What this tool shows
Enter a domain and SYNAPSE pulls together everything public about its DNS: every record type (A, AAAA, MX, NS, TXT, SOA, CNAME, CAA), its email-security posture (SPF, DMARC, DKIM, MX), registrar and WHOIS details, DNSSEC status, and subdomains discovered through Certificate Transparency logs. A health scorecard then highlights the gaps worth fixing, all in a single fast lookup, no signup.
Frequently asked questions
What is DNS reconnaissance?
DNS reconnaissance is mapping everything publicly known about a domain's DNS: its records (A, MX, NS, TXT, etc.), email-security setup, registrar details, and subdomains. It's the first step in understanding (or auditing) a domain's footprint and attack surface.
How does this find subdomains?
It queries Certificate Transparency logs, the public, append-only records of every TLS certificate issued. Because certificates list the hostnames they cover, CT logs reveal subdomains that have ever had a certificate. Some may no longer resolve, so treat the list as historical breadth rather than a live inventory.
What do the health checks mean?
The scorecard flags common configuration gaps: missing or weak SPF/DMARC (email spoofing risk), no DNSSEC, a single nameserver (no redundancy), and missing CAA records. Each item explains why it matters so you know what's worth fixing.
Is this like dnsdumpster?
Same idea: a fast, free domain map combining DNS records and subdomain discovery, with added email-security analysis, registrar/WHOIS, and a health scorecard. And when you want continuous coverage, you can turn any of it into a monitor.