Skip to main content

DNS History Lookup Past resolutions and current DNS records

Try it now
Examples

Enter a domain to inspect its DNS records and available history.

Output

How this check works · illustration

See which addresses a domain has resolved to, from AlienVault OTX passive DNS, next to its current A, AAAA, MX, NS, TXT, CNAME and CAA records. Use DNS history to spot attacker infrastructure pivots, shared hosting, and suspicious domain moves during SOC triage.

curl -d "email=you@example.com" https://ismalicious.com/api/keys/instant

50 free requests/month · instant API key · no signup form

OTX

Passive DNS source

8

Record types resolved live

Capabilities

Signals for your investigation.

Connect the signals, then examine the context.

Record History

Current A, AAAA, MX, NS, TXT, CNAME, CAA and DNSKEY records, resolved at lookup time.

First and Last Seen

Each past resolution carries the dates passive DNS first and last saw it.

IP History

Track which IP addresses a domain has pointed to over time.

Nameserver Changes

See the nameservers a domain uses today, next to the hosts it resolved to before.

Infrastructure Mapping

Identify connections between domains through shared infrastructure.

Reputation Alerts

Watch a domain and get an email when it is newly listed; it is checked daily at 06:00 UTC. DNS record changes are not monitored.

Applications

Use cases.

Workflows to evaluate with your existing tools.

Threat Hunting

Track attacker infrastructure, pivot from one domain to related hosts, and enrich alerts with historical DNS context.

Incident Response

Investigate when malicious DNS changes occurred.

Brand Monitoring

Check where your domains resolve today and where they resolved before.

Due Diligence

Review a domain's history before acquisition.

Support

Frequently asked questions.

How far back does DNS history go?

As far back as AlienVault OTX passive DNS observed the domain. Each past resolution shows the first and last dates it was seen; we keep no archive of our own beyond that.

What DNS record types do you track?

Current records: A, AAAA, MX, NS, TXT, CNAME, CAA and DNSKEY, plus the DMARC, MTA-STS, TLS-RPT and BIMI TXT records. Past resolutions are the record types passive DNS observed, mostly A, AAAA and CNAME.

How can DNS history help with threat hunting?

Attackers often reuse infrastructure. DNS history helps you identify connections between domains and track when malicious infrastructure was set up.

Can I get alerts for DNS changes?

No. Monitoring watches reputation, not DNS records: a watched domain is checked daily at 06:00 UTC and you get an email when it is newly listed.

New to the term? Read the glossary definition.

Get Started

Ready to get started?

Test the available signals in your workflow. Review the sources and limits before integrating.

No credit card required · Free API key