Infoblox recently highlighted an interesting observation: one of the most common yet least addressed security risks is the dangling DNS record. This is not a new vulnerability, but rather administrative debt that accumulates over years, offering attackers a surprisingly easy pathway into an organization’s services. Dangling DNS records are an invisible security risk that cannot be solved by processes alone.

What Is a Dangling DNS Record?

The most typical example is a CNAME record pointing to an external service, such as an Azure Web App, an AWS S3 bucket, or a domain used for a marketing campaign. When the underlying service is decommissioned, the DNS record easily remains active.

If an attacker notices this before the organization does, they can create a cloud service with the same name or register the expired domain and redirect traffic. Users are then routed to an address that looks completely legitimate but is actually controlled by the attacker.

The same issue also applies to A and MX records. This is therefore not just about websites, but also about email and other business-critical services.

The Problem Isn’t DNS – It’s the Organization

Infoblox correctly notes that the root cause is rarely technical. In large organizations, external DNS is no longer managed by a single infrastructure team. Multiple parties are involved, such as:

  • Software development
  • DevOps teams
  • Azure, AWS, and Google Cloud environments
  • Marketing and communications (campaign domains)
  • Business units
  • Infrastructure team
  • Legal department managing trademarks and domain names

Anyone can set up new services, but no one necessarily owns their entire lifecycle. Cloud services have made deploying new services extremely easy. At the same time, the number of DNS records is constantly growing, without a natural process for removing them. In audits, it is typical to find that a company has thousands of domains, dozens of registrars and DNS providers, and numerous dangling DNS records.

Processes Alone Are No Longer Enough

Infoblox primarily recommends better processes and regular audits. This is a good starting point, but in practice, it is no longer sufficient. A modern enterprise may have:

  • Hundreds of developers
  • Multiple cloud platforms
  • Dozens of DevOps teams
  • Thousands of DNS records
  • Continuous campaigns and temporary services

It is not realistic to expect every project to remember to notify the infrastructure team when a service is decommissioned. This is not due to negligence, but because the operating model does not scale.

Automation Is Needed

In my view, the solution is not to add more instructions or approval chains, but to automate DNS (domain) lifecycle management. DNS should be a continuously monitored entity where automation identifies, for example:

  • Dangling CNAME, A, and MX records
  • Expired domain names
  • Decommissioned cloud services
  • DNS changes across different cloud environments
  • Anomalous delegations
  • New subdomains and their owners

At the same time, all stakeholders—development, infrastructure, security, marketing, and legal—should see the same up-to-date view of the organization’s DNS assets.

DNS Is a Company’s Digital Asset Register

DNS is no longer just a domain name service. In practice, it describes the company’s entire digital attack surface:

  • Public services
  • Cloud services
  • APIs
  • Email
  • Brand domains
  • Partner integrations

If this entity is managed with Excel spreadsheets, emails, and occasional audits, blind spots will inevitably emerge. Therefore, DNS management should be viewed as continuous asset management (Digital Asset Management), not as a series of individual change requests.

Attackers are already actively looking for dangling DNS records because they provide one of the easiest ways to hijack an organization’s trusted domain names. Organizations need to be able to find these errors automatically before attackers do. Dangling DNS records are an invisible security risk.

Processes remain important, but in today’s multi-cloud environments, they are not enough on their own. Continuous visibility, automated detection, and lifecycle management are required—otherwise, dangling DNS records will simply sit waiting for the next person to find them.

 

Hannu Rokka, Senior Advisor

5Feet Networks Oy