Skip to main content
Network & InfrastructureUpdated September 3, 2026

DNS History

DNS history is a record of historical DNS resolution data for a domain — including all IP addresses it has ever resolved to, when changes occurred, and what nameservers have been used. It is used in threat investigations to trace infrastructure reuse and identify related malicious domains.

Try it on a domain: DNS history lookup.

DNS history is the timeline of what a name has resolved to. Live DNS gives one answer for now; history gives every answer that was observed, with the dates a record appeared and disappeared, for A, AAAA, MX, NS and TXT records. It is built from passive DNS: resolvers that record what they were asked and what they answered.

Attackers move infrastructure and the history remembers it. A domain that pointed at a bulletproof host last year and at a parking page today still carries that year. A set of domains that all changed nameservers on the same day were very likely changed by the same hand.

The history also protects against a common false positive. An address that hosted phishing in 2024 may serve a legitimate business in 2026; the history shows the handover, so the old listing can be read as expired rather than as a verdict on the current tenant.

Example

A suspicious domain resolves to a clean CDN address today. Its history shows that for six weeks in the spring it resolved to an address that three sources list as a C2 for the same period. The domain is the durable indicator; the CDN address is not.

In isMalicious

The DNS history tool at /threat-intel/dns-history shows the resolution timeline for a domain, and the report page surfaces previous addresses and nameserver changes alongside the current records so a pivot is available without leaving the lookup.

Frequently Asked Questions

What is DNS History?

DNS history is a record of historical DNS resolution data for a domain — including all IP addresses it has ever resolved to, when changes occurred, and what nameservers have been used. It is used in threat investigations to trace infrastructure reuse and identify related malicious domains.

How is DNS History related to Reverse IP Lookup?

DNS History and Reverse IP Lookup are both key concepts in threat intelligence. Reverse IP lookup returns all domain names hosted on a given IP address. It is used by threat hunters to identify other malicious domains sharing the same hosting infrastructure as a known bad actor — a technique known as infrastructure pivoting.

Related Terms

Put this intelligence to work

Query indexed indicators — IPs, domains, URLs, and hashes — in seconds.

Check any indicator free
← Back to Glossary