Definition · Subdomain Enumeration
What is Passive DNS?
The DNS itself has no memory: query a name today and you learn only where it points now. Passive DNS fills that gap. Operators of resolvers and network sensors record the answers they observe and publish them as a searchable history, so an analyst can ask which hostnames have ever resolved to a given IP address, or which addresses a hostname has used in the past.
What it is used for
- Subdomain discovery — finding names that were never in your inventory, including ones that no longer resolve
- Infrastructure pivoting — taking one known IP address and finding every other hostname that has pointed at it
- Incident investigation — establishing where a domain was hosted at the time of an event
- Change detection — noticing that a hostname has moved to a new provider
Why it matters for external exposure
Passive DNS is one of the reasons an attacker can find hosts you have forgotten. A staging subdomain that resolved for three weeks in 2021 may still be recorded, and if the underlying DNS record survives without the resource behind it, that history is a shortlist of subdomain takeover candidates. Pivoting on shared IP addresses also reveals infrastructure you never publicised, because it was co-hosted with something you did.
Limitations
Coverage is uneven and depends on whose sensors saw the traffic. Absence of a record proves nothing, timestamps indicate observation rather than creation, and different providers hold different slices of history. Passive DNS is a lead generator, not an authoritative inventory — findings need confirming with live resolution.
Related concepts
Passive DNS is a core OSINT source used during reconnaissance, sits alongside reverse DNS and certificate transparency logs as a way to enumerate names, and helps surface dangling DNS records during subdomain enumeration.