Definition ยท Subdomain Enumeration
What is DNS Zone Transfer?
Zone transfer is the mechanism by which a secondary name server obtains a zone from a primary. A full transfer is known as AXFR; IXFR requests only the records that have changed since a given serial number. Both are legitimate and necessary parts of running DNS โ the problem is exclusively one of who is allowed to ask.
The misconfiguration
A name server that answers AXFR requests from any source discloses every record in the zone in one response: every A, CNAME, MX, and TXT entry, including internal-looking hostnames, development environments, and third-party services. Testing it takes one command:
dig AXFR example.com @ns1.example.com
A well-configured server returns a refusal. A misconfigured one returns the zone.
Why it matters for external exposure
Attackers normally have to piece a hostname list together from certificate transparency logs, passive DNS, and brute-force guessing โ all incomplete. An open zone transfer replaces that with the authoritative answer, including the names that none of those sources would have revealed. It is a single request, requires no authentication, and leaves nothing to guess.
Fixing it
Restrict transfers to the specific addresses of your secondary servers, and prefer TSIG keys so that authorisation depends on a shared secret rather than an IP address. Test every authoritative server for the zone, not just the first one listed โ a secondary left permissive is exactly as disclosing as a permissive primary.
Related concepts
Open zone transfers are checked during reconnaissance and penetration testing, and the record set they expose is the same one that subdomain enumeration and asset discovery otherwise have to reconstruct piece by piece.