Skip to main content
•CONTINUOUS ATTACK SURFACE SENTINELRFC 7208 / 7489 / 8461

Continuous Perimeter Surveillance Built for Security Engineers

SubdomainWatch is an autonomous Attack Surface Management (CASM) platform and Shift-Left sentinel. We eliminate dangling DNS takeovers, RFC 7208 SPF lookup exhaustion, and SSL/TLS expiration blackouts through continuous verification and pre-merge Terraform gates.

42
Cloud Signatures
AWS, GitHub, Heroku, Azure
≤ 10
RFC 7208 SPF Limit
Zero PermError drops
100%
Shift-Left IaC Gate
Pre-merge Terraform scanner
0
SSRF Egress Risk
Strict NetGuard RFC 1918 block
// 01. THE GENESIS—WHY MODERN DNS PERIMETERS ROT

The Cloud Decommissioning Paradox

Modern cloud velocity creates two structural perimeter failures that traditional port scanners miss:

DECOMMISSIONING LEAKCVE SURFACE

Dangling CNAME Takeovers

When S3 buckets, Heroku dynos, or CDN origins are deleted, active CNAME records frequently linger in DNS. Attackers register the abandoned target namespace to claim your subdomain—bypassing CORS, hijacking session cookies, and hosting weaponized phishing.

EMAIL REPUTATION DECAYRFC 7208 §4.6.4

Silent SPF 10-Lookup PermErrors

Every added SaaS integration (SendGrid, Zendesk, Salesforce) adds an SPF include:. Exceeding 10 DNS queries triggers a hard PermError, causing Google and Microsoft mail servers to silently route customer correspondence to spam.

THE ARCHITECTURAL BLINDSPOT OF PERIODIC AUDITS

Quarterly vulnerability assessments miss DNS state because it is ephemeral. A Terraform PR merged at 9:00 AM can create an exploitable dangling CNAME in 90 seconds; a SaaS include update can breach the 10-lookup ceiling overnight without any repository commit. Security requires continuous surveillance paired with pre-merge IaC gates.

// 02. ARCHITECTURAL METHODOLOGY—HOW THE ENGINE OPERATES

Five Detection & Verification Disciplines

Every finding is verified against live public DNS infrastructure with deterministic protocol proofs:

// 01. CNAME INTERCEPTOR

42 Cloud Fingerprints

Recursive DNS resolution & HTTP token verification for orphaned AWS S3, Heroku, Azure, and CDN assets.

Canonical Trace Proof
// 02. EMAIL HYGIENE

RFC 7208 & 7489 Evaluator

Recursive SPF include counter enforcing the ≤10 lookup limit to prevent silent PermError delivery drops.

Lookup Tree & DMARC Audit
// 03. TLS EXPIRY RADAR

Multi-Threshold Alerts

Automated 30d, 14d, and 7d milestone escalation before failed ACME renewals trigger user-facing outages.

X.509 Chain Math
// 04. SHADOW IT RECON

Exposed Staging Detector

16-prefix scanner evaluating HTTP basic auth barriers, leaked stack traces, and missing noindex tags.

Compound Risk Scoring
// 05. NETGUARD & AUTO-TRIAGE

Zero-SSRF Egress & Hysteresis

Strict RFC 1918/IMDS egress filtering with an atomic 2-clean-scan window to eliminate flapping alert fatigue.

Kernel Socket Verification & State Lock
// 03. SHIFT-LEFT DEFENSE—TAKEOVER GUARD FOR TERRAFORM

Prevent Dangling DNS in CI/CD Before Merge

Fixing a compromised subdomain post-incident is costly. SubdomainWatch includes Takeover Guard, an open-source Go security binary and GitHub Action that analyzes Terraform plans directly in pull requests.

PRE-MERGE IAC VALIDATION PIPELINE

Zero-Account Standalone or SaaS Sync

  • Inspects tfplan.json: Correlates created/modified DNS records against live authoritative nameservers.
  • SARIF 2.1.0 Native Integration: Emits standard security alerts directly into the GitHub Pull Request Security tab.
  • In-Code HCL Overrides: Supports cryptographic override comments with strict line proximity and expiration date boundaries.
  • Post-Apply Sentinel Mode: Verifies DNS propagation settle delays (default 45s) after infrastructure is provisioned.
.github/workflows/takeover-guard.ymlGitHub Action v2
name: Takeover Guard Gate
on: [pull_request]

jobs:
  guard:
    runs-on: ubuntu-latest
    permissions:
      contents: read
      security-events: write
    steps:
      - uses: actions/checkout@v4
      - uses: subdomainwatch/takeover-guard@v2
        with:
          plan_file: 'tfplan.json'
          fail_on_severity: 'CRITICAL'
          sarif_file: 'subdomainwatch-guard.sarif'
Free standalone mode. Zero signup required.100% Shift-Left
// 04. RESEARCH TEAM & ORIGIN—WHO BUILT SUBDOMAINWATCH

Toby Daeche

Lead Security Architect & Founder
Architectural Rigor

Engineered from the belief that external security monitoring should be deterministic, transparent, and non-invasive. We reject probabilistic heuristics in favor of protocol-level proofs and reproducible evidence.

Zero-Retention Philosophy

DNS telemetry queried by SubdomainWatch is never resold or retained longer than necessary for differential scan analysis. We operate with strict data minimization principles and cryptographic auditability.

Open-Source Contribution

Our cloud takeover signatures database and Takeover Guard CI/CD analyzer are publicly maintained on GitHub, allowing the wider cybersecurity ecosystem to audit, contribute, and benefit from collaborative threat intelligence.

// 05. TOPIC CLUSTER & CRAWL HUB—HIGH-VALUE INTERNAL LINK NETWORK

Explore The SubdomainWatch Ecosystem

Navigate our complete directory of free diagnostic security tools, cloud provider takeover signatures, infrastructure solutions, and protocol implementation guides.

// 06. STANDARDS & EXTERNAL AUTHORITIES—VERIFIABLE E-E-A-T ENTITY ANCHORING

Grounding in Official Internet Standards

SubdomainWatch builds directly upon published standards governed by the Internet Engineering Task Force (IETF) and OASIS Open. We link to authoritative specifications for full verification.

// INSTANT PERIMETER RECONNAISSANCE

Audit Your Perimeter in Under 15 Seconds

Execute an immediate, non-invasive scan across our 42 cloud takeover signatures, RFC 7208 SPF lookup limits, and TLS certificate chains. Or install our open-source GitHub Action to guard Terraform pull requests automatically.

Instant Terminal Probe (No Auth Required)
curl -s 'https://subdomainwatch.com/api/probe?target=yourdomain.com'

Returns immediate JSON telemetry: root DNS delegation, CNAME chain status, SPF recursive depth, DMARC alignment, and X.509 validity dates.