1 دقائق قراءة
هذا المحتوى متاح حاليًا باللغة الإنجليزية فقط.
The main threats to DNS
| Threat | What happens | Core control |
|---|---|---|
| Registrar account takeover | All name servers are pointed at the attacker | Strong MFA and registrar lock |
| DNS spoofing | Users are sent to forged IP addresses | DNSSEC |
| Subdomain takeover | A subdomain pointing at a deleted cloud resource is claimed | Regular inventory and cleanup of stale records |
| Unauthorized certificate | Another authority issues a certificate in your name | CAA record and CT monitoring |
| Expired domain | The domain is re-registered and email traffic captured | Auto-renewal and a calendar |
Checklist
- Registrar account: Hardware key or app-based MFA, few privileged users and change notifications.
- Transfer and update locks: clientTransferProhibited on; consider registry lock for critical domains.
- DNSSEC: Sign the zone and publish the DS record correctly at your registrar.
- CAA: Allow only the certificate authorities you actually use.
- Email records: Complete SPF, DKIM and DMARC; null MX and
p=rejectfor domains that never send mail. - Inventory: Regularly remove unused subdomains and CNAMEs pointing to third-party services.
- Monitoring: Watch DNS changes and certificate transparency logs; an unexpected record is the first warning sign.
See where you stand
DNS Lookup shows all your records plus DNSSEC and CAA status. Subdomain Finder lists your public subdomains from certificate transparency logs. WHOIS Lookup lets you check the transfer lock and expiry date.
Professional support
For an architecture and configuration review of your DNS, see our DNS Security service.



