Dependency Blast Radius

Understand the fallout before it happens. Choose any asset and this maps dependencies in both directions: everything that would break if it went down (your single points of failure), and everything it quietly relies on to work (its own supply chain of DNS, mail, hosting, and networks). The resilience view that turns 'what if this fails' into a concrete answer.

How it uses the graph

Traverses the DNS, email, BGP, web layers of the graph, in 52 steps:

How it walks the graph52 steps
01What this is

Identifying the asset type…

DNSemailBGPweb
02Infrastructure role

Classifying the infrastructure role (nameserver, mail, CDN…)…

DNSemailBGPweb
03Resolution

Resolving the asset to its address(es)…

DNSemailBGPweb
04Own redundancy (single points of failure)

Counting the asset's own nameservers, mail servers and addresses…

DNSemailBGPweb
05Domains depending on it for DNS

Finding the domains this host is a nameserver for, with their NS redundancy…

DNSemailBGPweb
06Domains depending on it for mail

Finding the domains this host handles mail for, with their MX redundancy…

DNSemailBGPweb
07CNAME / SPF / web dependents

Finding the CNAMEs, SPF includers and sites that depend on it…

DNSemailBGPweb
08Hosts depending on this address

Finding the hostnames served by this address, with their address redundancy…

DNSemailBGPweb
09Owning prefix & ASN (route diversity)

