← All cheat sheets

DNSWALK

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

dnswalk is a DNS debugger that performs zone transfers and checks
DNS zones for internal consistency. It verifies that records are
properly configured and identifies common DNS misconfigurations.

BASIC USAGE#

dnswalk <domain>.                # Check DNS zone (trailing dot required)
dnswalk -r <domain>.             # Recursive check of subdomains
dnswalk -f <domain>.             # Force zone transfer (no check for SOA)

OPTIONS#

dnswalk -r <domain>.             # Recursively check subdomains
dnswalk -a <domain>.             # Turn on warning for duplicate A records
dnswalk -d <domain>.             # Debug mode (print DNS queries)
dnswalk -F <domain>.             # Perform "fascist" checks (extra strict)
dnswalk -i <domain>.             # Suppress check for invalid characters
dnswalk -l <domain>.             # Check lame delegations
dnswalk -m <domain>.             # Check for missing reverse (PTR) records

CHECKS PERFORMED#

# dnswalk automatically checks for:
# - Lame delegations
# - Duplicate A records
# - Missing reverse (PTR) records
# - Invalid characters in hostnames
# - MX records pointing to CNAME
# - NS records pointing to CNAME
# - Unreachable nameservers
# - SOA serial number issues
# - Orphaned glue records
# - Missing A records for NS/MX entries

EXAMPLES#

# Basic zone check
dnswalk example.com.

# Recursive check with all warnings
dnswalk -r -a -l -m example.com.

# Debug mode to see all queries
dnswalk -d example.com.

# Strict checking mode
dnswalk -F example.com.

# Check with lame delegation detection
dnswalk -l example.com.

INTERPRETING OUTPUT#

# Output prefixes:
# WARN:  = Warning (potential issue)
# FAIL:  = Failure (definite problem)
# INFO:  = Informational message
# DEBUG: = Debug information (-d flag)

# Common warnings:
# "lame delegation" = NS record points to non-authoritative server
# "A record not found" = hostname has no A record
# "MX record points to CNAME" = RFC violation
# "no reverse entry" = missing PTR record

NOTES#

- IMPORTANT: Domain must end with a trailing dot (.)
- Requires zone transfers to be enabled on the DNS server
- Written in Perl, requires Net::DNS module
- Best used for auditing DNS zones you manage
- Results depend on AXFR being allowed (many servers block this)
- Consider combining with dnsenum for a more complete audit