ActorStack.dev

Passive DNS samples what was asked; a zone file records what exists

Two sources that look interchangeable for infrastructure questions and answer differently shaped questions. Which one to reach for depends on whether you need history, resolution or completeness.

By Oswaldo Carabano6 min read

Short answer

Passive DNS builds its picture from queries that sensors observed, so its coverage is a property of the sensor network: a domain nobody looked up is a domain it does not know about, and a record that stopped being queried fades from it. A registry zone file is the authoritative list of what is delegated in a top-level domain right now, complete within that TLD and silent about everything else. For 'what exists today in these TLDs', the zone file is the better answer; for 'what did this domain resolve to last March', only passive DNS holds it, because a zone file has no history and no A records at all.

Key points

  • Passive DNS coverage is a property of a sensor network, so a domain nobody queried is a domain it does not hold.
  • A registry zone file is complete within its top-level domain, because the registry publishes what it has delegated rather than what somebody observed.
  • Zone files contain no A, MX or TXT records, so a question about what a name resolved to cannot be answered from one at all.
  • Passive DNS holds history, and a zone-file snapshot holds the present, which is why a change is visible only by comparing two snapshots.
  • Country-code top-level domains are visible to passive DNS and absent from gTLD zone data, which is a coverage difference that runs the other way.
  • The honest pairing is zone files for what is delegated now and passive DNS for what was resolving then.
On this page6 sections

Both get called “DNS data”. They are closer to opposites.

Two sources, two questions

Passive DNS answers what has been seen resolving. A zone file answers what is delegated right now. Almost every practical difference between them follows from that one distinction.

Completeness against observation

Passive DNS is assembled from queries that sensors observed, so its coverage is a property of the sensor network. A domain nobody looked up is a domain it does not hold, and a quiet domain is underrepresented relative to a busy one. A zone file is complete within its TLD by construction: the registry publishes what it delegated, whether anyone ever queried it or not.

History exists in only one of them

Passive DNS keeps what it saw, so it can answer questions about last March. A zone file is a snapshot of now. History in zone data exists only as a series of snapshots you kept — which is exactly how new delegations and zone exits are computed, by comparing one day against the next.

What each source physically contains

Passive DNSRegistry zone file
Delegation (NS)ObservedAuthoritative
Resolution (A, MX, TXT)YesNot present at all
HistoryYesOnly what you snapshotted
Country-code TLDsYesNo

Where each one's coverage gap falls

Passive DNS is thin where traffic is thin. Zone data is absent where ICANN's contracts do not reach, which is every country-code TLD. Those gaps do not overlap, which is the argument for holding both.

Choosing for a given investigation

For every domain currently on this nameserver, the zone file, and it is the better answer by some distance. For what did this host serve in March, passive DNS, because a zone file never held it.

Frequently asked questions

Is passive DNS better than zone files?
Neither is better; they answer differently shaped questions. Passive DNS holds observed history including resolution data and country-code TLDs, while a zone file is the registry's complete and current record of delegation within the TLDs it covers.
Can a zone file tell me what a domain resolved to?
No. A zone file contains delegation and DNSSEC records and nothing else — a domain's own A, MX and TXT records are published by its nameservers rather than by the registry, so resolution history is outside the source entirely.
Which one finds every domain on a nameserver?
The zone file, within the top-level domains it covers, because it records every delegation the registry made rather than the subset a sensor network happened to observe. Outside those TLDs, passive DNS is the only one of the two with anything at all.

Sources

Every URL below was requested and returned a page on the date shown.

  1. Platform docschecked 18 Sept 2026
    RFC 1035 — Domain Names: Implementation and SpecificationIETF
  2. Platform docschecked 18 Sept 2026
    Centralized Zone Data ServiceICANN
  3. Operator claimchecked 18 Sept 2026
    Reverse Nameserver Lookup — Actor README and input schemaActorStack / Apify Store
Racks of network equipment in a dimly lit server room, lit blue by their indicators.
DomainsGuide

Reverse nameserver lookup

Pivoting from a nameserver to the domains delegated to it is useful on infrastructure that belongs to one organisation and useless on a large provider's. The difference is the whole technique.

6 min
Racks of network equipment in a dimly lit server room, lit blue by their indicators.
DomainsMeasured

What dns_provider can tell you

The nameserver identifies who runs the DNS for 69.1% of domains. It does not identify what a site is built with, and the measurement that settled that question is worth seeing.

5 min
A laptop screen showing a plain text-mode terminal with a command prompt.
DomainsComparison

dnstwist versus zone search

Permutation engines find the squats their rules predicted. Searching the registry zone finds what is actually registered, including the spellings no generator would produce — and each approach misses something the other catches.

6 min