DNS Explorer

Discover DNS records and subdomains from available public sources.

Advanced options

One zone-transfer attempt and up to 16 NSEC links. Refused AXFR is normal. NSEC3 hashes are not discovered hostnames.

Names are relative to your domain unless a full name within that domain is supplied. These checks do not enumerate every selector or service.

Queries use PJHTech’s resolver and public certificate search. Discovery may be incomplete. A full DNS zone is not always publicly available.

Enter a domain and choose Explore DNS.

How DNS lookup and subdomain discovery work

The initial query checks A, AAAA, CNAME, DNAME, MX, NS, SOA, TXT, CAA, HTTPS and SVCB separately. It also checks _dmarc, _mta-sts and _smtp._tls. Supplied service owners receive SRV and TLSA queries; supplied DKIM selectors receive TXT queries. ANY is not used as a zone inventory.

Discovery combines public Certificate Transparency names from crt.sh, names in DNS answers and seven common candidates: www, mail, smtp, vpn, api, dev and status. Current address checks follow the candidates. There is no separate passive-DNS-history subscription in this release. A certificate may outlive a hostname, and wildcard DNS may answer for names that were never configured individually.

Read sources and TTL correctly

Each record includes its source, query time and answer or authority section. Recursive TTLs are remaining cache lifetimes. Direct parent-side DS and extended authoritative answers are labeled separately. DNSKEY, NSEC3PARAM, DS and returned RRSIG records are available in All records and the DNSSEC filter. Unavailable parent queries are reported as incomplete, not as proof that DS is absent.

Bounded research, not a complete zone dump

One operation lasts at most 90 seconds and uses at most 240 DNS questions, 60 names and 2,000 records. Responses are bounded to 2 MiB overall. AXFR is limited to one public server, five seconds, 500 records and 1 MiB; NSEC walking stops after 16 links. PTR checks cover at most ten public addresses. External service-provider names receive limited address lookups, never recursive subdomain discovery.

The queue allows at most two active jobs per client, five starts per minute, 20 DNS Explorer starts per hour for the service and two starts per exact domain per ten minutes. Stop keeps observations already received. A limit or source failure produces a partial result. NXDOMAIN, NODATA, SERVFAIL, REFUSED and timeouts remain separate outcomes.

DNS answers use TTL-based caching; the resolver may also cache negative answers. Certificate observations are cached for up to one day. Results remain available to this browser session through the existing private job mechanism for seven days and are not indexed. Reloading does not start a new query.

Continue investigating

Match an exact TXT value · Compare public resolvers · Use dig for DNS troubleshooting

Sources

crt.sh Certificate Transparency search · DNS record format · DNSSEC validation and parent-side DS · DNS zone transfers