ActorStack.dev

Reverse nameserver lookup, and when the answer is worth having

Pivoting from a nameserver to the domains delegated to it is useful on infrastructure that belongs to one organisation and useless on a large provider's. The difference is the whole technique.

By Oswaldo Carabano6 min read

Short answer

A reverse nameserver lookup takes a nameserver hostname and returns the domains delegated to it, which is the registry's own record of delegation rather than an inference. The technique works on a nameserver that belongs to one organisation — a company's own `ns1.company.com`, a small hosting provider, an infrastructure under investigation — and collapses on a large provider's, because Cloudflare alone accounts for 20.9% of the namespace and a lookup there returns tens of millions of unrelated domains. Shared hosting is not a relationship: two domains on a big provider's nameservers share a vendor and nothing else, and reading `dns_provider` before drawing a conclusion is what separates those two cases.

Key points

  • A reverse nameserver lookup returns the domains delegated to a given nameserver, taken from the registry's own zone record rather than inferred from traffic.
  • Cloudflare alone accounts for 20.9% of the namespace, so a lookup on a large provider's nameserver returns tens of millions of unrelated domains.
  • Two domains sharing a big provider's nameservers have a vendor in common and nothing else, which is why co-location is not evidence of a link.
  • Two domains on the same obscure, self-run nameserver very often do share an owner, and that is the case the technique exists for.
  • `dns_provider` on every row is what lets those two situations be told apart before a conclusion is written down.
  • `all_nameservers` shows the domain's full delegation, so a partial migration is visible rather than hidden behind the one server that matched.
On this page6 sections

A technique that is genuinely powerful in one situation and genuinely useless in another, with nothing in the output to tell you which you are in unless you look.

What the query actually answers

Give it ns1.example-dns.com and it returns the domains delegated to that server across 1,075 generic top-level domains. Because it reads the registry's own delegation record, it is the registry's view rather than a sample of observed traffic — a distinction with real consequences.

When the answer is useless

On a large provider. Cloudflare alone accounts for 20.9% of the namespace, so looking up one of its nameservers honestly returns tens of millions of unrelated domains and the row cap truncates the answer long before it means anything. There is no insight there to find.

When it is the only way to know

On infrastructure that belongs to one organisation: a company's own ns1.company.com, a small hosting provider, a nameserver hosting suspended domains, a specific setup under investigation. There the set of domains delegated to it is a meaningful group, and it is a group that is genuinely hard to enumerate any other way.

Shared hosting is not a relationship

Reading the full delegation

all_nameservers returns every server the domain delegates to, not just the one that matched. A domain halfway through a migration shows both providers, which is visible in that field and invisible in a result that only echoed the query. dnssec comes back on every row too, and it needs its TLD to mean anything.

Writing it up without overclaiming

State the nameserver, state the provider, and state the coverage: 1,075 gTLDs, no country-code TLDs. An empty result is a real finding — that nameserver hosts nothing else in the covered zones — and it costs only the start fee.

Frequently asked questions

What is a reverse nameserver lookup?
It is the query that starts from a nameserver hostname and returns the domains delegated to it. Read from registry zone files, it is the registry's own record of which domains point at that server rather than a sample of observed traffic.
Why is looking up a big provider useless?
Because the answer is tens of millions of unrelated domains and the row cap truncates it long before it means anything. Cloudflare alone is 20.9% of the namespace, so sharing its nameservers says only that both domains use Cloudflare.
When does the technique actually work?
On a nameserver that belongs to one organisation: a company's own `ns1.company.com`, a small hosting provider, or a specific infrastructure under investigation. There, the set of domains delegated to it is a meaningful group rather than a customer list.
Can I conclude two domains share an owner?
Only with the provider in view. On a large shared provider the answer is no. On an obscure self-run nameserver it is very often yes, and `dns_provider` is the field that tells you which situation you are looking at before you write anything down.

Sources

Every URL below was requested and returned a page on the date shown.

  1. Operator claimchecked 18 Sept 2026
    Reverse Nameserver Lookup — Actor README and input schemaActorStack / Apify Store
  2. Platform docschecked 18 Sept 2026
    RFC 1035 — Domain Names: Implementation and SpecificationIETF
  3. Platform docschecked 18 Sept 2026
    Centralized Zone Data ServiceICANN
A white measuring tape curving across a dark background, showing the numbers 15 to 45.
DomainsMeasured

DNSSEC adoption by TLD

Measured across the whole zone, 5.0% of domains publish a DS record. Per registry the rate runs from 0% to 100%, which is what makes the global figure unusable on its own.

5 min
A shelf of office binders with dated labels along their spines.
DomainsComparison

Passive DNS versus zone files

Two sources that look interchangeable for infrastructure questions and answer differently shaped questions. Which one to reach for depends on whether you need history, resolution or completeness.

6 min
A row of residential mailboxes on posts in front of a wooden fence and trees.
DomainsGuide

Detecting domain hijacking

Whoever controls the nameservers controls the mail, the site and the certificates. That change happens in the registry zone, which is the one layer most monitoring never looks at.

7 min