Skip to content
Vol. 1 · Ed. 2026
CyberGlossary
Entry № 891

Passive DNS

Reviewed byCybersecurity entrepreneur & security researcher

What is Passive DNS?

Passive DNSA historical database of observed DNS resolutions that lets investigators look up which IPs a domain pointed to and which domains shared an IP over time.


Passive DNS (pDNS) is built by sensors placed just above recursive resolvers that record the responses the resolver receives, without ever querying authoritative servers themselves. The technique was introduced by Florian Weimer in his 2005 paper Passive DNS Replication, presented at the FIRST conference; his system logged resolver answers and replicated them into a central, queryable database. Sensors typically capture only inter-server (cache-miss) traffic above the resolver, so they avoid recording the stub queries of individual end users.

Datasets from providers such as Farsight DNSDB (now part of DomainTools), VirusTotal, SecurityTrails, and CIRCL let defenders pivot from a domain to historical IPs, sibling domains, name servers, and first-seen/last-seen timestamps. Many expose records in the IETF Common Output Format (COF, draft-dulaunoy-dnsop-passive-dns-cof) so results are interchangeable across vendors. It is a core resource for threat hunting, malware infrastructure mapping, takedowns, and tracking fast-flux and domain-generation algorithms — for example, confirming that a phishing domain first resolved only hours before a campaign began. Because pDNS records only what was actually observed, it complements WHOIS, certificate transparency, and active scanning, and it is non-intrusive to the operators of the observed domains.

flowchart LR
  C[Clients] --> R[Recursive resolver]
  R -->|cache-miss queries| AUTH[Authoritative servers]
  S[pDNS sensor] -. observes responses .-> R
  S --> DB[(Passive DNS database)]
  AN[Analyst] -->|pivot on domain / IP| DB
  DB -->|historical resolutions| AN

● Examples

  1. 01

    Pivoting from a suspicious C2 domain to other domains historically hosted on the same IP within DNSDB.

  2. 02

    Confirming that a phishing domain first resolved 24 hours before the malicious email campaign began.

● Frequently asked questions

What is Passive DNS?

A historical database of observed DNS resolutions that lets investigators look up which IPs a domain pointed to and which domains shared an IP over time. It belongs to the Defense & Operations category of cybersecurity.

What does Passive DNS mean?

A historical database of observed DNS resolutions that lets investigators look up which IPs a domain pointed to and which domains shared an IP over time.

How do you defend against Passive DNS?

Defences for Passive DNS typically combine technical controls and operational practices, as detailed in the full definition above.

What are other names for Passive DNS?

Common alternative names include: pDNS, DNS observation data.

● Related terms