Skip to main content
ALL SIGNATURES|WordPress.com
SCAN DOMAIN FREE
HIGH SEVERITYCMSID: wordpress-com

WordPress.com Dangling DNS Takeover Fingerprint

CNAME points to an unmapped WordPress.com blog. Attackers can map the custom domain to their personal WordPress.com site.

CNAME Fingerprint Rule

*.wordpress.com
302 / 404

Response Body Token

Do you want to register this domain?

When SubdomainWatch scanner receives HTTP responses matching this token on a dangling CNAME, it raises a critical alert immediately.

Remediation Guide & Mitigation

Action Required: Delete the CNAME in DNS or add domain mapping in your WordPress.com account.

Immediate Defensive Checklist:

  • Audit authoritative DNS zone records for any CNAME records pointing to *.wordpress.com.
  • Verify whether the corresponding target resource is still active in your cloud tenant.
  • If the service was deprecated, delete the DNS record immediately to prevent hijackers from claiming the endpoint.
  • Add automated continuous monitoring to alert before third parties can register matching resource names.

Monitor WordPress.com In Real-Time

SubdomainWatch continuously monitors your DNS zones for orphaned WordPress.com pointers, expired certificates, and dangling records 24/7.

START FREE AUDIT NOW →