Tracing the address to its prefix and announcing ASN(s)…

DNSemailBGPweb
10Round 2: what depends on the hostnames

Finding what depends on round-2 hostnames (DNS, mail, CNAME, SPF, links)…

DNSemailBGPweb
11Round 2: what depends on the addresses

Reverse-resolving round-2 addresses to the hosts that depend on them…

DNSemailBGPweb
12Round 2: what depends on the prefixes

Expanding round-2 prefixes to their IPs and routing ASN(s)…

DNSemailBGPweb
13Round 2: what depends on the networks

Expanding round-2 ASNs to the prefixes they announce…

DNSemailBGPweb
14Round 3: what depends on the hostnames

Finding what depends on round-3 hostnames (DNS, mail, CNAME, SPF, links)…

DNSemailBGPweb
15Round 3: what depends on the addresses

Reverse-resolving round-3 addresses to the hosts that depend on them…

DNSemailBGPweb
16Round 3: what depends on the prefixes

Expanding round-3 prefixes to their IPs and routing ASN(s)…

DNSemailBGPweb
17Round 3: what depends on the networks

Expanding round-3 ASNs to the prefixes they announce…

DNSemailBGPweb
18Round 4: what depends on the hostnames

Finding what depends on round-4 hostnames (DNS, mail, CNAME, SPF, links)…

DNSemailBGPweb
19Round 4: what depends on the addresses

Reverse-resolving round-4 addresses to the hosts that depend on them…

DNSemailBGPweb
20Round 4: what depends on the prefixes

Expanding round-4 prefixes to their IPs and routing ASN(s)…

DNSemailBGPweb
21Round 4: what depends on the networks

Expanding round-4 ASNs to the prefixes they announce…

DNSemailBGPweb
22Round 5: what depends on the hostnames

Finding what depends on round-5 hostnames (DNS, mail, CNAME, SPF, links)…

DNSemailBGPweb
23Round 5: what depends on the addresses

Reverse-resolving round-5 addresses to the hosts that depend on them…

DNSemailBGPweb
24Round 5: what depends on the prefixes

Expanding round-5 prefixes to their IPs and routing ASN(s)…

DNSemailBGPweb
25Round 5: what depends on the networks

Expanding round-5 ASNs to the prefixes they announce…

DNSemailBGPweb
26Round 6: what depends on the hostnames

Finding what depends on round-6 hostnames (DNS, mail, CNAME, SPF, links)…

DNSemailBGPweb
27Round 6: what depends on the addresses

Reverse-resolving round-6 addresses to the hosts that depend on them…

DNSemailBGPweb
28Round 6: what depends on the prefixes

Expanding round-6 prefixes to their IPs and routing ASN(s)…

DNSemailBGPweb
29Round 6: what depends on the networks

Expanding round-6 ASNs to the prefixes they announce…

DNSemailBGPweb
30Round 7: what depends on the hostnames

Finding what depends on round-7 hostnames (DNS, mail, CNAME, SPF, links)…

DNSemailBGPweb
31Round 7: what depends on the addresses

Reverse-resolving round-7 addresses to the hosts that depend on them…

DNSemailBGPweb
32Round 7: what depends on the prefixes

Expanding round-7 prefixes to their IPs and routing ASN(s)…

DNSemailBGPweb
33Round 7: what depends on the networks

Expanding round-7 ASNs to the prefixes they announce…

DNSemailBGPweb
34Round 8: what depends on the hostnames

Finding what depends on round-8 hostnames (DNS, mail, CNAME, SPF, links)…

DNSemailBGPweb
35Round 8: what depends on the addresses

Reverse-resolving round-8 addresses to the hosts that depend on them…

DNSemailBGPweb
36Round 8: what depends on the prefixes

Expanding round-8 prefixes to their IPs and routing ASN(s)…

DNSemailBGPweb
37Round 8: what depends on the networks

Expanding round-8 ASNs to the prefixes they announce…

DNSemailBGPweb
38Round 9: what depends on the hostnames

Finding what depends on round-9 hostnames (DNS, mail, CNAME, SPF, links)…

DNSemailBGPweb
39Round 9: what depends on the addresses

Reverse-resolving round-9 addresses to the hosts that depend on them…

DNSemailBGPweb
40Round 9: what depends on the prefixes

Expanding round-9 prefixes to their IPs and routing ASN(s)…

DNSemailBGPweb
41Round 9: what depends on the networks

Expanding round-9 ASNs to the prefixes they announce…

DNSemailBGPweb
42Round 10: what depends on the hostnames

Finding what depends on round-10 hostnames (DNS, mail, CNAME, SPF, links)…

DNSemailBGPweb
43Round 10: what depends on the addresses

Reverse-resolving round-10 addresses to the hosts that depend on them…

DNSemailBGPweb
44Round 10: what depends on the prefixes

Expanding round-10 prefixes to their IPs and routing ASN(s)…

DNSemailBGPweb
45Round 10: what depends on the networks

Expanding round-10 ASNs to the prefixes they announce…

DNSemailBGPweb
46Blast-radius recap

Tallying the blast radius…

DNSemailBGPweb
47Ownership (WHOIS registrant)

