dig piratemoo.com
dig –x piratemoo.com // Reverse DNS lookup
dig piratemoo.com -t mx +short // Grab mail info
dig piratemoo.com -t ns +short // Grab NS info
dig piratemoo.com -t cname // Grab CNAME info
dig axfr piratemoo.com ns08.domaincontrol.com // Check DNS xfers
host
host piratemoo.com // find the address of said host
host -t mx piratemoo.com // Check mail info
-t flagged is used to specify a specific type of scan (ns/mx/cname)
host -t axfr piratemoo.com ns08.domaincontrol.com // Check DNS zone xfers
Success? host -l zonetransfer.me piratemoo.com
dnsenum --noreverse -o file.txt piratemoo.com // Google scrape to get subdomains
dnsenum --dnsserver piratemoo.com github.com -p 10 -s 50
-o output file
-p pages value // specifies # of pages searched on google
-s scrap value // defines max # of subdomains from google
-w whois
--dnsserver // uses dns server for A/NS/MX queries
--noreverse // skip reverse lookup
--enum shortcut to --threads 5 -s 15 -w
NMAP
nmap -sSU -p 53 --script dns-nsid piratemoo.com // Retrieves info through nameserver ID
nmap -T4 -p 53 --script dns-brute piratemoo.com // Enumerate hostnames by brute forcing common subdomains