DNS Fundamentals
DNS translates names (target.com) to IP addresses. It sounds boring, but it’s one of the richest reconnaissance sources there is: an organization’s DNS records reveal its mail servers, subdomains, cloud providers, leaked internal infrastructure, and much more. Almost every pentest starts with DNS, and several attacks (poisoning, subdomain takeover, rebinding) live here.
How it works (resolution)
Section titled “How it works (resolution)”When you request www.target.com, your resolver asks in a chain: root → TLD (.com) → target.com’s authoritative server → IP. That hierarchy and the cache along the way are the basis of several attacks.
Record types (what they reveal)
Section titled “Record types (what they reveal)”A name -> IPv4 AAAA name -> IPv6CNAME alias of another name (key in subdomain takeover)MX mail servers (who runs the email: Google, O365...)NS authoritative name serversTXT free text: SPF, DKIM, DMARC, verifications (lots of info!)SOA zone data PTR IP -> name (reverse DNS)SRV services (in AD: _ldap._tcp.dc._msdcs -> locates DCs)TXT records leak providers (SaaS the company uses), MX the mail, CNAME point to third-party services (takeover-able), and SRV in AD locate the Domain Controllers.
Querying DNS (recon)
Section titled “Querying DNS (recon)”dig target.com A ; dig target.com MX ; dig target.com TXT ; dig target.com NSdig +short target.comnslookup -type=any target.comhost target.com# reverse DNSdig -x 1.2.3.4# locate an AD domain's DCsnslookup -type=srv _ldap._tcp.dc._msdcs.domain.localSubdomain enumeration
Section titled “Subdomain enumeration”Subdomains are surface: dev., staging., vpn., mail., admin. Each is a possible door (see Subdomain Enumeration).
# zone transfer (if misconfigured, gives you EVERYTHING)dig axfr @ns1.target.com target.com# brute force / passivesubfinder -d target.com ; amass enum -d target.com# Certificate Transparency (subdomains via certificates)curl -s "https://crt.sh/?q=%25.target.com&output=json"A misconfigured zone transfer (AXFR) hands over the whole zone — a classic finding.
DNS-related attacks
Section titled “DNS-related attacks”- Subdomain takeover: a CNAME points to an already-released third-party service → you claim it (see Subdomain takeover).
- Open zone transfer → total enumeration.
- DNS cache poisoning / spoofing → redirect victims.
- DNS rebinding → bypass the Same-Origin Policy toward internal services.
- DNS exfiltration → extract data encoded in queries (covert channel).
Why it matters in security
Section titled “Why it matters in security”DNS is the first step of passive recon: without touching the target, you learn its mail, its cloud, its subdomains, and sometimes its internal infrastructure. And in AD, DNS locates the Domain Controllers. Mastering dig and subdomain enumeration gives you any target’s initial map.
Mastery checklist
Section titled “Mastery checklist”- I can explain hierarchical resolution and the cache’s role
- I know the record types and what each reveals
- I query A/MX/TXT/NS/SRV with dig and nslookup
- I attempt a zone transfer (AXFR)
- I enumerate subdomains (subfinder/amass/crt.sh)
- I locate an AD domain’s DCs via SRV records
- I recognize subdomain takeover, rebinding, and DNS exfiltration