MetaDIG is a small command line tool that enumerates subdomains for an apex domain via the SecurityTrails API, then resolves each subdomain to show its DNS chain with a focus on CNAME targets and A records.
It is designed for quick infrastructure mapping and vendor fingerprinting (CDN, WAF, PaaS), with colored keyword highlighting and a simple frequency summary at the end.
Given an apex domain (example: accor.com), MetaDIG:
- Calls SecurityTrails to discover subdomains.
- Runs
digon each subdomain to capture: • CNAME (when present) • A records and TTLs - Optionally enriches A record IPs using Team Cymru WHOIS to show ASN, country code, and AS name.
- Highlights common provider keywords in the output.
- Prints a summary: • total subdomain count processed • keyword frequency counts
press.accor.com CNAME pressaccorcom.epresspack.link. TTL 900 A 54.36.54.250
group.accor.com CNAME iv78fgv.ng.impervadns.net. TTL 30 A 45.60.159.180
sofitel.accor.com CNAME i3tf7zxzobp.8tx293jn7e.ioriveredge.net. TTL 20 A 110.164.21.130 ; TTL 20 A 110.164.21.8
Subdomains count: 555
cloudfront 12
impervadns 45
...
macOS or Linux recommended.
• Python 3.10+
• dig (usually provided by bind tools)
• whois (optional, for ASN enrichment)
On macOS:
brew install whoisdig is usually available, but if not:
brew install bindExport your API key as an environment variable:
export SECURITYTRAILS_APIKEY="YOUR_KEY"Run against an apex domain:
python3 st_subdomains_cname_a.py accor.comUseful flags:
python3 st_subdomains_cname_a.py accor.com --children-only
python3 st_subdomains_cname_a.py accor.com --include-inactive
python3 st_subdomains_cname_a.py accor.com --limit 200
python3 st_subdomains_cname_a.py accor.com --workers 40
python3 st_subdomains_cname_a.py accor.com --no-asnThe script uses a thread pool to resolve many subdomains in parallel. If you run into rate limiting, timeouts, or your DNS resolver gets grumpy, reduce concurrency:
python3 st_subdomains_cname_a.py accor.com --workers 10MetaDIG highlights specific keywords to make common infrastructure patterns pop visually.
Red:
• cloudfront
• impervadns
• edgecastcdn
• fastly
• ioriveredge
• edgekey
• cloudflare
Blue:
• vercel-dns
• adobeaemcloud
• azurewebsites
• amazonaws
Yellow:
• api
At the end of the run, MetaDIG prints keyword frequencies across the output.
.
├── st_subdomains_cname_a.py
└── README.md
• The script only queries:
• SecurityTrails API for subdomain enumeration
• DNS resolvers via dig
• Team Cymru WHOIS (optional) for ASN enrichment
• No results are uploaded anywhere else. • Be mindful of your organization’s policies before scanning third party domains.
Set the environment variable or pass --api-key:
export SECURITYTRAILS_APIKEY="YOUR_KEY"
python3 st_subdomains_cname_a.py example.comInstall whois:
brew install whoisTry fewer workers:
python3 st_subdomains_cname_a.py example.com --workers 10• Output to JSON or CSV
• Save raw dig output per subdomain
• Add AAAA and MX modes
• Smarter keyword counting (per record type and per vendor category)
• Resolver selection and retry logic
This tool is intended for legitimate security and infrastructure analysis. Use it responsibly and only against domains you are authorized to assess.