Definition ยท Subdomain Enumeration

What is DNS Zone Transfer?

Zone transfer is the mechanism by which a secondary name server obtains a zone from a primary. A full transfer is known as AXFR; IXFR requests only the records that have changed since a given serial number. Both are legitimate and necessary parts of running DNS โ€” the problem is exclusively one of who is allowed to ask.

The misconfiguration

A name server that answers AXFR requests from any source discloses every record in the zone in one response: every A, CNAME, MX, and TXT entry, including internal-looking hostnames, development environments, and third-party services. Testing it takes one command:

dig AXFR example.com @ns1.example.com

A well-configured server returns a refusal. A misconfigured one returns the zone.

Why it matters for external exposure

Attackers normally have to piece a hostname list together from certificate transparency logs, passive DNS, and brute-force guessing โ€” all incomplete. An open zone transfer replaces that with the authoritative answer, including the names that none of those sources would have revealed. It is a single request, requires no authentication, and leaves nothing to guess.

Fixing it

Restrict transfers to the specific addresses of your secondary servers, and prefer TSIG keys so that authorisation depends on a shared secret rather than an IP address. Test every authoritative server for the zone, not just the first one listed โ€” a secondary left permissive is exactly as disclosing as a permissive primary.

Open zone transfers are checked during reconnaissance and penetration testing, and the record set they expose is the same one that subdomain enumeration and asset discovery otherwise have to reconstruct piece by piece.

See what your business is exposing

SurfaceLoop checks every internet-facing asset you own across seven risk categories, daily.