u/PlasmaJam

▲ 187 r/sysadmin

Parked domains protection

I have access to about 200 DNS zones of companies, some of which have up to 400 domains in their portfolios, and none of them hardens their parked domains. The best I've seen so far was DMARC p=reject on a few random parked domains inside a few (not even a dozen) DNS zones, mostly at companies that have an in-house IT guy.

The other 3 DNS records that nobody adds are:

  • Null MX, so the domain refuses inbound mail
  • SPF -all, so the envelope sender can't be forged
  • DKIM wildcard, to revoke every forgotten key, including keys from whoever owned the domain before you.

Every unhardened parked domain is impersonation infrastructure used against your company. Targeting your clients. And it's just 5 min per domain or a basic script with an API call for bulk deployment.

The cheapest & highest-leverage security work in your stack.

Type Hostname Value
MX @ .
TXT @ v=spf1 -all
TXT *._domainkey v=DKIM1; p=
TXT _dmarc v=DMARC1; p=reject
reddit.com
u/PlasmaJam — 3 days ago
▲ 378 r/DMARC+2 crossposts

Expired DMARC reporting endpoint exposed a NYSE Fortune 1000's infrastructure for $10

I registered an expired DMARC reporting domain (gca-emailauth[.]org) for $10. It had been published as the aggregate-reporting address in Global Cyber Alliance DMARC training docs going back to a 2019 bootcamp, and at some point it lapsed.

Shortly after registration, aggregate DMARC reports for 86 domains across 20+ organizations started arriving.

56 belonged to The Toro Company (NYSE-listed), including myturf[.]com, their distributor platform, which sits at p=none. The rest - University of Wisconsin–Stevens Point (14 subdomains), the North Carolina School of Science and Mathematics, Ennis ISD (Texas), Great Prairie AEA (an Iowa education agency serving 35,000 students), two county governments, and several commercial domains.

For most of these it was a second rua address sitting behind a working commercial processor (Proofpoint, in Toro's case). Reports still arrived at the primary.

GCA's engineers later traced it to a former partner who'd held the domain and let it lapse - the dependency was never written down.

As of my last sweep, 65 of the 86 still publish the endpoint. We disclosed to everyone whose reports we were receiving; only 21 domains stopped publishing the endpoint, and almost nobody replied.

After 8 months of owning the domain, we coordinated a transfer back to GCA.

sh.consulting
u/PlasmaJam — 9 days ago