• Introducing DNS Takeover Alerts: Closing the Gap DMARC Cannot Cover

Introducing DNS Takeover Alerts: Closing the Gap DMARC Cannot Cover

by

Last Updated:
5 min read
Introducing DNS Takeover Alerts: Closing the Gap DMARC Cannot Cover

Your organization has done the hard work. You deployed SPF, DKIM, and DMARC across every sending domain and advanced to p=reject. On paper, your email authentication is complete.

There is, however, a way for an attacker to send emails from your brand that pass SPF, pass DMARC alignment, and land cleanly in the inbox, with no detection at any stage. The technique is called subdomain takeover, and DMARC enforcement cannot stop it.

Today, we are introducing a new alert type in PowerAlerts, built specifically to catch it: DNS Takeover Alerts.

The Problem: An Attack DMARC Was Never Designed to Stop

DMARC at enforcement is widely recognized as the gold standard in email authentication, and for good reason. It checks that an email claiming to come from a domain is actually authorized, and tells receiving servers to reject anything that is not. But this protection relies entirely on DNS records, and those records can easily be forgotten as infrastructure changes.

The-Problem--An-Attack-DMARC-Was-Never-Designed-to-Stop-

Consider a scenario that occurs more often than most teams realize. Your organization reaches p=reject across all sending domains. Months later, a developer decommissions a staging environment but does not remove its CNAME record, which still points to a cloud resource that no longer exists. An attacker identifies the dangling DNS record, claims the same cloud resource, provisions a mail server, and begins sending phishing emails from @staging.yourcompany.com.

The phishing messages pass SPF and DMARC, and reach inboxes, carrying your brand name with them. This is not a theoretical concern. The SubdoMailing campaign of February 2024 demonstrated the technique at scale, sending millions of fraudulent emails from hijacked subdomains belonging to fully DMARC-enforced brands. Enforcement alone leaves this attack surface entirely unmonitored.

The Solution: Introducing DNS Takeover Alerts

DNS Takeover Alerts is a new alert type within our PowerAlerts feature that continuously monitors your domain infrastructure for the DNS misconfigurations that make subdomain takeover possible. When a risk is detected, you receive an instant notification with a plain-language explanation of the issue and its remediation, allowing you to resolve it before an attacker discovers it.

The capability is built directly into the PowerAlerts module you already use. It sits alongside your existing DNS, Threshold, and Forensic alerts and follows the same configuration flow, so there is no new tool to learn and no separate dashboard to monitor.

How to Configure DNS Takeover Alerts

Setting it up takes three simple steps; the platform handles the rest:

Step 1: Select Domains/Domain Groups

DNS takeover alerts

Choose the domains or domain groups you want to monitor for takeover risks. Select individually or apply a group to cover many domains at once.

Step 2: Choose Alert Type

DNS takeover alerts

Select DNS Takeover from the list of alert types, sitting alongside your existing DNS, Threshold, and Forensic alerts.

Step 3: Set Alert Conditions

DNS takeover alerts

Enable the check types you want to run, from Dangling NS and MX to CNAME, SPF, and A/AAAA, or turn on all five for complete coverage.

Step 4: Select Notification Groups

DNS takeover alerts

Assign the team or contacts who should be notified when a risk is detected, so the right people can act the moment an alert fires.

Five Checks Covering the Full Attack Surface

Many platforms that address this risk cover only the most common cases. PowerDMARC’s DNS Takeover Alerts provide five distinct check types, including two that no other DMARC platform monitors.

1. Dangling NS (Critical)

Nameserver records pointing to a server that no longer exists. If an attacker registers the expired nameserver, they gain full DNS control of the subdomain. This is the highest-risk scenario.

2. SPF Subdomain Takeover (Critical)

SPF records with include: or redirect= directives pointing to expired domains. An attacker can register the domain, craft its SPF, and send authenticated email on your behalf. This check is evaluated across all five mechanisms: include, redirect, a, mx, and exists.

3. Dangling MX (Critical)

MX records pointing to a mail server hostname that no longer resolves. An attacker can provision a mail server at that hostname and intercept or impersonate your inbound email.

4. Dangling CNAME (High)

CNAME records pointing to a hostname that no longer resolves, a frequent result of cloud resource deletions or SaaS cancellations. An attacker can provision a resource at the same address and claim the subdomain.

5. Dangling A/AAAA (Warning)

A or AAAA records pointing to IP addresses that may no longer be under your control and could be reclaimed by a third party.

The PowerDMARC Advantage

The final two checks, Dangling MX and Dangling A/AAAA, represent coverage that is not available elsewhere in the DMARC market.

Why This Matters

DMARC enforcement is a critical foundation, confirming that your legitimate senders are aligned and authorized. DNS Takeover Alerts extend that protection to the surrounding DNS infrastructure, giving you a more complete defense:

  • Identify and remediate misconfigurations before an attacker can exploit them, rather than responding after a fraudulent email has been sent.
  • Five check types monitor the full range of dangling records, including Dangling MX and Dangling A/AAAA scenarios not covered elsewhere in the DMARC market.
  • An initial scan runs immediately on save, and ongoing monitoring keeps watch as your DNS records change over time.
  • Every alert includes the severity, the affected subdomain, and a plain-language message that tells you exactly what to fix.
  • The feature lives inside the PowerAlerts module you already use, with no new tool to learn and no separate dashboard to monitor.

Availability

DNS Takeover Alerts are available on PowerDMARC Enterprise plans. To get started, open the PowerAlerts module, create a new DNS Takeover alert, and run your first scan, or contact our team for more information.

DNS takeover alerts