Pentestas / help

DNS Infrastructure Scanner

DNS Infrastructure Scanner — Sweep a CIDR or IP list for live DNS servers and score each responder.
DNS Infrastructure Scanner in the Pentestas Security tools UI.

Category: DNS

Discovers DNS listeners in a range and runs ~12 probes: capability across major RR types, multi-baseline hijack detection (vs 1.1.1.1 / 8.8.8.8 / 9.9.9.9), DNSSEC AD-bit, EDNS0, open recursion, version disclosure, NXDOMAIN rewrite, UDP→TCP fallback, ASN enrichment.

Inputs

CIDR (e.g. 203.0.113.0/24) or pasted IP list. Large ranges may require engagement scope assertion.

How to run it

  1. Open Security tools → DNS Infrastructure Scanner.
  2. Paste CIDR or IPs → run.
  3. Review live resolvers and risk flags (open recursor, hijack, rewrite).

Output

Per-host scorecard + flags.

Notes

  • Ranges > 1024 hosts need an engagement scope assertion in-product.
  • /tools/dns-infra/
  • /tools/dns-audit/
  • /tools/port-scanner/

← Back to Security tools overview