Loading
Loading
A reverse NS lookup finds every domain whose NS records point to a specific name server. Run a reverse NS lookup by entering a name server hostname to see which domains delegate their DNS to it. You get the full domain list paginated 100 per page, with the last-seen date and TTL for every record. Search one exact hostname or use a wildcard to match a provider's name server range. Security analysts use it to map attacker infrastructure, and DNS administrators use it to audit delegation.
A reverse NS lookup works backward from a name server to the domains that use it. A standard NS record lookup takes a domain and returns its name servers. A reverse NS lookup inverts that: you enter a name server hostname, such as ns1.cloudns.net, and get back the domains that delegate their DNS to it.
DNS itself cannot answer this. A resolver walks from a domain to its records and never back, and no record type lists the domains delegated to a name server. Reverse NS lookups rely on passive DNS instead, which is why every result carries a last-seen date rather than a live status.
Domains sharing a name server share a DNS provider, not necessarily a web server.
Every reverse NS lookup returns a total record count and a paginated table of the domains pointing to that name server.
| Field | What it tells you |
|---|---|
| Total Records | How many matching records passive DNS holds for that name server. A count in the tens of thousands points to a major DNS provider, while a short count usually means a self-hosted name server, where the domains are far more likely to be related. |
| Domain Name | The matched domain. Results are paginated 100 per page. |
| Record Type | The record behind the match, NS for this lookup. |
| Name Server | The name server the record points to. With wildcard matching this varies row to row, so you can see which of a provider's name servers each domain actually uses. |
| TTL | How long resolvers cache the record, in seconds. Unusually short values often mean a migration is in progress. |
| Last Seen | When the record was last observed. Use it to separate live records from stale ones. |
The tool searches passive DNS for NS records, matching your input against the name server field of each record and returning the domains that match. Each result carries the date the record was last seen.
You get two matching modes.
Three lookups get called “reverse” and they answer different questions. Search results for reverse NS often mix all three.
| Lookup | You enter | You get back | Source |
|---|---|---|---|
| NS record lookup | A domain | The name servers authoritative for that domain | Live DNS query |
| Reverse NS lookup | A name server hostname | Every domain whose NS records point to it | Passive DNS |
| Reverse DNS (PTR) lookup | An IP address | The hostname the IP identifies itself by | Live DNS query against the .arpa zone |
| Reverse IP lookup | An IP address | Every domain resolving to that IP | Passive DNS (A and AAAA records) |
The live lookups usually return one answer each. The reverse lookups return a list, because no single DNS record holds it, which is why both carry a Last Seen date on every row.
| Query | What it matches |
|---|---|
| ns1.google.com | Only domains pointing to that one name server |
| ns*.google.com | Google's name servers ns1 through ns4 under google.com |
| *.ns.cloudflare.com | Domains on any Cloudflare name server, whatever name the zone was assigned |
| ns1.cloudns.* | The ns1 name server across every TLD ClouDNS operates it on |
Wildcard queries scan far more passive DNS records than exact ones, so they take longer to return. Anchoring the start of the hostname, as in ns*.cloudns.net rather than *.cloudns.net, narrows the search.
A wildcard query on a DNS provider's name server pattern returns a record count that gives a rough measure of how widely that provider is used, along with the domains behind it for competitive research. A provider's domains spread across several name server hostnames and sometimes several TLDs, so one query rarely covers the full footprint.
An NS record is a DNS record that names the authoritative name servers for a domain. Most domains publish two or more, so resolution continues if one server is unreachable.
NS records exist at two levels. The TLD registry holds the records that hand a domain off to the name servers set at its registrar, and the domain itself publishes its own NS records. The two sets should match, and when they drift apart, resolvers can behave inconsistently. Where a name server's hostname sits under the domain it serves, as ns1.google.com does for google.com, the registry also carries a glue record with its IP address, because resolving that hostname would otherwise mean asking the very name server you are trying to find.
Query the domain's NS records with a forward DNS lookup, such as our DNS Lookup API. Paste one of the returned name server hostnames into the reverse NS lookup above to see which other domains use it.
No. A shared name server means a shared DNS provider, not shared hosting. Two domains on the same name server can run on unrelated infrastructure under different owners. To find domains that genuinely share a server, run the IP through our IP to Domain Lookup.