Skip to main content

DNS Security & Discovery

Infracast automatically discovers and audits DNS infrastructure across AWS Route53, Azure DNS, and GCP Cloud DNS โ€” surfacing misconfigurations, subdomain takeover risks, and zone hygiene issues in real time.

Overviewโ€‹

DNS is a critical but often overlooked attack surface. Misconfigured records can expose internal services, enable subdomain hijacking, or leak zone data. Infracast integrates DNS zone discovery directly into its unified asset graph, correlating DNS records with the cloud resources they point to.

Supported Providersโ€‹

ProviderAuth MethodCapabilities
AWS Route53IAM Role / Access KeyZone discovery, record enumeration, health check correlation, DNSSEC status, query logging
Azure DNSService PrincipalPublic and private zone discovery, record enumeration, email security record detection (SPF, DMARC, DKIM)
GCP Cloud DNSService AccountZone discovery, record enumeration, DNSSEC configuration and key specs

DNS Zone Discoveryโ€‹

Once connected, Infracast discovers:

  • All hosted zones (public and private)
  • All record sets (A, AAAA, CNAME, MX, TXT, NS, SOA, PTR, SRV)
  • TTL values and routing policies
  • Health check associations (Route53)
  • DNSSEC signing status and key specs

Discovered zones and records appear as nodes in the Infracast asset graph, linked to the cloud accounts and resources they belong to.

How to Enableโ€‹

  1. Navigate to Settings โ†’ Discovery Sources
  2. Click Add Source โ†’ select your DNS provider (Route53 / Azure DNS / GCP Cloud DNS)
  3. Provide credentials (IAM role ARN, service principal, or service account)
  4. Click Save & Discover โ€” discovery runs immediately and on your configured schedule

DNS Security Rulesโ€‹

Infracast ships 10 DNS security rules (hot-reloadable YAML, part of the standard compliance pack):

Rule IDNameSeverity
DNS-001DNSSEC Not Enabled on Public ZoneHIGH
DNS-002DNS Query Logging DisabledMEDIUM
DNS-003Dangling CNAME โ€” Potential Subdomain TakeoverCRITICAL
DNS-004Missing CAA RecordMEDIUM
DNS-005Missing SPF RecordHIGH
DNS-006Missing DMARC RecordHIGH
DNS-007Wildcard DNS Record in Production ZoneMEDIUM
DNS-008Stale DNS Record โ€” Target Not FoundHIGH
DNS-009DNS Zone Missing DKIM RecordsMEDIUM
DNS-010Long TTL on Critical RecordsLOW

All rules appear in the Findings view with remediation steps, framework mappings (NIST 800-53 SC-20, SC-21, SC-22), and direct links to the affected records.

Subdomain Takeover Analyzerโ€‹

The Subdomain Takeover Analyzer checks every CNAME record against a database of known takeover-vulnerable services and flags records pointing to unclaimed endpoints.

Checked services include:

  • AWS S3, CloudFront, Elastic Beanstalk
  • Azure App Service, Azure Blob Storage, Azure Cloud App, Azure Traffic Manager
  • Heroku, GitHub Pages
  • Shopify, Zendesk, Ghost, Pantheon

How it works:

  1. Infracast enumerates all CNAME records in discovered zones
  2. Each target is checked against the known-vulnerable service database
  3. Records pointing to unclaimed or deleted resources are flagged as Critical findings
  4. Affected records appear in the graph with a takeover-risk indicator

Common Takeover Scenariosโ€‹

  • CNAME pointing to an S3 bucket that no longer exists
  • Subdomain pointing to a decommissioned Heroku app
  • Internal service CNAME pointing to a deleted Azure App Service
  • GitHub Pages CNAME where the repository was deleted or made private

Asset Graph Integrationโ€‹

DNS records are first-class nodes in the Infracast asset graph, linked to cloud accounts and the resources they reference:

[Route53 Zone: example.com]
โ”œโ”€โ”€ [A Record: api.example.com โ†’ 54.1.2.3]
โ”‚ โ””โ”€โ”€ [EC2 Instance: i-abc123]
โ”œโ”€โ”€ [CNAME: blog.example.com โ†’ acme.github.io] โš  TAKEOVER RISK
โ””โ”€โ”€ [MX Record: example.com โ†’ mail.example.com]
โ””โ”€โ”€ [A Record: mail.example.com โ†’ 54.4.5.6]

This enables cross-domain attack path analysis โ€” for example, a subdomain takeover can chain into phishing campaigns or cookie theft against the parent domain.

UI โ€” DNS Security Pageโ€‹

Three tabs are available:

Zones โ€” table with provider badge, zone type (public/private), record count, DNSSEC status, query logging, SPF, DMARC indicator badges. Click to expand zone records inline.

Subdomain Takeover Risks โ€” severity-sorted list of dangling CNAMEs. Each entry shows the zone, record name, CNAME target, matched vulnerable service, risk level, and a one-click remediation guide.

DNSSEC Status โ€” coverage percentage (zones with DNSSEC enabled / total), per-zone DNSSEC detail table.

Summary stat cards at the top: Total Zones ยท Total Records ยท Takeover Risks ยท Zones Without DNSSEC.

Compliance Mappingโ€‹

DNS security rules map to the following framework controls:

FrameworkControlMapped Rules
NIST 800-53SC-20, SC-21, SC-22DNS-001 through DNS-010
CIS Controls9.2, 12.1DNS-001, DNS-003, DNS-004
FedRAMPSC-20, SC-21DNS-001, DNS-003
CMMCSC.L2-3.13.8DNS-003, DNS-004
PCI-DSS6.4.3, 11.3DNS-001, DNS-002

Permissions Requiredโ€‹

AWS Route53โ€‹

{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"route53:ListHostedZones",
"route53:ListResourceRecordSets",
"route53:GetHealthCheck",
"route53:ListHealthChecks"
],
"Resource": "*"
}
]
}

Azure DNSโ€‹

Required role: DNS Zone Contributor (read-only operations only; Infracast does not modify records)

GCP Cloud DNSโ€‹

Required role: roles/dns.reader

API Referenceโ€‹

# List all discovered DNS zones
GET /api/v1/tenants/{tenantID}/dns/zones

# Get a specific zone
GET /api/v1/tenants/{tenantID}/dns/zones/{zoneID}

# List DNS records across all zones
GET /api/v1/tenants/{tenantID}/dns/records

# List subdomain takeover risks
GET /api/v1/tenants/{tenantID}/dns/takeover-risks

# Check DNSSEC status
GET /api/v1/tenants/{tenantID}/dns/dnssec-status

# Get DNS-related findings
GET /api/v1/tenants/{tenantID}/findings?category=dns
API paths corrected 2026-09-14

DNS endpoints are tenant-scoped. The previously documented global DNS paths and a per-zone takeover-scan POST do not exist. Takeover risks are returned by /api/v1/tenants/{tenantID}/dns/takeover-risks.

Troubleshootingโ€‹

No zones discoveredโ€‹

  • Verify credentials have the required read permissions
  • Check that the DNS provider is listed under Settings โ†’ Discovery Sources
  • Review discovery logs under Settings โ†’ Discovery โ†’ History

Takeover scan shows false positivesโ€‹

Some CNAME targets that appear unclaimed may belong to private services not visible from the scanner's vantage point. Use the Mark as Accepted Risk action on the finding to suppress with justification.