DNS security
Dangling DNS checker
Find CNAME records that point at a name which no longer exists. A dangling CNAME usually means a hosted service was removed while its DNS record stayed behind, and on some platforms someone else could claim the name it points at.
What this checks
- The domain and its
www.name, or for a subdomain, that name only. - Whether each name is a CNAME, and where its chain of aliases ends.
- Whether the final target exists: a chain that ends in a name that does not exist (NXDOMAIN), with no addresses, is dangling.
- Whether that target is on a platform where names can be claimed by others; if so, the finding is raised to High.
- The A and AAAA records for each name, so you can see what it resolves to when it does.
What the result means
A CNAME makes one name an alias for another, often a name at a hosting, storage or software platform. When the service is deleted, the platform's name stops existing but your alias remains, and your name stops resolving.
A pass means each name either has no CNAME or its CNAME resolves. A finding means the chain ends in a name that does not exist. It is Medium severity, and High with medium confidence when the target is on a platform where names can be claimed by others, because whoever claims it could serve content on your name.
The finding says the record is stale. It does not claim a takeover is possible: that depends on the platform and on whether the name can still be registered there. Either way, remove the record or recreate the service.
How to fix common issues
CNAME points at a name that does not exist
Remove the CNAME record if the service is no longer used, or recreate the resource it points at. Review DNS whenever a hosted service is retired.
Domain has no address records
No action is needed if the domain is not meant to serve a website. Otherwise add A and/or AAAA records at your DNS provider.
Cyber Essentials and ISO 27001
Neither Cyber Essentials nor ISO 27001 names dangling DNS. A clean result is technical evidence for broader ISO/IEC 27001:2022 Annex A controls: 5.9 Inventory of information and other associated assets, since a record left behind for a retired service shows the inventory has fallen out of date, and 8.9 Configuration management.
The organisation still has to establish who owns each DNS record, a decommissioning step that removes records when a service is retired, and a regular review of the zone. The check shows the records it looked at today, not that process.
Scope and limitations
- It checks the domain and its
www.name, or the one subdomain you enter. It does not discover other subdomains: list them with the subdomain finder and check each name. - It flags only CNAME chains that end in a name that does not exist. A CNAME whose target still resolves passes, even if the resource behind it has been deleted, and other record types pointing at resources you no longer hold are not judged.
- It never tries to claim the target or serve content, so it does not test whether a takeover is possible. Which platforms count as claimable comes from a list of hosting names that may not be complete.
Related guides
Questions
- What is a dangling DNS record?
- A DNS record that still points at something that has gone. Most often it is a CNAME to a hosted service that was deleted, so the target name no longer exists. That is the case this tool looks for.
- What is a subdomain takeover?
- When a CNAME points at a platform name that anyone can create, and that name is free, someone else can claim it and serve their own content on your subdomain. This check flags the stale record and rates it High on such platforms; it does not attempt or confirm a takeover.
- How do I check all my subdomains?
- Run this check for each name. The subdomain finder lists names that have appeared in public certificates, which makes a good starting list, but it misses names that never had a certificate of their own, such as those covered only by a wildcard.
Related security tools
- Subdomain finder - Find a domain's subdomains in public certificate transparency logs.
- DNS checker - Look up a domain's A, AAAA, CNAME, MX, TXT, NS, SOA, CAA and DS records through public resolvers.
- DNS security checker - Check a domain's address records, nameserver redundancy, CAA, DNSSEC and dangling CNAMEs.
- Website security checker - Check a domain's DNS, email authentication, TLS, security headers and public technology in one pass.

