A domain resolves to dozens of IPs over months or years. Which are stable hosting addresses, and which are short-lived, fast-flux, or load-balancer entries? Manually querying Farsight DNSDB for every domain is impractical.
The Farsight tab aggregates historical A-record data from Farsight Security’s DNSDB—the world’s largest passive DNS database. It displays the number of times each domain-to-IP mapping has been observed globally, along with first and Last Seen dates, giving you a clear picture of infrastructure longevity and change.
Available for Domains. It works alongside Zetalytics (granular query-level detail), PADNS (current live resolutions), and Infrastructure Variance (ASN Diversity and IP churn).
How It Works
Farsight passively collects DNS responses worldwide. Silent Push surfaces the aggregated RRset counts and time windows. Per the latest updates, the table is streamlined: the Type column has been removed (all entries are A records for this view), the Domain Wide View toggle is gone, and risk-score/ASN columns are not displayed.
Generate a Set of Results
Open Total View for any domain.
Switch to the Farsight tab.
The table loads with Count, Domain, IP, First Seen, and Last Seen columns.
Adjust result size or apply date filters as needed.
Example
For silentpush.com, the top rows show:
Count 2344 for IP
8.6.112.0(First Seen 2025-09-04, Last Seen 2026-04-02)Similar high-count entries for
8.47.69.0and older infrastructure from 2020.
High counts with recent Last Seen indicate primary, long-term hosting IPs.
Fields
Count: Number of global observations of this exact domain-to-IP A record.
Domain: The domain name.
IP: The IPv4 address the domain resolved to.
First Seen: Earliest date this resolution was recorded in Farsight DNSDB.
Last Seen: Most recent date the resolution appeared.
Use Case
Defenders quickly identify stable infrastructure (high Count + long First/Last Seen span) versus ephemeral IPs used in malicious campaigns. Correlating Farsight data with Whois changes or Threat Feeds helps attribute hosting providers and detect evasion tactics.
Work with Farsight Results
Pivot on Domain or IP directly into other tools.
Export CSV for reports or SIEM enrichment.
Save high-count IPs to monitoring lists for continued tracking.
Tips
Focus on rows with the highest Count for core Infrastructure mapping.
Compare First Seen vs. Last Seen spans to spot infrastructure migration events.
Combine with Zetalytics for subdomain-level granularity and PADNS for current status.