Ask most organizations for a complete list of the domains and subdomains they own, and you will get a spreadsheet that is confidently wrong. It will be missing the campaign subdomain marketing spun up last year, the staging environment a developer created and forgot, the domain acquired through a company you bought, and the third-party service someone connected with a CNAME that no longer resolves anywhere useful. The list describes what the organization thinks it owns. Reality is larger, messier, and changing constantly.
This gap is not a documentation failure to be fixed once. It is a structural condition of how DNS gets used. Domains and subdomains are created by many people, through many tools, for many reasons, and almost never deliberately retired. Treating your DNS inventory as a static list you compile occasionally guarantees it will be out of date within weeks. The alternative is to treat it as a living asset: continuously discovered, continuously reconciled, and owned.
This guide covers why DNS inventory drifts, what a complete catalog actually includes, and how to build and maintain one that reflects reality rather than intention.
Why Your Inventory Is Always Incomplete
The reasons an inventory drifts out of date are worth naming, because each points to a category of asset that manual documentation tends to miss.
Decentralized creation. DNS records get created by whoever needs one: developers, marketers, IT, external agencies, SaaS onboarding flows. Each addition is reasonable in isolation, and almost none of them update a central record. This is the root of the shadow DNS problem, assets that exist and resolve but were never centrally tracked.
Acquisitions and reorganizations. When one company absorbs another, it inherits a domain portfolio that is often poorly documented and sometimes actively unknown. These inherited assets are frequently the least monitored and the most likely to contain forgotten exposures, a risk we explore in the context of DNS governance during mergers and acquisitions.
Abandonment without removal. Projects end and services are decommissioned, but the DNS records pointing at them usually remain. The record outlives the thing it pointed to, which is exactly how dangling records and takeover exposure accumulate.
Defensive and parked domains. Organizations register variants, misspellings, and regional versions defensively, then lose track of them. They are owned, they are rarely monitored, and they still carry the organization's name.
What a Complete Catalog Actually Contains
A living inventory is broader than a list of primary domains. To be useful for security and operations, it needs to capture several layers.
- All registered domains, including defensive registrations, regional and country-code variants, and brand-protection domains that redirect or sit parked.
- All subdomains, including the transient ones created for campaigns, testing, and one-off integrations, which are the hardest to enumerate and the most likely to be forgotten.
- The records under each, and where they point, so that third-party dependencies (CNAMEs to SaaS platforms, delegations to external nameservers) are visible as the dependencies they are.
- Ownership, a named person or team responsible for each domain and subdomain, so that anything unowned can be questioned.
- Provider and account, which registrar and DNS provider each domain lives with, since portfolios spread across multiple providers are common and easy to lose track of.
An inventory that captures only the first layer, the primary domains everyone already knows about, misses precisely the assets where risk concentrates.
How to Discover What You Actually Own
Building the catalog means discovering assets rather than transcribing what you already believe. Several complementary techniques get you there.
Start from your registrar and DNS provider accounts. Pull the authoritative list of registered domains from every registrar you use. This is the reliable core, though it only covers domains, not subdomains, and only the providers you remember to check.
Enumerate subdomains actively. Certificate Transparency logs are a powerful source here: every publicly trusted certificate issued for your domains is logged, which surfaces subdomains that were never documented. Combined with other discovery methods, this reveals the subdomain footprint your documentation does not have.
Cross-reference with the teams that create records. Marketing, development, and any group that stands up services will each know about assets central IT does not. A periodic reconciliation with them surfaces the human knowledge that no automated scan captures.
Reconcile and assign ownership. Every discovered asset should be matched to an owner. Anything that cannot be explained or owned is a finding: a candidate for removal, or at least for investigation.
Why It Has to Be Continuous
The single most important shift is from inventory-as-event to inventory-as-process. A catalog built in a one-time project is accurate on the day it is finished and decaying by the next. New subdomains appear, services are decommissioned, domains approach expiry, and records change, continuously.
A living inventory is one that updates itself: continuously discovering new subdomains as they appear, flagging records that have gone dangling, tracking approaching expirations, and surfacing changes as they happen. The human work shifts from compiling the list to reviewing what the continuous process surfaces, which is a far smaller and more sustainable task. This is the same principle that turns a quarterly audit from a scramble into a review, which we cover in our quarterly DNS audit checklist.
The Inventory Is the Foundation for Everything Else
A complete, current DNS inventory is not an end in itself. It is the prerequisite for every other DNS security and governance activity. You cannot detect subdomain takeover on subdomains you have not discovered. You cannot assess email authentication on domains you do not know you own. You cannot produce compliance evidence for an estate you cannot fully enumerate. Inventory is the base layer of DNS posture management, and its completeness sets the ceiling on how good everything above it can be.
How DNS Assistant Helps
Maintaining a living inventory by hand is the part that defeats most teams, and it is precisely where continuous tooling earns its place. DNS Assistant builds and maintains this catalog as an ongoing process rather than a manual exercise:
- Subdomain discovery surfaces the subdomains your documentation lacks, including forgotten and transient ones, using Certificate Transparency and other discovery methods.
- Continuous monitoring keeps the catalog current as new subdomains appear and records change, rather than letting it decay after an initial scan.
- Dangling record detection across 22+ cloud providers flags the abandoned-but-not-removed records that inventory drift produces.
- WHOIS and expiration tracking keeps registration and expiry visible across your portfolio.
- A viewable change history and data export in CSV, Excel, or PDF turn the living inventory into something you can review and hand to an auditor.
- Multi-tenant, role-based access suits organizations and agencies maintaining inventories across many entities.
The catalog stays current because the discovery and monitoring are continuous; the ownership decisions and cleanup remain yours to make.
Build Your Catalog
You can start by inspecting a domain you already know about with the free DNS lookup tool or a Free Domain Risk Report. For the discovery that turns a partial list into a living inventory, finding the subdomains and dangling records you do not yet know about, start free at dnsassistant.com.
Start Monitoring Your DNS Today
Get real-time alerts, track record changes, and keep your domains secure with DNS Assistant.
Sign Up Free