Historical DNS Resolution Data in Legendary OSINT: Tools and Methods
Legendary OSINT provides two primary resources for retrieving historical DNS resolution data—PassiveDNS (Mnemonic) and Completedns—both cataloged in the infrastructure domains documentation and accessible via REST API or web scraping techniques.
When investigating domain infrastructure, access to historical DNS resolution data reveals how IP addresses and hostnames have evolved over time. The K2SOsint/Legendary_OSINT repository maintains a curated collection of OSINT tools specifically for this purpose, documenting passive DNS services and historical lookup databases. This guide examines the two primary tools listed in docs/infra-domains.md for querying past DNS records.
PassiveDNS (Mnemonic) for Historical DNS Lookups
As documented at line 29 of docs/infra-domains.md, PassiveDNS (Mnemonic) is explicitly categorized as a historical DNS resolution tool within Legendary OSINT. This free service aggregates passive DNS observations from network sensors worldwide, storing historic A, AAAA, CNAME, and other record types associated with queried domains. The platform exposes a REST API that returns structured JSON data, making it suitable for automated intelligence gathering and integration into OSINT pipelines.
Completedns DNS History Database
Completedns appears at line 20 of docs/infra-domains.md as a searchable DNS history database that archives past DNS records for specific hostnames. Unlike PassiveDNS, which relies on passive observation data, Completedns maintains a historical database accessible primarily through web interfaces. This tool complements PassiveDNS by providing an alternative source for cross-referencing domain infrastructure changes and verifying historical name resolution patterns.
Querying Historical DNS Data Programmatically
Both services support programmatic retrieval of historical DNS resolution data, though they require different technical implementations. The following Python examples demonstrate how to extract historical records from each platform according to the Legendary OSINT documentation.
PassiveDNS API Implementation
The PassiveDNS service provides a dedicated endpoint at https://passivedns.mnemonic.no/api/v1/lookup that accepts domain parameters and returns JSON-encoded historical observations.
import requests
def query_passivedns(domain):
url = "https://passivedns.mnemonic.no/api/v1/lookup"
params = {"domain": domain}
resp = requests.get(url, params=params, timeout=10)
resp.raise_for_status()
return resp.json()
print(query_passivedns("example.com"))
Completedns Web Scraping Approach
Completedns requires parsing HTML tables to extract historical DNS data from https://completedns.com/dns-history/{domain}. The service presents records in a table identified by the dns-history-table class.
import requests
from bs4 import BeautifulSoup
def get_completedns_history(domain):
url = f"https://completedns.com/dns-history/{domain}"
resp = requests.get(url, timeout=10)
resp.raise_for_status()
soup = BeautifulSoup(resp.text, "html.parser")
# The table with historic records is identified by the class 'dns-history-table'
table = soup.find("table", class_="dns-history-table")
return table.get_text(separator="\n") if table else "No data found"
print(get_completedns_history("example.com"))
Summary
- PassiveDNS (Mnemonic) offers API-based access to passive DNS observations for historical DNS resolution data, documented at line 29 of
docs/infra-domains.mdin the Legendary OSINT repository. - Completedns provides a web-based DNS history database for retrieving past records, referenced at line 20 of
docs/infra-domains.md. - Both tools reside in the Infrastructure/Domains category, supporting investigations into domain infrastructure evolution.
- Implementation differs by platform: PassiveDNS uses structured JSON API responses, while Completedns requires HTML parsing of the
dns-history-tableclass elements.
Frequently Asked Questions
What types of DNS records does PassiveDNS store historically?
PassiveDNS stores historical A, AAAA, CNAME, and other record types collected through passive DNS observation. The API returns timestamped resolution data, enabling investigators to track when specific IP addresses or hostnames were associated with a target domain according to the Legendary OSINT source documentation.
Does Completedns provide an API for historical DNS lookups?
Completedns does not expose a public API for historical DNS resolution data; it operates primarily through a web interface. As implemented in the documentation, retrieving data requires scraping the HTML from https://completedns.com/dns-history/{domain} and parsing the table with class dns-history-table to extract historical records.
Where are these historical DNS tools documented in Legendary OSINT?
Both tools are cataloged in docs/infra-domains.md within the K2SOsint/Legendary_OSINT repository. PassiveDNS is specifically noted for historical DNS resolution at line 29, while Completedns appears at line 20 as a DNS history lookup service.
Which tool is recommended for automated OSINT workflows?
PassiveDNS (Mnemonic) is better suited for automated workflows due to its structured JSON API and consistent response format. Completedns requires HTML parsing and is more appropriate for manual verification or when PassiveDNS data needs corroboration from an alternative historical DNS resolution data source.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →