DNS analysis
SkillAI & modelsDeep DNS analysis for attack surface, record mining, zone transfers, DNSSEC/NSEC walking, and dangling records. Load during recon, on "DNS", a domain in scope, or hunting takeovers/origin IPs. Signals: a root domain, CNAMEs, MX/TXT/SPF, NS servers, subdomains to resolve.
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the DNS analysis skill
What this skill tells your AI
The instructions your AI receives, as published by noorqureshi/sploitagent in skills/recon/recon-dns-analysis/SKILL.md and read by ahel’s review.
When it applies
Early recon and anytime you want surface/intel from DNS: subdomains, mail/infra hints, cloud providers, dangling records (takeover leads), and origin IPs hiding behind a CDN.
Why it works
DNS is a public map of an org's infrastructure. Records leak providers (CNAME → SaaS), mail and SPF/DMARC hosts, and misconfigurations (open zone transfer dumps everything; NSEC lets you walk a DNSSEC zone). Stale records point at deprovisioned services (→ takeover).
Method
- Enumerate records:
dig ANY domain, plus explicitA AAAA CNAME MX TXT NS SOA— TXT/SPF reveal third parties; MX reveals mail infra. - Zone transfer (rare but total): find NS (
dig NS domain), thendig axfr @ns1 domain— a successful AXFR dumps every record. - DNSSEC walking: if NSEC is used, walk the chain to enumerate names (
dnsrecon -t zonewalk). - Dangling / takeover leads: resolve CNAMEs; ones pointing at unclaimed SaaS →
web-subdomain-takeover. - Origin discovery: historical DNS (SecurityTrails), SPF-listed IPs, and cert SANs can reveal the real origin behind a CDN (bypass the WAF later).
Gotchas
- AXFR is usually refused — but when it works it's the whole zone; always try the NS servers.
- CDN/proxied records hide the origin; pivot to cert/historical data, not the proxied A record.
- Wildcard DNS inflates brute-force — detect and filter it (
dnsxwildcard handling).
Verify success
A richer map: resolvable subdomains, provider/infra hints, any AXFR/NSEC dump, and takeover or origin-IP leads to hand to the next skill.
References
dig/dnsrecon docs; SecurityTrails; OWASP Amass; can-i-take-over-xyz.
Signals
- GitHub stars
- 20
- Forks
- 7
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
recon-dns-analysis- Source
- github.com/noorqureshi/sploitagent
github.com/noorqureshi/sploitagent
Related picks
Skill · microsoft
The pick for Infrahttp-to-https
Skill · thedaviddias
The pick for Infraowasp-security
Skill · davila7
The pick for Web (OWASP)owasp-web
Skill · nahid-sparktales
The pick for Web (OWASP)skill-creator
Skill · anthropics
More in AI & modelswayfinder
Skill · mattpocock
More in AI & models