CertaDNS
Glossary

Attacks

Dangling record

A DNS record pointing at a resource that no longer exists or is no longer yours — typically a CNAME to a SaaS platform after the account lapsed. Whoever can claim that resource next controls a hostname under your domain.

Defined in NIST SP 800-81r3.

Where this appears

The lessons that use this term, and what each is for.

DKIM PractitionerNo key for signatureSeparate a missing key, a wrong selector and a broken delegation from one another.DKIM PractitionerWhat decaysFind the selectors, delegations and vendors that have quietly stopped being correct.Domain Security FundamentalsDangling recordsExplain how a leftover DNS record hands an attacker a hostname you own.Domain Security FundamentalsFinding them before someone else doesTriage a list of CNAME targets for takeover risk and state the retirement rule that prevents recurrence.DNS Security PractitionerThree kinds of danglingRank a dangling CNAME, NS and MX by what each one hands an attacker.DNS Security PractitionerRetiring a service safelyDefine a decommission order that cannot leave a record pointing at claimable infrastructure.Brand ProtectionWatching your own estateDetect an unauthorised change to your own records before anybody outside does.Brand ProtectionThe window closesExplain why evidence gathered after a response has begun is worth nothing.Domain Trust ArchitectureWhat to do with no budgetList the controls that cost nothing but attention, and deploy them in an afternoon.Domain Trust ArchitectureWhat decays, and how fastGive each control a review cadence derived from how quickly it goes wrong.Domain Security PractitionerThe CNAME from 2024Work a dangling record whose original owner and purpose are both unknown.Domain Security PractitionerA year laterDescribe what a successful programme looks like twelve months on, and how you would know.