← Blog
// OSINT · RECONOCIMIENTO

Passive recon: your domain's public footprint

Published Aug 11, 2026 · 8 min read
OSINTReconocimientoBlue TeamDNS

The first phase of a serious attack doesn't touch the target. Before sending a single packet, whoever means business gathers everything already public: DNS, certificates, historical records, exposed services. It's called passive reconnaissance, it's undetectable to you, and it almost always reveals more than you'd think. The good news: you can look at your own footprint with the same eyes and shrink it.

What's known without touching you

1. DNS: the map of your infrastructure

DNS records are public by definition. One look says a lot:

dig +short MX example.com
dig +short TXT example.com     # look for "v=spf1 …"
dig +short NS example.com

2. Certificate Transparency: the subdomain snitch

Here's the gem. Every TLS certificate issued by a public CA is recorded in open logs (Certificate Transparency). Querying them —on crt.sh, say— lists subdomains without touching the target: dev., staging., vpn., jenkins., internal-mail.… The admin panel you thought was hidden has been in a public log for months.

⚠️ Material for defense and authorized pentesting. Against your own domain it's pure hygiene; against third parties without permission, it isn't.

3. WHOIS, Wayback and Shodan

🔍 To see your footprint at a glance, the OSINT Quick Recon gathers a domain's passive recon from open sources, and the DNS Lookup pulls the records (MX, TXT, NS…) and tests zone transfer. All in your browser.

The defensive side: shrink the surface

Your passive footprint is what the attacker gets for free. Shrinking it is one of the best-return investments:

Footprint checklist

Passive recon can't be prevented —it's public information— but you can control what's out there. Look at yourself through an attacker's eyes once a quarter and you'll take half their work away.

Share: LinkedIn X
Sergio Belmonte Morales
Sergio Belmonte Morales
Cybersecurity Analyst · SOC · Sentinel/KQL specialist