Spamhaus Technology and abuse.ch Logo
Solutions
Data
Email & Network
Cyber Threat Intelligence
Resources
About
Back to Previous Page

Blog

Ways to use passive DNS intelligence: Security Professional

Posted on
July 01, 2026
Author
Spamhaus Technology Team
Read time
2 mins

Introduction

Introduction

Security Professionals can use passive DNS intelligence to investigate a suspicious domain or IP address and find out what’s really behind it: a single malicious IP, or a much larger multi-layered operation.

Content

Here are a few ways to dig deeper:

  • Check the subnet: Investigate domains that are within the same subnet as the suspicious IP. Some (or most) of these will display similar behaviours.

  • Watch for reuse: Abusers recycle their resources e.g. the same web server often hosts several phishing domains, not just one. Passive DNS intelligence lets you acquire the information before, or immediately after, they change their domain or IP address.

  • Map the full range: In larger more complex operations, an abuser may control the full /24 subnet. Passive DNS intelligence can reveal all the domains that are pointing to an IP address in the subnet, giving you the full picture instead of a single data point.

  • Audit your own zones: Use passive DNS intelligence to find invalid or unauthorised records in the zones you control. This is a sign of unauthorised access or cache poisoning/spoofing, where corrupt DNS data is introduced into a resolver’s cache, causing the name server to return false results.

SEE THE FULL PICTURE WITH DETEQTIVE

A single suspicious IP rarely tells the whole story. Deteqtive's pattern matching and broader DNS coverage surface the entire cluster of related domains and infrastructure behind it, so you're not left guessing whether you've found one bad actor or missed the rest of their operation.

Want to know more? Deteqtive is currently in early access, you can find more information here or get in touch if you have any questions.