Ultimate DNSrecon Cheat Sheet



Ultimate DNSrecon Cheat Sheet

DNS enumeration and reconnaissance tool. Discover subdomains, records, zone transfers, and DNS misconfigurations.

1. Basic Enumeration

Standard DNS enumeration and record discovery.

Basic Domain Scan

dnsrecon -d example.com

Verbose Output

dnsrecon -d example.com -v

Save to File

dnsrecon -d example.com --xml output.xml

Save as JSON

dnsrecon -d example.com --json output.json

Save as CSV

dnsrecon -d example.com --csv output.csv

Save to Database

dnsrecon -d example.com --db output.db

Basic Flags

  • -d <domain> : Target domain
  • -v : Verbose mode
  • --xml <file> : XML output
  • --json <file> : JSON output
  • --csv <file> : CSV output

Output Options

  • --db <file> : SQLite database
  • --iw : Continue on error
  • --disable_check_recursion
  • --disable_check_bindversion

2. Record Types

All Record Types (Default)

dnsrecon -d example.com

Specific Record Types

dnsrecon -d example.com -t A,AAAA,MX,NS,SOA,TXT

A Records Only

dnsrecon -d example.com -t A

MX Records

dnsrecon -d example.com -t MX

NS Records

dnsrecon -d example.com -t NS

TXT Records (SPF/DKIM)

dnsrecon -d example.com -t TXT

SRV Records

dnsrecon -d example.com -t SRV
Record TypeDescriptionUse Case
AIPv4 addressHost discovery
AAAAIPv6 addressIPv6 mapping
MXMail serverEmail infrastructure
NSName serverDNS infrastructure
SOAStart of authorityZone information
TXTText recordsSPF, DKIM, DMARC
SRVService recordsService discovery
CNAMECanonical nameAlias resolution
PTRPointer recordReverse DNS
CAACertificate authorityCertificate policy
Pro Tip: Record Analysis
TXT records often contain valuable information:
dnsrecon -d example.com -t TXT | grep -E "spf|dkim|dmarc|google-site"
This reveals email security configuration and service integrations.

3. Zone Transfers

Zone Transfer Test

dnsrecon -d example.com -t axfr

Zone Transfer with Specific Server

dnsrecon -d example.com -t axfr -n ns1.example.com

Zone Walk (DNSSEC)

dnsrecon -d example.com -t zonewalk

Check All NS for Zone Transfer

dnsrecon -d example.com -t axfr --threads 10

Reverse Lookup Zone Transfer

dnsrecon -r 192.168.1.0/24 -t axfr

Zone Transfer Types

  • -t axfr : Full zone transfer
  • -t zonewalk : DNSSEC zone walk
  • -r <range> : Reverse zone
  • -n <server> : Specific NS

Zone Transfer Info

  • Reveals all subdomains
  • Shows internal structure
  • Identifies hidden hosts
  • Maps network topology
Warning:

Zone transfers are misconfigurations. Always test all name servers:
dnsrecon -d example.com -t ns
Then test each NS for zone transfer:
dnsrecon -d example.com -t axfr -n ns1.example.com

4. Brute Force

Basic Brute Force

dnsrecon -d example.com -t brt

With Custom Wordlist

dnsrecon -d example.com -t brt -D /path/to/wordlist.txt

With Thread Control

dnsrecon -d example.com -t brt -D wordlist.txt --threads 20

Brute Force with Output

dnsrecon -d example.com -t brt -D wordlist.txt --csv results.csv

Google Enumeration

dnsrecon -d example.com -t goo

Bing Enumeration

dnsrecon -d example.com -t bing

Brute Force Types

  • -t brt : Brute force subdomains
  • -t goo : Google search
  • -t bing : Bing search
  • -t yand : Yandex search
  • -t crt : Certificate search

Wordlist Options

  • -D <file> : Custom wordlist
  • --threads <num> : Thread count
  • --tcp : TCP queries
  • --lifetime <sec> : Query timeout
Pro Tip: Wordlists
Use comprehensive wordlists for better results:
-D /usr/share/wordlists/SecLists/Discovery/DNS/subdomains-top1million-5000.txt
-D /usr/share/wordlists/SecLists/Discovery/DNS/dns-Jhaddix.txt
-D /usr/share/wordlists/SecLists/Discovery/DNS/namelist.txt

