DNS Enumeration
dig - DNS Zone Transfers
Find nameservers
dig ns [domain]
dig ns [domain] @[dns-server]Attempt zone transfer (AXFR)
dig axfr @[dns-server] [domain]
dig axfr @[nameserver] [domain]dig axfr @10.10.10.13 megacorpone.comQuery specific record types
dig @[dns-server] [domain] ANY
dig @[dns-server] [domain] A
dig @[dns-server] [domain] AAAA
dig @[dns-server] [domain] MX
dig @[dns-server] [domain] TXT
dig @[dns-server] [domain] SOA
dig @[dns-server] [domain] CNAME
dig @[dns-server] [domain] NS
dig @[dns-server] [domain] PTRReverse DNS lookup
Short output (just the answer)
Trace DNS path
Verbose output
dnsenum
Basic enumeration with wordlist
Attempt zone transfer
Full enumeration
dnsrecon
Basic reconnaissance
Reverse DNS lookup for range
Attempt zone transfer
Zone transfer against all NS records
Bruteforce subdomains
Standard record enumeration
Google enumeration
host
Simple lookup
Specific record type
Zone transfer attempt
nslookup
Interactive mode
Command line
Zone transfer
fierce
Basic domain scan
With DNS server
Subdomain bruteforce
Zone Transfer Attack Workflow
Subdomain Enumeration
Using dig with wordlist
Using host with wordlist
DNS Cache Snooping
Common DNS Record Types
Record Type
Description
Tips
Last updated