Arsenly
Tools
Free Tools
Pricing
Resources
Sign in Get started
← All tools

DNS Recon Pro

Recon & Discovery

A passive domain-intelligence hub - DNS, email-auth, DNSSEC, registration and per-IP exposure (ASN, ports, CVEs) in one pass.

What is DNS Recon Pro?

DNS Recon Pro is a one-shot domain-intelligence hub. From a single domain it gathers the DNS records, resolves the full CNAME chain, scores mail authentication (SPF/DMARC/DKIM), checks DNSSEC and CAA, fingerprints the DNS/mail provider, and detects wildcard DNS.

It then enriches every resolved IP with passive exposure data - ASN/owner/country (Team Cymru), plus open ports and known CVEs (Shodan InternetDB) - and pulls the domain’s registration (registrar, creation/expiry, transfer-lock) over RDAP. A zone-transfer (AXFR) test and an on-demand Certificate-Transparency hostname pull round it out.

Everything is sourced passively from third-party APIs (no scan is sent to the target); only the AXFR test connects directly to the zone’s own name servers. Findings are ranked Critical → Info with context.

What it gathers

  • DNS records + CNAME chain - A/AAAA/MX/NS/TXT/SOA/CAA and the full CNAME resolution path.
  • Email auth - parses SPF (+all/?all/soft-fail/10-lookup limit), DMARC policy & reporting, and DKIM selectors.
  • DNSSEC & CAA - DS/DNSKEY + validating (AD) flag, and CA issuance restrictions.
  • IP intelligence - per resolved IP: ASN / owner / country plus open ports and known CVEs.
  • Registration (RDAP) - registrar, creation/expiry dates, domain age and transfer-lock.
  • AXFR (zone transfer) - attempts a transfer that would leak the entire zone.
  • Provider, wildcard & dangling CNAME - infra fingerprint and takeover signals.
  • CT-log hostnames - on-demand subdomain preview from Certificate Transparency.

Where it fits in your workflow

  • Get a complete passive picture of a domain before going hands-on.
  • Find email-spoofing, zone-leak and exposed-service issues for a report.
  • Spot takeover candidates and expiring/abandoned domains during recon.
Use DNS Recon Pro

Run it from your dashboard.

Create free account Sign in Use via API

At a glance

CategoryRecon & Discovery
RunsServer-side
Token cost 5 / run (free tier)
Access Pro
Status● Live

Frequently asked questions

What does an open AXFR mean?

It means a name server will hand over the full DNS zone to anyone who asks - a serious information-disclosure issue that maps your entire infrastructure.

Where do the open ports and CVEs come from?

From Shodan’s InternetDB (free, passive) keyed on each resolved IP - it reports what Shodan already observed, so nothing is scanned or sent to your target. ASN/owner/country come from Team Cymru over DNS.

Why does DMARC matter?

Without a strong DMARC policy, attackers can spoof email from the domain. The tool tells you whether the policy actually enforces (reject/quarantine) or is only monitoring.

Explore more tools →