DNS (53)
Dig
dig axfr <domain> @<ip address>
AXFR (Full Zone Transfer) is a type of DNS zone transfer that replicates the entire DNS zone from the master server to the slave server. This is done when the slave server is being set up or when the master server has been updated with new DNS resource records.
Lookup Domain
If there is port 53 and we found another subdomain, check the IP of the other domain, sometimes they are different IP address.
check subdomain with this:
DNS Recon
Requirement:
IP Address
Range Target
Last updated