Passive DNS is a historical database of DNS answers — a record of which domain names resolved to which IP addresses, and when. Where a normal DNS lookup tells you where a domain points right now, passive DNS tells you where it pointed last month, last year, and every change in between.
That history is a powerful pivot. It reveals infrastructure a target has since abandoned, links domains that once shared an IP, and exposes the movement of malicious hosts as they hop between providers. Passive DNS is collected by sensors watching real resolutions, so it captures records that were never meant to be found and that current lookups would miss entirely.