Cheatsheet

DNS zone transfer cheatsheet

dig, nslookup, host, dnsrecon, fierce, dnsenum — every AXFR attack and detection command, plus the defensive configuration that stops zone transfer leakage.

Run DNS zone transfer scanner

Attack & detection commands

01

dig AXFR (classical)

The default workflow — enumerate name servers, then attempt AXFR against each. If a server returns the SOA record and zone data, zone transfer is allowed.

# Enumerate NS records
dig +short NS example.com

# Attempt AXFR against each nameserver
dig axfr example.com @ns1.example.com
dig axfr example.com @ns2.example.com
02

nslookup zone transfer

Older but still useful — set query type to any, specify the server, then issue ls -d.

nslookup
> server ns1.example.com
> set type=any
> ls -d example.com
03

host -l

The one-liner. Equivalent to a dig AXFR but with simpler syntax.

host -l example.com ns1.example.com
04

dnsrecon (automated enumeration)

Scripted enumeration — auto-discovers nameservers and attempts AXFR against each, outputs structured results.

dnsrecon -d example.com -t axfr
dnsrecon -d example.com -t std
05

fierce (brute-force fallback)

If AXFR is refused, fierce brute-forces subdomains as a fallback — producing many of the same findings zone transfer would have.

fierce --domain example.com
fierce --domain example.com --subdomain-file subdomains.txt
06

dnsenum (combined)

Combines NS enumeration, AXFR attempts, Google-based subdomain discovery, and reverse DNS lookups.

dnsenum --threads 10 example.com
07

zonetransfer.me (safe practice target)

zonetransfer.me is a public, intentionally-misconfigured domain maintained for pentesters to validate AXFR tooling without touching production targets.

dig axfr zonetransfer.me @nsztm1.digi.ninja
dig axfr zonetransfer.me @nsztm2.digi.ninja

Defensive configuration

BIND (allow-transfer)

zone "example.com" {
    type master;
    file "example.com.zone";
    allow-transfer { 203.0.113.5; 198.51.100.7; };
};

BIND (TSIG-authenticated)

key "transfer-key" {
    algorithm hmac-sha256;
    secret "base64-encoded-secret";
};

zone "example.com" {
    type master;
    allow-transfer { key "transfer-key"; };
};

PowerDNS

# pdns.conf
allow-axfr-ips=203.0.113.5,198.51.100.7

Firewall (defence-in-depth)

# iptables — block external TCP/53 except from known secondaries
iptables -A INPUT -p tcp --dport 53 -s 203.0.113.5 -j ACCEPT
iptables -A INPUT -p tcp --dport 53 -s 198.51.100.7 -j ACCEPT
iptables -A INPUT -p tcp --dport 53 -j DROP

Stop finding vulnerabilities manually

TigerStrike uses AI agents to continuously discover, validate, and exploit vulnerabilities across your applications — so your team can focus on fixing what matters.