Definition · Subdomain Enumeration

What is Passive DNS?

The DNS itself has no memory: query a name today and you learn only where it points now. Passive DNS fills that gap. Operators of resolvers and network sensors record the answers they observe and publish them as a searchable history, so an analyst can ask which hostnames have ever resolved to a given IP address, or which addresses a hostname has used in the past.

What it is used for

  • Subdomain discovery — finding names that were never in your inventory, including ones that no longer resolve
  • Infrastructure pivoting — taking one known IP address and finding every other hostname that has pointed at it
  • Incident investigation — establishing where a domain was hosted at the time of an event
  • Change detection — noticing that a hostname has moved to a new provider

Why it matters for external exposure

Passive DNS is one of the reasons an attacker can find hosts you have forgotten. A staging subdomain that resolved for three weeks in 2021 may still be recorded, and if the underlying DNS record survives without the resource behind it, that history is a shortlist of subdomain takeover candidates. Pivoting on shared IP addresses also reveals infrastructure you never publicised, because it was co-hosted with something you did.

Limitations

Coverage is uneven and depends on whose sensors saw the traffic. Absence of a record proves nothing, timestamps indicate observation rather than creation, and different providers hold different slices of history. Passive DNS is a lead generator, not an authoritative inventory — findings need confirming with live resolution.

Passive DNS is a core OSINT source used during reconnaissance, sits alongside reverse DNS and certificate transparency logs as a way to enumerate names, and helps surface dangling DNS records during subdomain enumeration.

See what your business is exposing

SurfaceLoop checks every internet-facing asset you own across seven risk categories, daily.