3 tools
DNS tools map the domain name system that underpins the internet, translating names into addresses and revealing how an organization's infrastructure is arranged. For OSINT and reconnaissance, DNS data is a goldmine: subdomain enumeration, historical records, name servers, and mail configuration can expose services, hosting providers, and connections between assets that are not obvious from a website alone.
The tools here range from active enumeration and brute-forcing to passive datasets that surface certificates and previously observed records. When choosing one, weigh coverage, whether it queries passively or actively, and how it handles rate limits. Active scanning can be intrusive, so stay within scope and applicable law and prefer passive sources for quiet research. Pair DNS work with broader domain and IP research and our domain and IP OSINT tools guide.
The amass tool searches Internet data sources, performs brute force subdomain enumeration, searches web archives, and uses machine learning to generate additional subdomain name guesses. DNS name reso
Columbus Project is an advanced subdomain discovery service with fast, powerful and easy to use API.
Discover and enumerate all subdomains associated with a website, including those not publicly advertised. Works by ingesting certificate transparency logs.
DNS records can reveal subdomains, hosting providers, mail servers, name servers, and historical infrastructure changes. This helps investigators map an organization's attack surface, discover forgotten or staging services, and link seemingly separate assets through shared infrastructure, all from publicly queryable data without touching the target's systems directly.
Active enumeration queries DNS servers directly and may brute-force subdomain names, which is thorough but noisier and potentially detectable. Passive enumeration draws on precollected datasets, certificate logs, and historical records without contacting the target. Passive methods are quieter and lower-risk, while active methods surface records that passive sources may have missed.
Querying public DNS records is generally legal, since the data is openly published to make the internet work. However, aggressive brute-forcing, zone transfers against systems you do not own, or activity beyond an authorized scope can cross legal and ethical lines. Stay within scope, respect rate limits, and follow applicable law.
Search all 1,200+ OSINT tools instantly, or run a target through the investigation console.
Open the OSINT directory →