A nameserver delegation can fail when the referenced server stops serving the zone. A more serious risk arises if an unrelated party gains control of a delegated nameserver's infrastructure or registrable domain. These are separate conditions: a failed response or an expiry-looking hostname does not prove that an attacker can take control.
Historical candidates and what remains unverified
The original analysis reported 1.55 million candidate lame delegations among 240.3 million domains across 1,929 TLD zone files, including a group of approximately 503,000 labeled as expired-nameserver cases. It highlighted 352,000 associated with dns-expired.com variants and 94,000 with onamae-expired.com variants. These figures are preserved as historical reported classifications. The original snapshot manifests, query outputs and timestamped ownership checks have not been reproduced for this update.
Names such as dns-expired.com may be intentional registrar parking infrastructure. Their wording does not establish that the nameserver's registrable domain has expired, is available, or is maliciously controlled. Domain registration expiry itself also does not mean immediate availability. Check registration lifecycle and control separately from DNS service behavior.
| Subdomain Takeover | NS Domain Takeover | |
|---|---|---|
| Attack surface | One CNAME → one subdomain | One NS domain → hundreds to thousands of domains |
| What's controlled | HTTP content on the subdomain | DNS answers for delegating domains whenever the hijacked nameserver is queried (A, MX, TXT, everything). Reliable control needs all nameservers under the expired domain, and fails against a DNSSEC-signed delegation |
| Email interception | Not directly possible | Full MX control → receive all email |
| TLS certificate issuance | Only for the specific subdomain | DNS-01 validation for any delegating domain |
| Detection difficulty | Moderate (check CNAME targets) | Low awareness, rarely scanned for |
| Cost to execute | Free (cloud service signup) | $10-15 (domain registration) |
A further 12,800 records were historically associated with dns1.stabletransit.com and related hostnames. That observation does not establish that Rackspace retired its DNS service or stopped serving those zones. No verified provider retirement evidence is supplied by this analysis.
How delegation control differs from a dangling CNAME
A CNAME points one owner name at another name. An NS delegation identifies servers trusted to answer for a zone, as described in RFC 1034. Unauthorized control of a delegated server can therefore affect more than a single web endpoint.
The outcome still depends on which servers a resolver selects, whether other legitimate authorities remain, and whether validation succeeds. A properly validated DNSSEC chain rejects forged data lacking valid signatures. Control of one nameserver does not guarantee every query, email delivery or certificate-validation attempt will use that server. See subdomain takeover for the separate application-service case.
Verify an owned domain without claiming third-party infrastructure
- Record the parent delegation and your provider's intended nameserver names. Compare both with the zone's own NS records.
- Resolve each nameserver's addresses and query every intended authoritative server directly for the zone's SOA. Check the response code, authoritative flag and expected data, rather than availability alone.
- Check registration and provider status through current official sources. Preserve the time and response of each check; a present-day result does not prove historical ownership.
- Validate the DNSSEC chain where used. A visible DS or DNSKEY alone is not proof of a valid chain.
- Ask the registrar or DNS provider to resolve unexplained delegation differences. Do not register or claim someone else's former infrastructure to test a hypothesis.
Use the DNS Inspector for known-name lookups and compare the result with your registrar and provider configuration. Typo-like nameservers require the same ownership checks before being labeled hostile.
Migrate and monitor deliberately
Keep old authoritative service available during a planned delegation transition. Copy the complete zone, verify the new authorities, coordinate DNSSEC, then change the parent delegation and allow relevant cached references to expire before retiring old infrastructure. The host-migration checklist covers the operational sequence.
Monitor direct authoritative responses and the registration/provider accounts controlling nameserver infrastructure. Alert on unexpected delegation, availability or ownership changes. A healthy website alone is not evidence that every delegated server is healthy.

