Lesson 1 of 1 in dig
What a Zone Gives Away
Record types, what each one is for, and why the answers you get for free are the start of most engagements.
2 min read
Not yet reviewed
DNS is a public database that answers anybody. Before touching a target at all, you can learn where its mail goes, which provider hosts it, what it has published about who may send on its behalf, and often the names of internal-sounding services somebody forgot were public.
The record types worth knowing
A / AAAA the address a name resolves to
MX where mail for this domain goes
NS which servers are authoritative for the zone
TXT anything at all - and in practice, policy
CNAME this name is really that name
- Line 2Frequently a third party, which tells you who handles their mail before you have sent a packet to them.
- Line 3Delegation. If the NS records point somewhere unexpected, part of this domain is run by somebody other than whoever runs the website.
- Line 4SPF, DKIM and DMARC live here, and so do domain-verification strings from every service the organisation has ever signed up to. That list is an inventory of their vendors, published deliberately and read rarely.
- Line 5The one that leaks by accident. A CNAME pointing at a service that no longer exists is a dangling record, and dangling records are how subdomain takeover happens.
Note
None of this is intrusion. Every one of those answers is published on purpose, by design, to anyone who asks. That is what makes DNS the first thing anybody looks at and the last thing anybody audits.
Trying it
Look up the TXT records for brightpath.example. One of them names a third-party service the organisation uses. Print the records.
What it looks like from the other side
Almost nothing. A DNS query goes to a resolver, and the target's own servers may never see it — the answer is very likely cached somewhere in between. This is the quietest reconnaissance there is, which is precisely why it is the first step.
Take care
The defensive move is not detection, because there is nothing reliable to detect. It is auditing what you publish: review your TXT records for services you no longer use, and your CNAMEs for names pointing at infrastructure you no longer own.
Why is a CNAME pointing at a decommissioned service dangerous?