5. Advanced Features

Reverse DNS Lookup

dnsrecon -r 192.168.1.0/24

Reverse DNS with Name

dnsrecon -r 192.168.1.1-192.168.1.254 -n 8.8.8.8

DNSSEC Check

dnsrecon -d example.com -t dnssEC

Cache Snooping

dnsrecon -d example.com -t snoop -n 8.8.8.8

BIND Version Check

dnsrecon -d example.com -t bv

Custom DNS Server

dnsrecon -d example.com -n 8.8.8.8
FlagDescriptionExample
-r <range>Reverse DNS range-r 192.168.1.0/24
-n <server>Custom DNS server-n 8.8.8.8
-t dnssECDNSSEC check-t dnssEC
-t snoopCache snooping-t snoop
-t bvBIND version-t bv
--tcpTCP queries--tcp
--lifetimeQuery timeout--lifetime 10

6. Automation Scripts

Complete DNS Enumeration

#!/bin/bash # dns-enum.sh - Complete DNS enumeration DOMAIN=$1 OUTPUT_DIR="dns-recon-$DOMAIN" mkdir -p $OUTPUT_DIR echo "[+] Basic enumeration..." dnsrecon -d $DOMAIN --json $OUTPUT_DIR/basic.json echo "[+] Zone transfer test..." dnsrecon -d $DOMAIN -t axfr --xml $OUTPUT_DIR/zonetransfer.xml echo "[+] Brute force subdomains..." dnsrecon -d $DOMAIN -t brt -D /usr/share/wordlists/subdomains.txt --csv $OUTPUT_DIR/bruteforce.csv echo "[+] DNSSEC check..." dnsrecon -d $DOMAIN -t dnssEC --json $OUTPUT_DIR/dnssec.json echo "[+] Complete! Results in $OUTPUT_DIR/"

Multi-Domain Scanner

#!/bin/bash # multi-scan.sh - Scan multiple domains while read -r domain; do echo "[+] Scanning $domain..." dnsrecon -d "$domain" --json "results-$domain.json" # Extract subdomains jq -r '.[].name' "results-$domain.json" | sort -u > "subdomains-$domain.txt" echo "[+] Found $(wc -l < subdomains-$domain.txt) subdomains" done < domains.txt

Zone Transfer Monitor

#!/bin/bash # zone-monitor.sh - Monitor for zone transfer vulnerabilities DOMAIN=$1 while true; do echo "[+] Testing zone transfer for $DOMAIN..." dnsrecon -d "$DOMAIN" -t axfr --xml results.xml if grep -q "Zone Transfer" results.xml; then echo "[!] Zone transfer successful!" # Send notification notify "Zone transfer found for $DOMAIN" fi sleep 86400 done

Reverse DNS Mapper

#!/bin/bash # reverse-map.sh - Map reverse DNS RANGE=$1 OUTPUT="reverse-dns.txt" echo "[+] Mapping reverse DNS for $RANGE..." dnsrecon -r "$RANGE" --json results.json # Extract PTR records jq -r '.[] | select(.type == "PTR") | "\(.name) -> \(.address)"' results.json > "$OUTPUT" echo "[+] Results saved to $OUTPUT" cat "$OUTPUT"

DNS Security Audit

#!/bin/bash # dns-audit.sh - DNS security audit DOMAIN=$1 REPORT="dns-audit-$DOMAIN.txt" echo "DNS Security Audit for $DOMAIN" > "$REPORT" echo "================================" >> "$REPORT" echo "[+] Checking DNSSEC..." dnsrecon -d "$DOMAIN" -t dnssEC >> "$REPORT" echo "[+] Checking BIND version..." dnsrecon -d "$DOMAIN" -t bv >> "$REPORT" echo "[+] Testing zone transfer..." dnsrecon -d "$DOMAIN" -t axfr >> "$REPORT" echo "[+] Checking cache snooping..." dnsrecon -d "$DOMAIN" -t snoop >> "$REPORT" echo "[+] Audit complete! Report: $REPORT"
Pro Tip: DNS Security Checks

Regularly audit DNS configuration:
1. Test zone transfers on all NS
2. Check DNSSEC implementation
3. Verify BIND version disclosure
4. Test cache snooping vulnerability
5. Review SPF/DKIM/DMARC records

⇧