• Tutorials
  • Courses
  • Tracks

During DNS enumeration, a tool attempts an AXFR for the target domain and receives a full zone transfer. What does this mean?

Last Updated :
Discuss
Comments

During DNS enumeration, a tool attempts an AXFR for the target domain and receives a full zone transfer. What does this mean?

The domain uses DNSSEC and is secure

The authoritative server allowed a zone transfer and exposed the entire DNS zone (all records) — a critical information leak

The authoritative server returned only SOA and NS records (normal)

The server refused the transfer due to rate limiting

Share your thoughts in the comments