logo

Dangling DNS and the dangers of subdomain hijacking

ID: 50adec42-7fdc-5d35-b8a4-e1a624a68278

STIX ID: report--50adec42-7fdc-5d35-b8a4-e1a624a68278

Feed Name: The Spamhaus Project

Threat Score
50/100

Date Published: 2024-07-17

Date Updated: 2026-04-30

Author: The Spamhaus Team

...
...

The report explains how attackers can exploit dangling CNAMEs by registering the expired target domain and adding SPF entries in TXT records (including via SPF include mechanisms), allowing them to send mail from hijacked subdomains and potentially receive mail via added MX records — enabling phishing and malware distribution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.