Input parameters below and click on the Update button to have commands dynamically updated.
WHOIS & Domain Enumeration
Basic WHOIS Lookup
Command-Line WHOIS
Basic domain WHOIS lookup
whois $ipQuery a specific WHOIS server
whois -h whois.verisign-grs.com $ipShow detailed results (Linux)
whois --verbose $ipOnline WHOIS Services
Extracting Nameservers & DNS Records
Query Nameservers
nslookup -type=NS $ipdig NS $iphost -t ns $ipQuery MX Records (Mail Servers)
nslookup -type=MX $ipdig MX $iphost -t mx $ipQuery TXT Records (SPF, DKIM, DMARC, etc.)
nslookup -type=TXT $ipdig TXT $iphost -t txt $ipSubdomain Enumeration
Brute-Force Subdomains
sublist3r -d $ipamass enum -d $ipassetfinder --subs-only $ipdnsrecon -d $ip -t brtPassive Subdomain Enumeration
crt.sh → Certificate Transparency logs
ThreatCrowd → OSINT subdomain lookup
VirusTotal → Find subdomains via DNS queries
Zone Transfer (AXFR Attack Check)
Try Zone Transfer (If Misconfigured)
dig AXFR example.com @ns1.$iphost -l example.com ns1.$ipdnsrecon -d $ip -t axfrReverse DNS Lookup
Find Domain Associated with an IP
nslookup $ipdig -x $iphost $ipFind Subdomains via Reverse Lookups
dnsrecon -r 192.168.1.0/24fierce -dns $ipUse DNS module for reverse lookups
recon-ngOnline DNS & WHOIS Tools
SecurityTrails → Historical DNS records
Spyse → Advanced domain intelligence
Robtex → DNS & network graphing
ViewDNS.info → DNS & WHOIS lookup tools
Automation & OSINT Tools for Domain Intelligence
theHarvester → Email, subdomains, and hosts reconnaissance
Subfinder → Fast passive subdomain discovery
Amass → OSINT-powered subdomain enumeration
MassDNS → High-performance DNS resolver
Nmap → Scan domains for open services
nmap -p80,443 $ip