Skip to main content
SCAN DOMAIN FREE
HIGH SEVERITYHOSTINGID: vercel

Vercel Dangling DNS Takeover Fingerprint

A custom domain points via CNAME to Vercel edge routers, but no deployment is linked to this domain. Attackers can add the unverified domain to their own project.

CNAME Fingerprint Rule

*.vercel-dns.com / cname.vercel-dns.com
404 Not Found

Response Body Token

404: NOT_FOUND

When SubdomainWatch scanner receives HTTP responses matching this token on a dangling CNAME, it raises a critical alert immediately.

Remediation Guide & Mitigation

Action Required: Delete the CNAME pointing to Vercel or link the domain in your verified Vercel team dashboard.

Immediate Defensive Checklist:

  • Audit authoritative DNS zone records for any CNAME records pointing to *.vercel-dns.com / cname.vercel-dns.com.
  • Verify whether the corresponding target resource is still active in your cloud tenant.
  • If the service was deprecated, delete the DNS record immediately to prevent hijackers from claiming the endpoint.
  • Add automated continuous monitoring to alert before third parties can register matching resource names.

Monitor Vercel In Real-Time

SubdomainWatch continuously monitors your DNS zones for orphaned Vercel pointers, expired certificates, and dangling records 24/7.

START FREE AUDIT NOW →
SubdomainWatch Security Research // Continuous External Attack Surface Intelligence