dnsspectre

module
v0.4.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Aug 4, 2026 License: MIT

README

dnsspectre

CI ANCC

dnsspectre — DNS hygiene and subdomain takeover detection. Part of SpectreHub.

What it is

  • Scans DNS zones for dangling records pointing to deleted resources
  • Detects subdomain takeover vectors (CNAME, NS, MX targets)
  • Checks for missing CAA records
  • Supports Route53, Cloud DNS, Azure DNS, and Cloudflare
  • Outputs text, JSON, SARIF, and SpectreHub formats

What it is NOT

  • Not a DNS monitoring service — point-in-time scanner
  • Not a penetration testing tool — detects risk, does not exploit
  • Not a DNS manager — reports findings, never modifies records
  • Not a certificate manager — flags missing CAA, does not issue certs

Quick start

Homebrew
brew tap ppiankov/tap
brew install dnsspectre
From source
git clone https://github.com/ppiankov/dnsspectre.git
cd dnsspectre
make build
Windows

Download dnsspectre_*_windows_amd64.zip from releases, unzip it, and run:

.\dnsspectre.exe version

Or install with Go:

go install github.com/ppiankov/dnsspectre/cmd/dnsspectre@latest
Usage
dnsspectre scan --provider route53 --format json

CLI commands

Command Description
dnsspectre scan Scan DNS zones for dangling records and takeover risk
dnsspectre init Generate config file and provider credentials
dnsspectre version Print version

SpectreHub integration

dnsspectre feeds DNS hygiene findings into SpectreHub for unified visibility across your infrastructure.

spectrehub collect --tool dnsspectre

Safety

dnsspectre operates in read-only mode. It inspects and reports — never modifies, deletes, or alters your DNS records.

Documentation

Document Contents
CLI Reference Full command reference, flags, and configuration

License

MIT — see LICENSE.


Built by Obsta Labs

Directories

Path Synopsis
cmd
dnsspectre command
internal
aws
dns
gcp

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL