DNS Explorer
Discover DNS records and subdomains from available public sources.
Enter a domain and choose Explore DNS.
Discovered names
Sources and coverage
Query diagnostics
DNS record text
Collected positive domain records, not a complete authoritative zone file. JSON preserves all observations, including negative-answer evidence.
How DNS lookup and subdomain discovery work
The initial query checks A, AAAA, CNAME, DNAME, MX, NS, SOA, TXT, CAA, HTTPS and SVCB separately. It also checks _dmarc, _mta-sts and _smtp._tls. Supplied service owners receive SRV and TLSA queries; supplied DKIM selectors receive TXT queries. ANY is not used as a zone inventory.
Discovery combines public Certificate Transparency names from crt.sh, names in DNS answers and seven common candidates: www, mail, smtp, vpn, api, dev and status. Current address checks follow the candidates. There is no separate passive-DNS-history subscription in this release. A certificate may outlive a hostname, and wildcard DNS may answer for names that were never configured individually.
Read sources and TTL correctly
Each record includes its source, query time and answer or authority section. Recursive TTLs are remaining cache lifetimes. Direct parent-side DS and extended authoritative answers are labeled separately. DNSKEY, NSEC3PARAM, DS and returned RRSIG records are available in All records and the DNSSEC filter. Unavailable parent queries are reported as incomplete, not as proof that DS is absent.
Bounded research, not a complete zone dump
One operation lasts at most 90 seconds and uses at most 240 DNS questions, 60 names and 2,000 records. Responses are bounded to 2 MiB overall. AXFR is limited to one public server, five seconds, 500 records and 1 MiB; NSEC walking stops after 16 links. PTR checks cover at most ten public addresses. External service-provider names receive limited address lookups, never recursive subdomain discovery.
The queue allows at most two active jobs per client, five starts per minute, 20 DNS Explorer starts per hour for the service and two starts per exact domain per ten minutes. Stop keeps observations already received. A limit or source failure produces a partial result. NXDOMAIN, NODATA, SERVFAIL, REFUSED and timeouts remain separate outcomes.
DNS answers use TTL-based caching; the resolver may also cache negative answers. Certificate observations are cached for up to one day. Results remain available to this browser session through the existing private job mechanism for seven days and are not indexed. Reloading does not start a new query.
Continue investigating
Match an exact TXT value · Compare public resolvers · Use dig for DNS troubleshooting
Sources
crt.sh Certificate Transparency search · DNS record format · DNSSEC validation and parent-side DS · DNS zone transfers