DNS Zone Transfer (AXFR), PTR & Subdomain Recon Builder (2026)

Build RFC 5936 AXFR/IXFR zone transfer tests, parse leaked BIND zone files for internal RFC 1918 subnets and dangling CNAME takeover risks, and generate TSIG-hardened `named.conf` / NSD policies.

DNS Zone Transfer (AXFR), PTR & Subdomain Recon Builder — Interactive Console
Runs locally in your browser • Instant output
DNS AXFR & Subdomain Recon Commands
# 1. Enumerate Authoritative Nameservers & SOA Serial
dig +short NS megacorpone.com
dig +short SOA megacorpone.com

# 2. Test Full DNS Zone Transfer (AXFR) over TCP/53
dig @ns1.megacorpone.com megacorpone.com AXFR
host -t axfr megacorpone.com ns1.megacorpone.com

# 3. Automated AXFR, NSEC Zone Walking & Brute-Force Recon
dnsrecon -d megacorpone.com -t axfr
fierce --domain megacorpone.com
subfinder -d megacorpone.com -silent | dnsx -a -resp

# 4. Reverse PTR Subnet Sweep (192.0.2.0/24)
dnsrecon -r 192.0.2.0/24 -n ns1.megacorpone.com
Hardened BIND TSIG & `allow-transfer` Remediation
// Hardened ISC BIND /etc/bind/named.conf.options
options {
    // Block unauthorized AXFR zone dumps globally
    allow-transfer { none; };
    allow-query-cache { none; };
    recursion no;
    version "not disclosed";
};

// Restrict zone transfers strictly to secondary NS with TSIG cryptographic key
zone "megacorpone.com" {
    type master;
    file "/etc/bind/db.megacorpone.com";
    allow-transfer { key "tsig-secondary-ns-key"; };
};
Ready
Embed / Cite This Tool (Markdown & HTML)
GitHub / Reddit Markdown Badge[![DNS Zone Transfer (AXFR), PTR & Subdomain Recon Builder](https://img.shields.io/badge/ZerosUniverse-Free_Tool-ff6a00)](https://www.zerosuniverse.com/tools/dns-zone-transfer-axfr-recon-builder/)
Blog / Documentation HTML Citation<a href="https://www.zerosuniverse.com/tools/dns-zone-transfer-axfr-recon-builder/">DNS Zone Transfer (AXFR), PTR & Subdomain Recon Builder — ZerosUniverse</a>

2026 Quick-Reference Cheat Sheet & Benchmark Table: DNS Zone Transfer (AXFR), PTR & Subdomain Recon Builder

Quick Answer & 2026 Technical Summary (dns zone transfer axfr dig command generator)Updated 2026 Standard

Standard DNS lookups fit inside compact UDP datagrams (512 bytes classically, or up to 4096 bytes with EDNS0). A full zone transfer (`AXFR`, RFC 5936) replicates thousands of resource records across authoritative servers and requires reliable, ordered delivery with congestion control over TCP port 53. Use this interactive dns zone transfer axfr dig command generator above to test dig axfr dns enumeration command builder, bind allow-transfer tsig hardening config, and parse axfr zone dump internal ip leak locally in your browser with zero server uploads.

Target Keyword Spec: dns zone transfer axfr dig command generator | Modules: Interactive `dig`, `host`, `dnsrecon` & `fierce` Command Studio • Live AXFR Zone Dump Parser & Internal IP Leak Detector • Dangling CNAME Subdomain Takeover & SRV Service Mapper
Primary Focus: dns zone transfer axfr dig command generator
Core Capability: dig axfr dns enumeration command builder
Privacy Mode: 100% Client-Side (Zero Upload)
Technical Parameter / ModuleStandard / Keyword SpecArchitecture & Validation RuleOperational Use Case (2026)
Interactive `dig`, `host`, `dnsrecon` & `fierce` Command Studiodig axfr dns enumeration command builderGenerate one-liner bash pipelines that enumerate authoritative `NS` records...Authorized External Attack Surface & Pentest Reconnaissance
Live AXFR Zone Dump Parser & Internal IP Leak Detectorbind allow-transfer tsig hardening configPaste raw `dig axfr` output to automatically extract `SOA` serials, interna...Auditing Split-Horizon DNS & RFC 1918 Internal IP Leakage
Dangling CNAME Subdomain Takeover & SRV Service Mapperparse axfr zone dump internal ip leakHighlight third-party CNAME targets (`.s3.amazonaws.com`, `.azurewebsites.n...Securing Primary-to-Secondary DNS Replication with TSIG
Execution & Privacy Architecture100% Client-Side WebCrypto / JS Sandbox0 Bytes Sent to External ServersSafe for internal SOC & authorized lab artifacts
NIST SP 800-53 / OWASP AlignmentOWASP ASVS v4.0.3 / NIST CSF 2.0Deterministic Rule & Header VerificationMaps findings to actionable hardening controls
Cryptographic & Entropy StandardSHA-256 / AES-256-GCM / Argon2id≥ 128-bit Effective Security MarginMeets 2026 post-quantum & zero-trust baselines
In-Depth ZerosUniverse Tutorial

What is DNS Enumeration & Zone Transfer Hardening?

