A passive domain-intelligence hub - DNS, email-auth, DNSSEC, registration and per-IP exposure (ASN, ports, CVEs) in one pass.
DNS Recon Pro is a one-shot domain-intelligence hub. From a single domain it gathers the DNS records, resolves the full CNAME chain, scores mail authentication (SPF/DMARC/DKIM), checks DNSSEC and CAA, fingerprints the DNS/mail provider, and detects wildcard DNS.
It then enriches every resolved IP with passive exposure data - ASN/owner/country (Team Cymru), plus open ports and known CVEs (Shodan InternetDB) - and pulls the domain’s registration (registrar, creation/expiry, transfer-lock) over RDAP. A zone-transfer (AXFR) test and an on-demand Certificate-Transparency hostname pull round it out.
Everything is sourced passively from third-party APIs (no scan is sent to the target); only the AXFR test connects directly to the zone’s own name servers. Findings are ranked Critical → Info with context.
It means a name server will hand over the full DNS zone to anyone who asks - a serious information-disclosure issue that maps your entire infrastructure.
From Shodan’s InternetDB (free, passive) keyed on each resolved IP - it reports what Shodan already observed, so nothing is scanned or sent to your target. ASN/owner/country come from Team Cymru over DNS.
Without a strong DMARC policy, attackers can spoof email from the domain. The tool tells you whether the policy actually enforces (reject/quarantine) or is only monitoring.