Pivot map
Pivot from here
Outputs from Viewdns Tools can become inputs for the next tool. These are the most relevant follow-on pivots in the library.
A global, open, stable, and secure Internet that serves the entire Asia Pacific community
ARIN is a nonprofit, member-based organization that administers IP addresses & ASNs in support of the operation and growth of the Internet.
AbuseIPDB provides IP reputation data and community abuse reports for identifying malicious hosts in network and threat investigations.
Algo VPN automates deployment of a personal WireGuard or IKEv2 VPN server in the cloud for private, secure OPSEC browsing.
A global, open, stable, and secure Internet that serves the entire Asia Pacific community
ARIN is a nonprofit, member-based organization that administers IP addresses & ASNs in support of the operation and growth of the Internet.
AbuseIPDB provides IP reputation data and community abuse reports for identifying malicious hosts in network and threat investigations.
AccountKiller provides direct deletion links and step-by-step instructions for removing accounts on hundreds of websites and social platforms.
Investigator Use
ViewDNS Tools (viewdns.info) is a comprehensive domain and network intelligence platform offering over 20 different DNS, WHOIS, and network analysis tools in a single interface. It provides reverse IP lookup, DNS propagation checking, WHOIS history, port scanning, and various other reconnaissance capabilities.
For OSINT investigators, ViewDNS is most valuable for its reverse IP lookup and WHOIS history features. Reverse IP lookup identifies all domains currently hosted on a specific IP address — a critical technique for discovering the full scope of an actor's web infrastructure or finding related fraudulent domains hosted on the same server.
When a malicious domain is identified and its hosting IP is resolved, reverse IP lookup at ViewDNS frequently reveals additional fraudulent domains on the same server. Criminal actors often host multiple fraud sites, phishing pages, or malware distribution points on the same IP address. Each co-hosted domain is a potential new investigation lead.
WHOIS history preserves historical registration records for domains across time, showing how registrant information, name servers, and registrars have changed. This historical record is essential because current WHOIS data is often hidden behind privacy services — historical records from before privacy protection was applied may contain unredacted personal information.
The IP geolocation and ISP lookup functions provide quick organization and location context for any IP. The DNS propagation checker is useful for verifying whether a domain's DNS records have propagated globally after changes — relevant when monitoring whether a malicious domain is still resolving after takedown action.
ViewDNS's port scan function provides a basic external view of open ports on a target, though for authorized assessments, dedicated tools provide more comprehensive results.
The platform's broad feature set makes it efficient for initial domain and IP reconnaissance — investigators can perform multiple types of lookups without switching between numerous specialized tools.
Document all ViewDNS tool outputs with the specific tool used, query input, results returned, and query timestamp.
Before You Pivot
Capture the target, search terms, and why this source is relevant before you leave the page.
Archive volatile pages, save screenshots, and keep timestamps for anything that may change.
Treat one tool as a lead source. Confirm important findings with independent sources.
Related tools
A global, open, stable, and secure Internet that serves the entire Asia Pacific community
AbuseIPDB provides IP reputation data and community abuse reports for identifying malicious hosts in network and threat investigations.
Internet-wide search interface for hosts and certificates with large-scale host, service, and virtual host coverage plus API access.
Utilize misconfigured DNS and old database records to find hidden IP's behind the CloudFlare network
Criminal IP delivers AI-powered IP threat intelligence, attack surface data, and fraud detection for cyber threat investigations.
Free domain research tool to discover hosts related to a domain. Find visible hosts from the attackers perspective for Red and Blue Teams.