Skip to main content
Infrawatch passive DNS records connect a queried name to the answer observed at a point in time. Use DNS to expand an investigation beyond a current IP address or recover infrastructure from an earlier observation.

What DNS gives you

  • Forward and reverse pivots - Move from a hostname to its answers or from an IP address back to observed names.
  • Subdomain discovery - List distinct current DNS owner names below a domain without writing an InfraQL expression.
  • Observation dates - See when a relationship was first and last observed.
  • Typed records - Filter A, AAAA, CNAME, MX, NS, TXT, and other record types.
  • Modern record types - Query the newer records that carry real configuration, including HTTPS and SVCB service bindings, rather than stopping at the classic set.
  • Normalized answers - Query IP and textual answers through dedicated fields.
  • Dangling-DNS context - Identify records associated with a dangling finding.

Start an investigation

Find names observed pointing to an IP:
Find recent CNAME observations for a domain:
List current subdomains:

Pivot through passive DNS

Follow a complete domain-to-IP investigation.

Browse DNS fields

Inspect record fields, meanings, and supported operators.