DNS Infrastructure Scanner
Category: DNS
Discovers DNS listeners in a range and runs ~12 probes: capability across major RR types, multi-baseline hijack detection (vs 1.1.1.1 / 8.8.8.8 / 9.9.9.9), DNSSEC AD-bit, EDNS0, open recursion, version disclosure, NXDOMAIN rewrite, UDP→TCP fallback, ASN enrichment.
Inputs
CIDR (e.g. 203.0.113.0/24) or pasted IP list. Large ranges may require engagement scope assertion.
How to run it
- Open Security tools → DNS Infrastructure Scanner.
- Paste CIDR or IPs → run.
- Review live resolvers and risk flags (open recursor, hijack, rewrite).
Output
Per-host scorecard + flags.
Notes
- Ranges > 1024 hosts need an engagement scope assertion in-product.
Related
- /tools/dns-infra/
- /tools/dns-audit/
- /tools/port-scanner/
← Back to Security tools overview