Skip to content

DNS security

Dangling DNS checker

Find CNAME records that point at a name which no longer exists. A dangling CNAME usually means a hosted service was removed while its DNS record stayed behind, and on some platforms someone else could claim the name it points at.

Checked from Ironfang Security's scanner address with the same low-impact limits as a scan. Nothing you enter is kept.

What this checks

What the result means

A CNAME makes one name an alias for another, often a name at a hosting, storage or software platform. When the service is deleted, the platform's name stops existing but your alias remains, and your name stops resolving.

A pass means each name either has no CNAME or its CNAME resolves. A finding means the chain ends in a name that does not exist. It is Medium severity, and High with medium confidence when the target is on a platform where names can be claimed by others, because whoever claims it could serve content on your name.

The finding says the record is stale. It does not claim a takeover is possible: that depends on the platform and on whether the name can still be registered there. Either way, remove the record or recreate the service.

How to fix common issues

CNAME points at a name that does not exist

Remove the CNAME record if the service is no longer used, or recreate the resource it points at. Review DNS whenever a hosted service is retired.

More in the Dangling DNS records check reference

Domain has no address records

No action is needed if the domain is not meant to serve a website. Otherwise add A and/or AAAA records at your DNS provider.

More in the Address records check reference

Cyber Essentials and ISO 27001

Neither Cyber Essentials nor ISO 27001 names dangling DNS. A clean result is technical evidence for broader ISO/IEC 27001:2022 Annex A controls: 5.9 Inventory of information and other associated assets, since a record left behind for a retired service shows the inventory has fallen out of date, and 8.9 Configuration management.

The organisation still has to establish who owns each DNS record, a decommissioning step that removes records when a service is retired, and a regular review of the zone. The check shows the records it looked at today, not that process.

Scope and limitations

Related guides

Questions

What is a dangling DNS record?
A DNS record that still points at something that has gone. Most often it is a CNAME to a hosted service that was deleted, so the target name no longer exists. That is the case this tool looks for.
What is a subdomain takeover?
When a CNAME points at a platform name that anyone can create, and that name is free, someone else can claim it and serve their own content on your subdomain. This check flags the stale record and rates it High on such platforms; it does not attempt or confirm a takeover.
How do I check all my subdomains?
Run this check for each name. The subdomain finder lists names that have appeared in public certificates, which makes a good starting list, but it misses names that never had a certificate of their own, such as those covered only by a wildcard.

Related security tools