- Open a terminal in Kali Linux and type “nmap -sL <target IP or domain name>” to perform a
simple DNS enumeration scan. - This will return a list of hostnames associated with the target IP or domain name.
- To perform a more comprehensive DNS enumeration, type “nmap -sL –dns-servers <target
IP or domain name>” - To check for DNS zone transfer, type “nmap –script dns-zone-transfer -p 53 <target IP or
domain name>” - To check for subdomains, type “nmap -sL –script dns-brute -p 53 <target IP or domain
name>” - To find DNS server version, type “nmap -sV –script dns-version -p 53 <target IP or domain
name>”
Reference:
Nmap: https://nmap.org/book/man.html