DNS Recon

ToolFeatureUse Cases
digversitileManual DNS recon
nslookupsimpleBasic DNS Queries
hoststreamlinedQuick checks
dnsenumautomatedDiscovering subdomains
fiercerecursiveUser friendly interface. subdomains and potential targets
dnsreconmulti-techniqueComprehensive DNS enumeration
theHarvesterOSINT tool grabs from various sorcesemail addresses, employee info, other data tied to a domain

Common Dig Commands

CommandDescription
dig domain.comDefault A record lookup
dig domain.com AGets IPv4 address
dig domain.com AAAAGets IPv6 address
dig domain.com MXMX records
dig domain.com NSName servers for the domain
dig domain.com TXTAny TXT records
dig somain.com CNAMECNAME
dig domain.com SOASOA record
dig @1.1.1.1 domain.comSpecific name server to query
dig +trace domain.comShows full path of DNS resolution
dig +x 192.111.1.1Performs reverse lookup on the IP address to find associated host name. Might have to specify a name server
dig +short domain.comprovides a short and concise answer to query
dig +noall +answer domain.comDisplays only the answer section of the query output
dig domain.com ANYRetrieves all available DNS records for the dns servers
  • Some servers can block DNS queries. Should get permission before performing extensive DNS recon

recon dns