Dynamic DNS providers let users instantly create and update subdomains, which threat actors frequently abuse for fast-flux C2, phishing landing pages, and disposable infrastructure. Tracking who created what, from which IP, and with what user-agent is critical for attribution.
The Dynamic DNS tab surfaces registration and update data from dynamic DNS ecosystems monitored by Silent Push. It reveals the email address used, creation/update IP, associated A record, account details, creation timestamp, and user-agent string—key indicators of automated or malicious activity.
Available for Domains that appear in tracked DDNS datasets.
How It Works
Silent Push continuously monitors popular dynamic DNS services and registration portals. When data exists, the tab displays a clean table with the exact column order requested. (If no data is available, the tab shows the friendly “No Dynamic DNS data available” message.)
Generate a Set of Results
Search a domain in Total View.
Click the Dynamic DNS tab.
Results appear in the new standardized column layout.
All pivotable fields (Email, IPs, Domain, etc.) link directly into other platform views.
Example
When data is present, you might see rows showing an email abuse@example.com used from the Created IP 185.220.101.XX to create malicious123.ddns.net with a specific A Record, Account ID, Created timestamp, and a scripted user-agent.
Fields
Email: The email address associated with the dynamic DNS account or registration.
Domain: The full domain or subdomain that was dynamically registered or updated.
A Record: The IPv4 address (A record) that the dynamic domain pointed to at the time of creation/update. Critical for mapping to live C2 servers or phishing hosts.
Domain Creator IP: The IP address of the system or user that initially created the dynamic DNS domain. Useful for linking multiple malicious registrations to the same actor.
Account: The internal account identifier on the DDNS provider.
Created: Timestamp when the dynamic DNS entry was first registered or updated.
User Agent: The HTTP user-agent string captured during creation or update often reveals the presence of automation tools or scripts.
Use Case
Incident responders use this view to pivot from a suspicious callback domain to the exact creation IP address and email address, speeding up attribution and blocking at the source. It is especially powerful when combined with WHOIS changes or Threat Feeds that flag the same domain.
Work with Dynamic DNS Results
Every field that exists in WHOIS-style searches is a pivot point.
Copy IPs or emails with one click.
Export the entire table as CSV.
Save interesting entries to a Draft Feed or monitoring list.
Tips
Look for clusters of domains created from the same Created IP or Domain Creator IP.
Unusual or headless user-agents often indicate scripted mass registration.
Correlate Created timestamps with spikes in Threat Feeds or Zetalytics activity.
If the tab is empty, the domain is not present in the current DDNS datasets.