Skip to main content
ALL SIGNATURES|AWS CloudFront
SCAN DOMAIN FREE
CRITICAL SEVERITYCLOUDID: aws-cloudfront

AWS CloudFront Dangling DNS Takeover Fingerprint

A CNAME references an unallocated or deleted CloudFront distribution. If an attacker knows the target, they can attempt to bind the custom domain to a newly provisioned CloudFront distribution.

CNAME Fingerprint Rule

*.cloudfront.net
403 Forbidden / 404

Response Body Token

Bad Request generated by cloudfront

When SubdomainWatch scanner receives HTTP responses matching this token on a dangling CNAME, it raises a critical alert immediately.

Remediation Guide & Mitigation

Action Required: Remove the dangling CNAME or ensure the CloudFront distribution is active with an attached ACM SSL certificate covering the custom domain.

Immediate Defensive Checklist:

  • Audit authoritative DNS zone records for any CNAME records pointing to *.cloudfront.net.
  • Verify whether the corresponding target resource is still active in your cloud tenant.
  • If the service was deprecated, delete the DNS record immediately to prevent hijackers from claiming the endpoint.
  • Add automated continuous monitoring to alert before third parties can register matching resource names.

Monitor AWS CloudFront In Real-Time

SubdomainWatch continuously monitors your DNS zones for orphaned AWS CloudFront pointers, expired certificates, and dangling records 24/7.

START FREE AUDIT NOW →