Ownership (WHOIS registrant)…

DNSemailBGPweb
48Supply chain across the stack

Supply chain across the stack…

DNSemailBGPweb
49DNS-provider dependency

DNS-provider dependency…

DNSemailBGPweb
50Mail & SPF-sender dependency

Mail & SPF-sender dependency…

DNSemailBGPweb
51True origins behind the edge

True origins behind the edge…

DNSemailBGPweb
52Physical-facility dependency

Physical-facility dependency…

DNSemailBGPweb

Why each step runs

  1. 01What this is. Reads the node label(s) so the fan-out anchors the right dependency edges for a host, IP, prefix or ASN.
  2. 02Infrastructure role. whisper.identify names the roles the asset plays (DNS operator, mail receiver, CDN, origin), which is exactly what determines who depends on it.
  3. 03Resolution. Establishes the pivot IP (a host resolves; an IP is its own) so the address/prefix/ASN dependency arms have an anchor.
  4. 04Own redundancy (single points of failure). How many nameservers / MX / A-records the asset itself has is its own resilience: a count of 1 means it has no alternative at that layer — a single point of failure.
  5. 05Domains depending on it for DNS. Each domain that uses this host as a nameserver depends on it for DNS. total_nameservers = 1 means this host is its ONLY nameserver — losing it takes the domain offline; > 1 means it has a fallback.
  6. 06Domains depending on it for mail. Each domain that uses this host as an MX depends on it for mail. total_mx = 1 means no backup mail server — mail stops if this host does.
  7. 07CNAME / SPF / web dependents. CNAMEs that alias to it, domains that SPF-include it, and sites that link it all break (resolution, mail-auth or references) if it disappears — the soft dependency surface.
  8. 08Hosts depending on this address. Every hostname resolving to this IP depends on it. total_addresses = 1 means the host is single-homed on this address — it has no alternative IP if this one goes away.
  9. 09Owning prefix & ASN (route diversity). The prefix and ASN that route the address are shared-fate dependencies. origin_count > 1 (MOAS) means the prefix is announced from more than one ASN — route diversity; a single origin is a routing single point of failure.
  10. 10Round 2: what depends on the hostnames. Each hostname fans out to what would break without it — the domains it is the nameserver or MX for, the CNAMEs that point at it, the senders that SPF-include it, the sites that link it. All are themselves expanded next round.
  11. 11Round 2: what depends on the addresses. Every hostname resolving to an address depends on it — if the address goes dark, they all do. SPF-IP senders trust it for mail.
  12. 12Round 2: what depends on the prefixes. Every IP inside the prefix depends on it being announced; the ASN that routes it is the shared-fate parent — its other prefixes are reached next round, unfolding the whole routing neighbourhood.
  13. 13Round 2: what depends on the networks. Every prefix an ASN announces depends on it for routing — if the network fails, that whole address space is unreachable.
  14. 14Round 3: what depends on the hostnames. Each hostname fans out to what would break without it — the domains it is the nameserver or MX for, the CNAMEs that point at it, the senders that SPF-include it, the sites that link it. All are themselves expanded next round.
  15. 15Round 3: what depends on the addresses. Every hostname resolving to an address depends on it — if the address goes dark, they all do. SPF-IP senders trust it for mail.
  16. 16Round 3: what depends on the prefixes. Every IP inside the prefix depends on it being announced; the ASN that routes it is the shared-fate parent — its other prefixes are reached next round, unfolding the whole routing neighbourhood.
  17. 17Round 3: what depends on the networks. Every prefix an ASN announces depends on it for routing — if the network fails, that whole address space is unreachable.
  18. 18Round 4: what depends on the hostnames. Each hostname fans out to what would break without it — the domains it is the nameserver or MX for, the CNAMEs that point at it, the senders that SPF-include it, the sites that link it. All are themselves expanded next round.
  19. 19Round 4: what depends on the addresses. Every hostname resolving to an address depends on it — if the address goes dark, they all do. SPF-IP senders trust it for mail.
  20. 20Round 4: what depends on the prefixes. Every IP inside the prefix depends on it being announced; the ASN that routes it is the shared-fate parent — its other prefixes are reached next round, unfolding the whole routing neighbourhood.
  21. 21Round 4: what depends on the networks. Every prefix an ASN announces depends on it for routing — if the network fails, that whole address space is unreachable.
  22. 22Round 5: what depends on the hostnames. Each hostname fans out to what would break without it — the domains it is the nameserver or MX for, the CNAMEs that point at it, the senders that SPF-include it, the sites that link it. All are themselves expanded next round.
  23. 23Round 5: what depends on the addresses. Every hostname resolving to an address depends on it — if the address goes dark, they all do. SPF-IP senders trust it for mail.
  24. 24Round 5: what depends on the prefixes. Every IP inside the prefix depends on it being announced; the ASN that routes it is the shared-fate parent — its other prefixes are reached next round, unfolding the whole routing neighbourhood.
  25. 25Round 5: what depends on the networks. Every prefix an ASN announces depends on it for routing — if the network fails, that whole address space is unreachable.
