Definition · Subdomain Enumeration
What is Dangling DNS Record?
A dangling DNS record is a pointer to nothing. The DNS entry is valid and resolves, but the thing on the other end has been deleted, released, or moved. Because the name still works and still belongs to your domain, whoever manages to occupy the vacated resource gets to serve content under your hostname.
How records end up dangling
- A cloud service, bucket, or app platform tenant is deleted while its CNAME remains
- A virtual machine is destroyed and its public IP address returns to the provider’s pool, still referenced by an A record
- A project ends, its infrastructure is torn down, and DNS is never part of the decommissioning checklist
- A supplier relationship ends but the CNAME delegating a subdomain to them stays
The common factor is that DNS is managed separately from the resources it names, often by a different team.
Why it matters for external exposure
A dangling CNAME to a claimable service is the precondition for subdomain takeover. Dangling A records carry a related risk: if the address is reassigned, the new occupant inherits traffic sent to your hostname, and any cookies scoped to your parent domain, session flows, or CSP allowances that trust the subdomain go with it. Certificate issuance is also affected, since some validation methods rely on control of the name.
Finding and preventing them
Compare your DNS zones against your live resources rather than auditing each in isolation, and check whether each CNAME target actually exists. Make DNS cleanup a required step when decommissioning anything, and keep an owner recorded for every record so orphaned entries have someone to ask. Continuous monitoring matters here because the record is harmless until the moment the resource is released.
Related concepts
Passive DNS helps identify names worth checking, asset discovery provides the resource side of the comparison, and subdomain enumeration finds the records nobody remembered creating.