Definition · Subdomain Enumeration
What is Reverse DNS?
A forward lookup turns a name into an address. Reverse DNS does the opposite, using PTR records published in special zones: in-addr.arpa for IPv4 and ip6.arpa for IPv6. The address is written backwards in the query, so 198.51.100.10 is looked up as 10.100.51.198.in-addr.arpa.
Who controls the records
PTR records are delegated with the IP space, which means the network operator publishes them — not the owner of the domain name. If you use a hosting provider, your reverse records are theirs to set unless they offer delegation, and this asymmetry is why forward and reverse records so often disagree.
Why it matters for external exposure
Reverse DNS is a cheap enumeration technique. Sweeping a netblock’s PTR records can reveal naming conventions, host roles, and internal-sounding names that no certificate log or web crawl would show — entries like vpn-test-02 or legacy-billing are informative to an attacker in exactly the way they are convenient to an administrator. When an organisation owns its own address space, a reverse sweep is one of the fastest ways to sketch its estate.
Where it is operationally required
Mail is the main case. Receiving servers commonly check that a sending IP address has a PTR record and that the name it returns resolves back to the same address — so-called forward-confirmed reverse DNS. Missing or generic reverse records on a sending host are a routine cause of delivery problems, independent of SPF and DKIM.
Related concepts
Reverse DNS is used alongside passive DNS and WHOIS during reconnaissance, feeds asset discovery across owned netblocks, and matters for the mail hosts named in your MX records.