DNS zone transfer cheatsheet
dig, nslookup, host, dnsrecon, fierce, dnsenum — every AXFR attack and detection command, plus the defensive configuration that stops zone transfer leakage.
Run DNS zone transfer scannerAttack & detection commands
dig AXFR (classical)
The default workflow — enumerate name servers, then attempt AXFR against each. If a server returns the SOA record and zone data, zone transfer is allowed.
# Enumerate NS records
dig +short NS example.com
# Attempt AXFR against each nameserver
dig axfr example.com @ns1.example.com
dig axfr example.com @ns2.example.comnslookup zone transfer
Older but still useful — set query type to any, specify the server, then issue ls -d.
nslookup
> server ns1.example.com
> set type=any
> ls -d example.comhost -l
The one-liner. Equivalent to a dig AXFR but with simpler syntax.
host -l example.com ns1.example.comdnsrecon (automated enumeration)
Scripted enumeration — auto-discovers nameservers and attempts AXFR against each, outputs structured results.
dnsrecon -d example.com -t axfr
dnsrecon -d example.com -t stdfierce (brute-force fallback)
If AXFR is refused, fierce brute-forces subdomains as a fallback — producing many of the same findings zone transfer would have.
fierce --domain example.com
fierce --domain example.com --subdomain-file subdomains.txtdnsenum (combined)
Combines NS enumeration, AXFR attempts, Google-based subdomain discovery, and reverse DNS lookups.
dnsenum --threads 10 example.comzonetransfer.me (safe practice target)
zonetransfer.me is a public, intentionally-misconfigured domain maintained for pentesters to validate AXFR tooling without touching production targets.
dig axfr zonetransfer.me @nsztm1.digi.ninja
dig axfr zonetransfer.me @nsztm2.digi.ninjaDefensive configuration
BIND (allow-transfer)
zone "example.com" {
type master;
file "example.com.zone";
allow-transfer { 203.0.113.5; 198.51.100.7; };
};BIND (TSIG-authenticated)
key "transfer-key" {
algorithm hmac-sha256;
secret "base64-encoded-secret";
};
zone "example.com" {
type master;
allow-transfer { key "transfer-key"; };
};PowerDNS
# pdns.conf
allow-axfr-ips=203.0.113.5,198.51.100.7Firewall (defence-in-depth)
# iptables — block external TCP/53 except from known secondaries
iptables -A INPUT -p tcp --dport 53 -s 203.0.113.5 -j ACCEPT
iptables -A INPUT -p tcp --dport 53 -s 198.51.100.7 -j ACCEPT
iptables -A INPUT -p tcp --dport 53 -j DROPStop finding vulnerabilities manually
TigerStrike uses AI agents to continuously discover, validate, and exploit vulnerabilities across your applications — so your team can focus on fixing what matters.