Scan every DNS record. Every zone. Every day.

Catch dangling subdomains, exposed databases, expiring certificates, and broken email authentication before they make the news. Continuous attack-surface management for every record across every provider.

Native API integrations, read-only by default
  • AWS Route 53
  • Cloudflare
  • Google Cloud DNS
  • Azure DNS
  • CSC Domain Manager
  • UltraDNS

What gets scanned · every record, every day

Deep coverage, no configuration.

DNS & hosting

TLS & HTTP

  • Certificate expiry
  • Hostname mismatch
  • Chain-of-trust validation
  • Weak cipher detection
  • HTTP status codes (4xx / 5xx)
  • Redirect chain mapping

Email authentication

  • SPF validated against RFC 7208
  • DKIM syntax per RFC 6376
  • DMARC policy per RFC 7489
  • MTA-STS per RFC 8461
  • Spoofable configs flagged (+all, missing DMARC)

Visual & content

  • Headless Chromium screenshots
  • Perceptual hash deduplication
  • Redirect-chain grouping
  • Unexpected content detection
The threat isn't hypothetical

Abandoned subdomains are being exploited right now.

Every one of these incidents started with a DNS record no one remembered to clean up. Attackers scan for them automatically. The question isn't whether you have any - it's whether you'll find them first.

  • Active · 2025–2026

    Hazy Hawk is hijacking the brands you trust

    An ongoing threat-actor campaign tracked by Infoblox has taken control of forgotten subdomains at Bose, Panasonic, Deloitte, and the US Centers for Disease Control - plus 34+ universities including Berkeley, Columbia, and Washington University in St. Louis - serving malware, fake antivirus warnings, and tech-support scams from domains users already trust.

    TechRadar · Infoblox research
  • 2020

    670 forgotten Microsoft subdomains

    Researchers at Vullnerability.com identified 670+ abandoned Microsoft subdomains that attackers could claim, including identityhelp.microsoft.com and data.teams.microsoft.com. A separate researcher found another 280 over the following two years. Microsoft fixed only a handful.

    Sophos · Naked Security
  • 2017

    One CNAME, and Uber's entire SSO was exposed

    A single forgotten DNS record (saostatic.uber.com pointing to an unregistered CloudFront distribution) put Uber's single sign-on at risk. Because cookies were shared across *.uber.com, one subdomain takeover would have unlocked session hijack on every Uber property. Caught by a researcher - and still took Uber two months to patch.

    ZDNet · Arne Swinnen disclosure
First finding in under 10 minutes · full scan in ~5 once connected

From silent drift to governed control.

Connect once. Every zone is continuously scanned for exposed ports, invalid records, and dangling subdomains. Investigate, remediate, and monitor - without leaving the platform.

  1. INTEGRATE~5 min
    01

    Connect every provider

    Create scoped API credentials at your DNS provider and paste them in. We provide step-by-step guides for each - read-only by default, controlled remediation when you're ready.

  2. SCAN~5 min
    02

    Zones discover and scan in parallel

    Records are port-scanned, certificate-checked, HTTP-probed, and screenshotted as they stream in. First findings start landing within a couple of minutes - no waiting for a full sync to finish.

  3. INVESTIGATEAny time
    03

    Triage with full context

    Every record carries screenshots, ISP info, open ports, and certificate details. Add notes, assign status, and suppress accepted risks with a full audit trail.

  4. MONITORDaily
    04

    Alerts stay ahead of drift

    Daily re-scans open new findings and auto-close resolved ones. Route alerts to Slack, Teams, email, or a webhook - real-time or scheduled.

One platform for every DNS exposure.

Continuous detection, investigation, remediation, and workflow orchestration - for the entire domain portfolio, across every provider you operate.

Enterprise DNS integration

Securely connect and govern your entire DNS estate across providers.

  • Scoped API credentials with read-only or controlled remediation
  • Native AWS Route 53, Cloudflare, GCP, Azure, CSC, UltraDNS
  • Web forwards and provider-specific record types
  • Extensible framework for additional platforms

Consolidated inventory

One source of truth for zones, records, certificates, IPs, screenshots and forwards.

  • Cross-provider, cross-registrar visibility
  • Rapid investigation of any externally-resolvable asset
  • Reduce risk from fragmented DNS operations

Continuous change detection

Reconcile drift across the estate without lifting a finger.

  • Catch changes made outside approved workflows
  • Auto-validate whether risks have been remediated
  • Close resolved findings without manual intervention
  • Real-time accuracy across every provider

See what's actually being served.

Every hostname screenshotted automatically. Spot takeover pages, brand misuse, and unexpected applications at a glance - then jump straight to the originating record.

  • Every web hostname, captured

    Headless Chromium renders the real page - same TLS, same redirects, same JavaScript. Full-size screenshots, not HTML scrapes.