Read our complete step-by-step editorial guide, architecture breakdown, and defensive best practices on ZerosUniverse.

Read Full Guide

How to Use DNS Zone Transfer (AXFR), PTR & Subdomain Recon Builder

01

Enter Target Domain & Authoritative Nameserver (or Load Sample)

Input your target domain (`example.com`), optional authoritative NS host, and internal CIDR block to generate tailored enumeration commands.

02

Copy Multi-Tool DNS Recon Commands (`dig`, `nmap`, `dnsrecon`)

Select from AXFR Zone Transfer, Reverse PTR Sweep, Active Directory SRV Enumeration, or DNSSEC NSEC Walk command templates.

03

Paste `dig axfr` Output into the Live Zone Analyzer

Run the analyzer on a real or sample zone dump to categorize record types, flag internal private IPs, and spot dev/staging hosts.

04

Deploy the Generated BIND 9 / PowerDNS Hardening Config

Copy the `allow-transfer` ACL and `tsig-key` configuration block into `/etc/bind/named.conf.options` to block unauthorized zone transfers.

Key Capabilities & Technical Architecture

Interactive `dig`, `host`, `dnsrecon` & `fierce` Command Studio

Generate one-liner bash pipelines that enumerate authoritative `NS` records first and test TCP port 53 `AXFR` / `IXFR` transfers against every nameserver.

Live AXFR Zone Dump Parser & Internal IP Leak Detector

Paste raw `dig axfr` output to automatically extract `SOA` serials, internal RFC 1918 (`10.x`, `172.16.x`, `192.168.x`) `A` records, `TXT` secrets, and staging hosts.

Dangling CNAME Subdomain Takeover & SRV Service Mapper

Highlight third-party CNAME targets (`.s3.amazonaws.com`, `.azurewebsites.net`, `.github.io`) and Active Directory `_ldap._tcp.dc._msdcs` SRV records.

BIND 9, PowerDNS & Knot TSIG `allow-transfer` Hardener

Produce production-ready `named.conf` ACLs with `allow-transfer { none; };` or HMAC-SHA256 TSIG key authentication for secondary nameservers.

Practical Use Cases

Authorized External Attack Surface & Pentest Reconnaissance

Test whether forgotten secondary authoritative nameservers (`ns2`, `ns3`) still permit unauthenticated TCP/53 AXFR dumps of the entire corporate DNS zone.

Auditing Split-Horizon DNS & RFC 1918 Internal IP Leakage

Scan exported zone files to ensure internal VPN gateways, Jenkins build nodes, and private `10.0.0.0/8` addresses are not published on public DNS.

Securing Primary-to-Secondary DNS Replication with TSIG

Replace IP-only `allow-transfer` rules with cryptographic HMAC-SHA256 Transaction Signatures (TSIG) across BIND 9 and PowerDNS clusters.

Frequently Asked Questions (FAQs)

Why does DNS Zone Transfer (`AXFR`) use TCP port 53 instead of UDP port 53?+

Standard DNS lookups fit inside compact UDP datagrams (512 bytes classically, or up to 4096 bytes with EDNS0). A full zone transfer (`AXFR`, RFC 5936) replicates thousands of resource records across authoritative servers and requires reliable, ordered delivery with congestion control over TCP port 53.

Why should pentesters test EVERY `NS` record for AXFR instead of just `ns1`?+

Organizations frequently lock down their primary nameserver (`ns1`) with `allow-transfer { secondary_ips; };`, but forget to apply the same ACL on secondary or backup regional nameservers (`ns2`, `ns3`, or ISP-hosted slave servers), leaving the secondary server wide open to public AXFR queries.

What does `Transfer failed.` vs `connection timed out` mean in `dig axfr`?+

`Transfer failed.` (or `REFUSED` in the DNS header status) means your TCP port 53 packet reached the nameserver, and the DNS daemon's ACL actively rejected the AXFR request. `connection timed out; no servers could be reached` typically means a perimeter firewall is dropping inbound TCP port 53 traffic while allowing UDP port 53.

How does DNSSEC `NSEC` vs `NSEC3` affect zone enumeration?+

Classic DNSSEC `NSEC` (Next Secure) records prove a subdomain does not exist by returning the alphabetically next valid hostname in plaintext (`alpha.example.com -> beta.example.com`), allowing an attacker to 'walk' the entire zone without AXFR. `NSEC3` (RFC 5155) mitigates trivial zone walking by hashing owner names with salt and iterations, though `NSEC3` white lies or compact denial of existence (RFC 9824) are preferred to prevent offline GPU hash cracking.

Why is IP-based `allow-transfer` alone insufficient without TSIG?+

Relying solely on source IP whitelisting in `allow-transfer` can be bypassed via BGP hijacking, shared cloud VPC IP reuse, or internal SSRF on the same subnet. Pairing IP ACLs with HMAC-SHA256 TSIG (`Transaction SIGnature`, RFC 8945) cryptographically authenticates every zone transfer request and response.