Spamhaus Technology and abuse.ch Logo
Back to Previous Page

Blog

Passive DNS vs. active DNS: what's the difference?

Posted on
September 30, 2026
Author
Spamhaus Technology Team
Read time
6 mins

Introduction

Introduction

Every day, billions of DNS lookups translate domain names into the infrastructure behind them. Most of those answers are used once and forgotten… unless recorded. For anyone investigating suspicious infrastructure, these records can be the difference between a dead end and a lead.

In this blog post, we take a closer look at both active and passive DNS, how they work, and how investigators use them to build a clearer picture of suspicious infrastructure.

What is Active DNS?

It is the process of querying authoritative name servers and getting back the ‘domain name to IP mappings’ that are live (active) right now. It works on any domain, and gives you the most up-to-date picture available. Investigators typically do this with command line tools such as dig or nslookup, or web-based DNS lookup tools.

The trade off is that the answer is only accurate the moment you make the query, and it shares nothing about what happened before. Take a phishing domain, it could move to a new hosting provider tomorrow. An active query wouldn’t be able to show where it's moved to, or where it's been.

The closest active DNS gets to providing any history is the SOA (start of authority) record. Every domain has one, and it includes a serial number that often works like a timestamp for when the domain's records were last changed. Unfortunately, it's easy to forge, so you can't rely on it, especially if you don't trust the provider.

What is Passive DNS?

Passive DNS data is essentially a searchable database of historical DNS answers, built from everyday DNS traffic. It is generated when a DNS lookup cannot be answered from a local cache and the hostname is resolved by an external authoritative server for resolution.

When you visit www.example.com, your DNS resolver first checks whether it has a recent answer saved (its cache). If no one’s checked that website recently, it has to ask the domain’s authoritative server, which is the one source of truth for that domain.

With special probes activated on the DNS resolver, it’s possible to record the answer that comes back along with a timestamp. Nobody has to look up a domain on purpose for it to be captured. It’s recorded simply because someone, somewhere, visited it. That’s what makes it passive DNS data. And that's what makes it a different tool from active DNS. It allows you to look back and get an idea: for how long has this setup been in place? Has a domain moved around a lot, or has it stayed put? You cannot reliably answer either question with active DNS alone.

Active vs Passive DNS: core differences

The most obvious difference is live versus historical data: active DNS shows what a domain resolves now, while passive DNS shows what has been observed over time. They aren't competing tools, they just answer different questions.

Here's how they compare side by side:

Active DNS Passive DNS
Timing Real-time Historical
Visibility Query can reach servers the target controls Invisible to the domain owner
Coverage One lookup Records observed over time
Use case Verifying current state Reconstructing what happened
Infrastructure movement Shows a snapshot only; no visibility into change Reveals how often and where, a domain's infrastructure has moved
Proxied or CDN-fronted domains Returns only the proxy's IP address (Cloudflare, for example) Can still show the original hosting server from before the domain moved behind the proxy

Where the line blurs in practice

Few, if any, providers run a purely passive or purely active dataset; it's almost always a mixture of both. They're built by blending genuinely passive feeds - logs shared by partners, existing DNS traffic - with active querying the provider runs itself: watching for new domains appearing in zone files and querying them directly, or following up on a known domain with further queries to see what else is tied to it.

Why Passive AND Active DNS matter for investigations

When you're trying to identify if a domain is legitimate, its history often holds much more information than its current state. A domain that's pointed to the same host for five years looks very different from one that's changed providers three times over the course of a month.

Let’s take a look at a practical example…

An analyst finds a suspicious domain, secure-examplebank-login[.]com. An active lookup reveals it points to a Cloudflare IP address. Frustratingly, this doesn't share much, as thousands of legitimate sites also sit behind the same IP.

This is where Passive DNS steps in. Said domain was first seen three weeks ago, and before moving behind Cloudflare it pointed directly to a server at a small hosting provider. Using Passive DNS, the analyst pivots, searching for every other domain that has used that same server. Dozens of lookalike banking domains show up, most of them first seen in the same week.

A single suspicious domain has now become a campaign, and using active DNS, it confirms which domains are still live, so they can be blocked first.

This is also a good example of why passive DNS is tied closely to reconnaissance: it tells you where to look before you do anything active. And a bonus: because you're searching historical records that already exist, rather than live look ups, you don't tip anyone off the way querying live infrastructure might.

In practice, investigators use both states: passive DNS maps the history and identifies associated infrastructure, while active DNS confirms what's live right now.

When active DNS is the better choice

You might assume passive DNS is always going to provide the most value, but there are a few scenarios where active DNS is in fact the better option - for example:

  • You need the most current answer, especially for low traffic domains: ones that  are unlikely to appear regularly in passive DNS because there simply isn't much traffic to capture.

  • The record type isn’t usually stored in passive DNS. Certain record types used for technical purposes, like SPF records, aren't consistently kept, since history on records like that isn't typically of much interest. If you need that data, a live DNS query is the safer bet.

Passive DNS Intelligence from Spamhaus

Spamhaus has been collecting and structuring passive DNS data for years. Historically, it's been made available through the Passive DNS API and Passive DNS Real-Time Feed, giving security teams a historical record built on trusted, high-volume DNS intelligence.

Now we’re introducing Deteqtive: a new, more intelligent way to work with that same data. It adds search, pivot, and pattern detection built directly on top, so investigators can move from a single domain to the full picture of a campaign, faster. Deteqtive is currently in beta and invite-only. If you'd like early access, request an invite.