Record History
Current A, AAAA, MX, NS, TXT, CNAME, CAA and DNSKEY records, resolved at lookup time.
How this check works · illustration
See which addresses a domain has resolved to, from AlienVault OTX passive DNS, next to its current A, AAAA, MX, NS, TXT, CNAME and CAA records. Use DNS history to spot attacker infrastructure pivots, shared hosting, and suspicious domain moves during SOC triage.
curl -d "email=you@example.com" https://ismalicious.com/api/keys/instant50 free requests/month · instant API key · no signup form
OTX
Passive DNS source
8
Record types resolved live
Connect the signals, then examine the context.
Current A, AAAA, MX, NS, TXT, CNAME, CAA and DNSKEY records, resolved at lookup time.
Each past resolution carries the dates passive DNS first and last saw it.
Track which IP addresses a domain has pointed to over time.
See the nameservers a domain uses today, next to the hosts it resolved to before.
Identify connections between domains through shared infrastructure.
Watch a domain and get an email when it is newly listed; it is checked daily at 06:00 UTC. DNS record changes are not monitored.
Workflows to evaluate with your existing tools.
Track attacker infrastructure, pivot from one domain to related hosts, and enrich alerts with historical DNS context.
Investigate when malicious DNS changes occurred.
Check where your domains resolve today and where they resolved before.
Review a domain's history before acquisition.
New to the term? Read the glossary definition.
Test the available signals in your workflow. Review the sources and limits before integrating.
No credit card required · Free API key