Dangling DNS can point to somebody else's resource
A DNS record left pointing at a cloud resource you have deleted is an invitation.
The name still resolves, the service it pointed at is gone, and whoever claims that address or storage bucket next receives your traffic under your domain name. It happens constantly during decommissioning, because deleting the resource and deleting the record are separate jobs owned by different people, and only one of them has an obvious deadline.
More on DNS and domains
- DNS is a directory, not proof of safetyIt only answers where
- DNSSEC signs answers but does not hide themA sealed postcard
- Encrypted DNS protects the resolver path, not the destinationCovered to the desk, open to the door
- Registrar compromise can outrank server securityIt all hangs from one fitting
- Registrar locks add friction to domain theftThe pin that makes them stop
- Subdomain takeover begins with abandoned ownershipNobody minding the stall
