> ## Documentation Index
> Fetch the complete documentation index at: https://www.docusnap.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Scanning Windows DNS

> Capturing Windows DNS servers with their configuration, zones and records—with credentials of your own or under the gateway's service account.

The *Windows DNS* scan module captures Windows DNS servers with their zones and
records. It requires a connected [gateway](/docs/en/scan/gateway-install).

## Captured data

Each DNS server becomes an asset of the type *DNS* with three groups:

| Group | Content |
| - | - |
| Service Configuration | configuration, security settings, forwarders, root hints, zone delegations |
| Zones | primary and secondary zones |
| Statistics | the statistics of the DNS server |

How the detail page of the type is structured is described in
[Directory and Network Services](/docs/en/assets/directory-services).

## Setting up the job

The wizard follows the standard path *Basics* › *Targets* › *Schedule* ›
*Summary*—see [Creating a Scan Job](/docs/en/scan/create-inventory). The
*Targets* step is what sets this module apart.

Each row carries the columns *Server Name* and *Credentials*. *Server Name*
takes one DNS server per row, as an address or hostname; the column does not
accept an address range.

*Search DNS Servers* fills in the servers from Active Directory instead: the
dialog asks for the *Domain* and credentials and adds the DNS servers it finds
as rows, including the servers in child domains.

The *Credentials* column may stay empty. The scan then runs under the
gateway's service account, and that account needs the rights listed under
[Permissions](#permissions). An entry in *Credentials for all targets* applies
to every row without an assignment of its own.

## Prerequisites

The scan connects to the DNS servers over WMI and queries the DNS data through
PowerShell.

### Ports and protocols

| Protocol | Port | Transport |
| - | - | - |
| NetBIOS Name Service, NetBIOS Datagram Service | 137, 138 | UDP |
| NetBIOS Session Service, SMB / CIFS over TCP | 139, 445 | TCP |
| RPC, dynamic ports | 49152–65535 | TCP/UDP |

### Permissions

* On the DNS servers the account needs domain administrator rights.
* Enter the account with the domain: `DOMAIN\user` or `user@domain.local`.

### Network requirements

* The firewall allows the ports above.
* The DNS servers have:
  * .NET Framework 4.6.1 or later,
  * PowerShell 3 or later, allowed to run,
  * the PowerShell module for DNS,
  * access to `C:\Windows\Temp` and to the `IPC$` share.

Scan DNS servers the gateway cannot reach directly on the server with the
`Discovery-DNS.exe` scan script—see
[Scanning by Script](/docs/en/scan/scan-by-script).

## Related

After it is created, the job appears among the jobs; how you watch and adjust
it is in [Managing Jobs](/docs/en/scan/manage-jobs). You capture the DHCP servers of
the same domain with [Windows DHCP](/docs/en/scan/dhcp).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.