslookup example.com

Host

host $(domain)
host -t A $(domain)
host -t MX $(domain)
host -t TXT $(domain)
host -t CNAME $(domain)

Host - zone transfer

host -l $(domain) ns1.$(domain)
host -l $(domain) ns2.$(domain)
host -l $(domain) ns3.$(domain)

DNSrecon

dnsrecon -d $(domain)

DNSrecon - zone transfer

dnsrecon -d $(domain) -t axfr

DNSrecon - subdomain enumeration

dnsrecon -d $(domain) -D subdomain.txt -t brt

dig

dig - zone transfer

dig axfr @1.1.1.1 example.com

dnsenum

dnsenum - zone transfer

dnsenum $(domain)
  • https://viewdns.info/
  • https://threatintelligenceplatform.com