  26. 26Round 6: what depends on the hostnames. Each hostname fans out to what would break without it — the domains it is the nameserver or MX for, the CNAMEs that point at it, the senders that SPF-include it, the sites that link it. All are themselves expanded next round.
  27. 27Round 6: what depends on the addresses. Every hostname resolving to an address depends on it — if the address goes dark, they all do. SPF-IP senders trust it for mail.
  28. 28Round 6: what depends on the prefixes. Every IP inside the prefix depends on it being announced; the ASN that routes it is the shared-fate parent — its other prefixes are reached next round, unfolding the whole routing neighbourhood.
  29. 29Round 6: what depends on the networks. Every prefix an ASN announces depends on it for routing — if the network fails, that whole address space is unreachable.
  30. 30Round 7: what depends on the hostnames. Each hostname fans out to what would break without it — the domains it is the nameserver or MX for, the CNAMEs that point at it, the senders that SPF-include it, the sites that link it. All are themselves expanded next round.
  31. 31Round 7: what depends on the addresses. Every hostname resolving to an address depends on it — if the address goes dark, they all do. SPF-IP senders trust it for mail.
  32. 32Round 7: what depends on the prefixes. Every IP inside the prefix depends on it being announced; the ASN that routes it is the shared-fate parent — its other prefixes are reached next round, unfolding the whole routing neighbourhood.
  33. 33Round 7: what depends on the networks. Every prefix an ASN announces depends on it for routing — if the network fails, that whole address space is unreachable.
  34. 34Round 8: what depends on the hostnames. Each hostname fans out to what would break without it — the domains it is the nameserver or MX for, the CNAMEs that point at it, the senders that SPF-include it, the sites that link it. All are themselves expanded next round.
  35. 35Round 8: what depends on the addresses. Every hostname resolving to an address depends on it — if the address goes dark, they all do. SPF-IP senders trust it for mail.
  36. 36Round 8: what depends on the prefixes. Every IP inside the prefix depends on it being announced; the ASN that routes it is the shared-fate parent — its other prefixes are reached next round, unfolding the whole routing neighbourhood.
  37. 37Round 8: what depends on the networks. Every prefix an ASN announces depends on it for routing — if the network fails, that whole address space is unreachable.
  38. 38Round 9: what depends on the hostnames. Each hostname fans out to what would break without it — the domains it is the nameserver or MX for, the CNAMEs that point at it, the senders that SPF-include it, the sites that link it. All are themselves expanded next round.
  39. 39Round 9: what depends on the addresses. Every hostname resolving to an address depends on it — if the address goes dark, they all do. SPF-IP senders trust it for mail.
  40. 40Round 9: what depends on the prefixes. Every IP inside the prefix depends on it being announced; the ASN that routes it is the shared-fate parent — its other prefixes are reached next round, unfolding the whole routing neighbourhood.
  41. 41Round 9: what depends on the networks. Every prefix an ASN announces depends on it for routing — if the network fails, that whole address space is unreachable.
  42. 42Round 10: what depends on the hostnames. Each hostname fans out to what would break without it — the domains it is the nameserver or MX for, the CNAMEs that point at it, the senders that SPF-include it, the sites that link it. All are themselves expanded next round.
  43. 43Round 10: what depends on the addresses. Every hostname resolving to an address depends on it — if the address goes dark, they all do. SPF-IP senders trust it for mail.
  44. 44Round 10: what depends on the prefixes. Every IP inside the prefix depends on it being announced; the ASN that routes it is the shared-fate parent — its other prefixes are reached next round, unfolding the whole routing neighbourhood.
  45. 45Round 10: what depends on the networks. Every prefix an ASN announces depends on it for routing — if the network fails, that whole address space is unreachable.
  46. 46Blast-radius recap. A count of everything that would be affected — dependent hosts, addresses, prefixes and networks — at the chosen depth.
  47. 47Ownership (WHOIS registrant). Names who owns the asset (registrant org, WHOIS email, registrar) so a blast-radius owner knows which party to contact when this asset fails or is a single point of failure.
  48. 48Supply chain across the stack. For a hostname input, traces each resolved address down to the announced prefix, routing ASN/network, registered prefix, and CDN/cloud vendor it depends on — the downstream supply chain the anchor's IP arm only reaches when given an IP directly.
  49. 49DNS-provider dependency. Rolls the asset's nameservers up to their operating provider (e.g. all ns*.google.com to google.com) so you see which DNS provider it depends on, not just raw nameserver names.
  50. 50Mail & SPF-sender dependency. Rolls MX and SPF-include hosts up to their mail provider apex, showing which mail/email-sender providers the asset depends on for deliverability.
  51. 51True origins behind the edge. De-CDNs the asset to its real origin IPs and networks so the dependency picture reflects where it actually runs, not just the CDN edge in front of it.
  52. 52Physical-facility dependency. Grounds the dependency chain in the physical data-center facilities the asset's hosting networks are present at — the deepest layer of what it depends on.