dnsrecon: Comprehensive DNS Enumeration Tool

dnsrecon is a powerful Python-based tool for extensive DNS reconnaissance. It’s designed to gather information about all types of DNS records for a given domain, identify common DNS misconfigurations, and help uncover potential attack surfaces. DNS reconnaissance is a critical step in any penetration test or security assessment.

Basic Usage: Host Enumeration with Brute-Force

This command attempts to brute-force common hostnames (like www, mail, ftp, etc.) for a domain using a provided dictionary file.

dnsrecon -t brt -D SecLists/Discovery/DNS/namelist.txt -d <target-domain.com>
# Example:
dnsrecon -t brt -D SecLists/Discovery/DNS/namelist.txt -d example.com

Command Breakdown:

  • dnsrecon: Invokes the dnsrecon tool.
  • -t brt: Specifies the type of enumeration to perform, in this case, brt for brute-force host enumeration.
  • -D SecLists/Discovery/DNS/namelist.txt: Specifies the dictionary file (namelist.txt from SecLists) containing a list of common hostnames to try.
  • -d <target-domain.com>: The target domain for which to perform the reconnaissance.

Other Useful dnsrecon Options

  • Standard Enumeration (-t std): Performs a standard enumeration that includes SOA, NS, A, AAAA, MX, and SRV records.

    dnsrecon -t std -d <target-domain.com>
  • Zone Transfer Attempt (-t axfr): Attempts to perform a full zone transfer (AXFR) from the domain’s name servers. A successful zone transfer indicates a serious misconfiguration.

    dnsrecon -t axfr -d <target-domain.com>
  • Google Search for Subdomains (-t goo): Uses Google to search for subdomains.

    dnsrecon -t goo -d <target-domain.com>
  • Reverse Lookup (-r): Performs a reverse lookup of a given IP range.

    dnsrecon -r <ip-range> -d <target-domain.com>
    # Example: dnsrecon -r 192.168.1.0/24 -d example.com
  • Using a Specific Name Server (-n): Specify a custom DNS server to query instead of the default.

    dnsrecon -t std -d <target-domain.com> -n <nameserver_ip>
    # Example: dnsrecon -t std -d example.com -n 8.8.8.8

Disclaimer: DNS reconnaissance should only be performed on systems for which you have explicit, written permission. Unauthorized scanning and enumeration of networks are illegal and unethical. This documentation is for educational and authorized security testing purposes only.