  • Perceptual hashing groups duplicates

    We fingerprint each screenshot with a perceptual hash so identical or near-identical pages collapse into a single finding. One parked-domain template, reviewed once.

  • Redirect chains collapse automatically

    Hostnames that redirect to the same destination are grouped together. Investigate distinct surfaces, not hundreds of rows of the same WordPress landing page.

Built for operations teams

Delete with confidence.

Cleaning up DNS is risky work. Delete the wrong record and you take down production. That's why every destructive action in DNS Watchdog is reversible - by design.

Every change is tracked and reversible, so your team can clean up DNS without the fear of breaking production.

  1. Step 01

    Pre-deletion snapshot

    Before any deletion, DNS Watchdog captures the exact record configuration - type, value, TTL, priority, and provider-specific metadata - so nothing is lost.

  2. Step 02

    One-click restore

    If a record was removed in error, restore it with a single click. The original configuration is re-created at your provider exactly as it was, typically in seconds.

  3. Step 03

    Full change log

    Every delete, restore, and status change is logged with who did it and when. Use the change log for incident review, team handover, or tracking what changed.

Simple, per-zone pricing.

Transparent per-zone pricing. No seats, no per-scan metering, no tiers hiding features behind a sales call.

Starting at
£1/zone/month

£500/month minimum

Pay only for the zones you monitor. The minimum keeps us focused on customers who have enough DNS estate to make continuous monitoring worthwhile.

  • Daily scans of every record in every zone
  • All 6 native DNS provider integrations
  • Full email auth validation (SPF, DKIM, DMARC, MTA-STS)
  • 37 port checks, TLS analysis, HTTP scanning
  • Visual record browser with screenshot capture
  • Slack, Teams, email, and webhook notifications
  • Role-based access and full audit trail

Enterprise

Custom

For teams with 5,000+ zones, custom compliance requirements, or procurement processes that need more than a credit card.

  • Everything in the per-zone plan
  • Volume pricing for 5,000+ zones
  • SSO / SAML and SCIM provisioning
  • Custom data residency (EU, UK, or US)
  • Dedicated onboarding and Slack channel
  • Signed DPA, custom MSA, and security review support
  • Annual invoicing and procurement-friendly terms

A good fit if

  • You manage 500+ zones across two or more DNS providers
  • You've been burned by DNS drift or have seen the headlines
  • Ops and security share responsibility and need an audit trail
  • You need continuous coverage, not a one-off audit

Probably not for you if

  • You manage fewer than ~500 zones
  • Single-provider with mature internal tooling

Answers to common questions.

Everything buyers ask us before they book a demo. Missing something? Drop us a note.

Which DNS providers does DNS Watchdog support?

DNS Watchdog has native integrations for AWS Route 53, Cloudflare, Google Cloud DNS, Azure DNS, CSC Domain Manager, and Neustar UltraDNS. The integration framework is extensible - get in touch if you need another provider and we'll scope it.

Do I have to give DNS Watchdog write access?

No. Read-only is the default. With read-only credentials, DNS Watchdog detects and reports every issue and auto-closes findings when you remediate in your provider directly. Write access only enables one-click deletion and rollback for teams that want remediation inside the platform.

How long does onboarding take?

Under ten minutes for most customers. Connect a provider (paste IAM or API credentials), zones auto-discover in a couple of minutes, and your first scan completes in another few. You'll usually have your first finding in Slack within 15 minutes.

What happens if I accidentally delete a DNS record?

DNS Watchdog snapshots every record before deletion. If a record was removed in error, you can restore it with a single click - the original configuration is re-created at your provider.

How often are my zones scanned?

Every record in every connected zone is scanned daily by default. You can trigger an on-demand rescan at any time. Records are re-checked the moment you make a change via the platform so findings close without waiting for the next daily cycle.

Where is my data stored?

DNS Watchdog runs on AWS in the UK. DNS provider credentials are encrypted at rest with AWS KMS in SSM Parameter Store, accessed only to perform the scans you've configured. Full details are in our Data Protection Policy.

Your next DNS incident is hiding in a zone you forgot about.

DNS Watchdog finds it first. Connect your providers in minutes and get continuous scanning, instant alerts, and one-click remediation across every record.

Built by practitioners.

DNS Watchdog is built by Neil Saunders, an infrastructure and operations leader who spent years managing large DNS portfolios across multiple providers and watched the same problem play out everywhere: records accumulating, ownership unclear, and security exposure growing silently in the background.

DNS Watchdog is the platform he wished he'd had. We're a UK-based team focused on turning DNS from an unmanaged blind spot into a governed, continuously monitored security domain.

DNS Watchdog Ltd.
167-169 Great Portland Street, 5th Floor
London W1W 5PF, United Kingdom