Skip to content

DNS Fundamentals

DNS translates names (target.com) to IP addresses. It sounds boring, but it’s one of the richest reconnaissance sources there is: an organization’s DNS records reveal its mail servers, subdomains, cloud providers, leaked internal infrastructure, and much more. Almost every pentest starts with DNS, and several attacks (poisoning, subdomain takeover, rebinding) live here.

When you request www.target.com, your resolver asks in a chain: root → TLD (.com) → target.com’s authoritative server → IP. That hierarchy and the cache along the way are the basis of several attacks.

A name -> IPv4 AAAA name -> IPv6
CNAME alias of another name (key in subdomain takeover)
MX mail servers (who runs the email: Google, O365...)
NS authoritative name servers
TXT free text: SPF, DKIM, DMARC, verifications (lots of info!)
SOA zone data PTR IP -> name (reverse DNS)
SRV services (in AD: _ldap._tcp.dc._msdcs -> locates DCs)

TXT records leak providers (SaaS the company uses), MX the mail, CNAME point to third-party services (takeover-able), and SRV in AD locate the Domain Controllers.

dig target.com A ; dig target.com MX ; dig target.com TXT ; dig target.com NS
dig +short target.com
nslookup -type=any target.com
host target.com
# reverse DNS
dig -x 1.2.3.4
# locate an AD domain's DCs
nslookup -type=srv _ldap._tcp.dc._msdcs.domain.local

Subdomains are surface: dev., staging., vpn., mail., admin. Each is a possible door (see Subdomain Enumeration).

# zone transfer (if misconfigured, gives you EVERYTHING)
dig axfr @ns1.target.com target.com
# brute force / passive
subfinder -d target.com ; amass enum -d target.com
# Certificate Transparency (subdomains via certificates)
curl -s "https://crt.sh/?q=%25.target.com&output=json"

A misconfigured zone transfer (AXFR) hands over the whole zone — a classic finding.

  • Subdomain takeover: a CNAME points to an already-released third-party service → you claim it (see Subdomain takeover).
  • Open zone transfer → total enumeration.
  • DNS cache poisoning / spoofing → redirect victims.
  • DNS rebinding → bypass the Same-Origin Policy toward internal services.
  • DNS exfiltration → extract data encoded in queries (covert channel).

DNS is the first step of passive recon: without touching the target, you learn its mail, its cloud, its subdomains, and sometimes its internal infrastructure. And in AD, DNS locates the Domain Controllers. Mastering dig and subdomain enumeration gives you any target’s initial map.

  • I can explain hierarchical resolution and the cache’s role
  • I know the record types and what each reveals
  • I query A/MX/TXT/NS/SRV with dig and nslookup
  • I attempt a zone transfer (AXFR)
  • I enumerate subdomains (subfinder/amass/crt.sh)
  • I locate an AD domain’s DCs via SRV records
  • I recognize subdomain takeover, rebinding, and DNS exfiltration