Nmap Domain Name Lookup
To run nmap on a subnet.
Nmap domain name lookup. In addition to scanning by ip address you can also use the following commands to specify a target. To scan a range of ip addresses 1 10. Desired domain name entry.
Dns server to be queried default. Desired dns record type default. To scan a host.
Nmap also reports the total number of ip addresses at the end. Dns servers known to nmap. Port of dns server to connect to default.
The registrar of record identified in this output may have an rdds service that can be queried for additional information on how to contact the registrant admin or tech contact of the queried domain name. You can scan the network for port 53 perhaps with version detection then try nmap list scans sl specifying each name server one at a time with dns servers until you find one which works. If the hosts sport domain names you do not recognize it is worth investigating further to prevent scanning the wrong company s network.
This is the basic format for nmap and it will return information about the ports on that system.