10 July 2008 | 13,570 views

DNSenum – Domain Information Gathering Tool

Don't let your data go over to the Dark Side!

The first stage of penetration testing is usually passive information gathering and enumeration (active information gathering). This is where tools like dnsenum come in, the purpose of DNSenum is to gather as much information as possible about a domain.

The program currently performs the following operations:

  1. Get the host’s addresse (A record).
  2. Get the namservers (threaded).
  3. Get the MX record (threaded).
  4. Perform axfr queries on nameservers (threaded).
  5. Get extra names and subdomains via google scraping (google query = “allinurl: -www site:domain”).
  6. Brute force subdomains from file, can also perform recursion on subdomain that have NS records (all threaded).
  7. Calculate C class domain network ranges and perform whois queries on them (threaded).
  8. Perform reverse lookups on netranges ( C class or/and whois netranges) (threaded).
  9. Write to domain_ips.txt file ip-blocks.

The output file domain_ips.txt will contain non-contiguous IP blocks:

You can download DNSenum v1.2 here:


Or you can read more here.


Recent in Hacking Tools:
- RWMC – Retrieve Windows Credentials With PowerShell
- MITMf – Man-In-The-Middle Attack Framework
- LaZagne – Password Recovery Tool For Windows & Linux

Related Posts:
- InstaRecon – Automated Subdomain Discovery Tool
- Complemento v0.4b – LetDown TCP Flooder, ReverseRaider Subdomain Scanner & Httsquash HTTP Server Scanner Tool
- dnsmap 0.22 Released – Subdomain Bruteforcing Tool

Most Read in Hacking Tools:
- Top 15 Security/Hacking Tools & Utilities - 1,954,429 views
- Brutus Password Cracker – Download brutus-aet2.zip AET2 - 1,332,808 views
- wwwhack 1.9 – Download wwwhack19.zip Web Hacking Tool - 665,959 views

Low-cost VPS Hosting

5 Responses to “DNSenum – Domain Information Gathering Tool”

  1. Glenn 10 July 2008 at 10:15 am Permalink

    Where do i get the Net::IP modules for windows installations , as i have to use windows box at work , thanks .

  2. Changlinn 11 July 2008 at 1:45 am Permalink

    This is all good and well, but isn’t it better to learn how to do this manually. A little nslookup/dig ping -a and http://www.onsamehost.com
    and some google hacking and you are done, and much richer for the experience.

  3. Pantagruel 11 July 2008 at 10:50 am Permalink


    Even pen testers get lazy, we also like the get as much info possible by using as little as tools possible.

    But I guess most of us already have written a script to get these details.

  4. Darknet 11 July 2008 at 10:52 am Permalink

    Yah I was gonna say why not look at it the other way? I know exactly how to do it and all the steps…why not use a tool that can automate it. It’s like saying don’t use Nessus or any VA scanner…manually test each machine on the network, each open port and each service. Hell why use nmap or any port scanner? Just manually craft the packets to send to each port with hping and listen for the results with wireshark.

  5. d347hm4n 15 July 2008 at 9:14 am Permalink

    @Glenn use it in a vm, then you wil have the linux net::ip modules