Skip to main content
SCAN DOMAIN FREE
CRITICAL SEVERITYCLOUDID: aws-s3

AWS S3 Dangling DNS Takeover Fingerprint

An orphan CNAME points to an Amazon S3 bucket that was deleted or never created. An attacker can create the S3 bucket with the exact matching name in any AWS account and host arbitrary payloads or phishing pages on your domain.

CNAME Fingerprint Rule

*.s3.amazonaws.com / *.s3-website-*.amazonaws.com
404 Not Found

Response Body Token

NoSuchBucket

When SubdomainWatch scanner receives HTTP responses matching this token on a dangling CNAME, it raises a critical alert immediately.

Remediation Guide & Mitigation

Action Required: Delete the dangling CNAME DNS record in your DNS provider immediately, or re-create the target S3 bucket under your own AWS account with appropriate public-access block controls.

Immediate Defensive Checklist:

  • Audit authoritative DNS zone records for any CNAME records pointing to *.s3.amazonaws.com / *.s3-website-*.amazonaws.com.
  • Verify whether the corresponding target resource is still active in your cloud tenant.
  • If the service was deprecated, delete the DNS record immediately to prevent hijackers from claiming the endpoint.
  • Add automated continuous monitoring to alert before third parties can register matching resource names.

Monitor AWS S3 In Real-Time

SubdomainWatch continuously monitors your DNS zones for orphaned AWS S3 pointers, expired certificates, and dangling records 24/7.

START FREE AUDIT NOW →