Skip to main content
DNS Checker(beta)

DNS Security Dashboard

Security analysis of 289,748,175+ domains derived from zone file data across hundreds of gTLDs. DNS Checker identifies misconfigurations, delegation failures, and infrastructure vulnerabilities that put domains at risk of hijacking, downtime, or DNS-based attacks.

This dashboard monitors five categories of DNS security findings across every gTLD in the dataset, from typosquatted nameservers that could enable phishing to DNSSEC gaps that leave domains vulnerable to cache poisoning (RFC 5452). Each finding includes severity ratings, affected domain counts, and actionable remediation guidance.

Analysis by Ishan Karunaratne · Data from 2026-08-09

Domains Analyzed

289,748,175

Finding Categories

5

High Severity Findings

3

Snapshot Date

2026-08-09

Key Findings Summary

As of 2026-08-09, automated analysis of 289,748,175 domains across hundreds of gTLDs reveals five categories of DNS security vulnerabilities. Lame delegations affect 4,802,461 domains where NS records point to non-functional nameservers, leaving them unreachable and vulnerable to nameserver takeover (RFC 1912). Typosquatted nameservers affect 1,506 domains with misspelled provider hostnames that attackers could register to hijack DNS resolution. DNSSEC adoption stands at just 5.5% despite its critical role in preventing cache poisoning attacks (RFC 4033–4035, RFC 5452). Provider concentration analysis shows 37 TLDs where a single DNS provider serves more than half of all domains, 7 of them above 90%, a systemic risk demonstrated by the 2016 Dyn DDoS attack.

FindingSeverityDomains / TLDs Affected
Lame Delegationshigh4,802,461 domains
Nameservers on Risky TLDshigh335,186 domains
Typosquatted Nameserverslow1,506 domains
Provider Concentrationlow37 TLDs (>50% share)
DNSSEC Gapshigh5.5% adoption

What This Dashboard Tracks

The DNS (Domain Name System) is the foundation of the internet. It translates domain names to IP addresses. When DNS is misconfigured or compromised, websites become unreachable, email stops working, and users can be silently redirected to malicious servers.

This dashboard analyzes zone files from hundreds of gTLDs, detecting five categories of DNS security issues:

  • Lame delegations, domains pointing to non-functional nameservers
  • Typosquatted nameservers, NS records with misspelled provider domains
  • DNSSEC adoption gaps, domains lacking cryptographic DNS validation
  • Provider concentration, TLDs over-reliant on a single DNS provider
  • Risky TLD nameservers, NS domains hosted on high-abuse extensions

Security Findings Overview

Lame Delegations

high

4,802,461 domains pointing to non-functional nameservers

4,802,461

domains affected

Impact

Domains with lame delegations have no functioning DNS. They are unreachable and vulnerable to nameserver takeover if the expired NS domain becomes available for registration.

Mitigation

Check that all NS records point to active, responsive nameservers. Remove or update stale delegation records.

View detailed lame delegations report

Nameservers on Risky TLDs

high

335,186 domains using nameservers on high-abuse TLDs

335,186

domains affected

Impact

Nameserver domains on extensions with elevated abuse rates are more likely to lapse or be suspended, creating a risk that someone else registers the lapsed NS domain and takes over DNS resolution. The listing reflects the extension, not the nameserver operator.

Mitigation

Host nameservers on well-established TLDs (.com, .net, .org). Avoid cheap or high-abuse extensions for critical DNS infrastructure.

View detailed nameservers on risky tlds report

Typosquatted Nameservers

low

1 unique typosquatted nameserver variants detected

1,506

domains affected

Impact

An attacker who registers the misspelled nameserver domain gains full control over DNS resolution for every domain pointing to it, enabling phishing, traffic interception, and email hijacking.

Mitigation

Audit your NS records for typos. Use DNS monitoring to detect unauthorized nameserver changes.

View detailed typosquatted nameservers report

Provider Concentration

low

37 TLDs have >50% single-provider dependency, 7 of them above 90%

37

TLDs >50% single-provider

Impact

When the majority of a TLD's domains depend on a single DNS provider, an outage or compromise at that provider could render most domains under that TLD unreachable, a systemic risk to the namespace.

Mitigation

Registry operators should encourage provider diversity. Domain owners should consider secondary DNS with a different provider.

View detailed provider concentration report

DNSSEC Gaps

high

Only 5.5% of domains have DNSSEC enabled

5.5%

adoption rate

Impact

Without DNSSEC, DNS responses can be forged through cache poisoning attacks (Kaminsky attack, RFC 5452). Attackers can redirect users to malicious servers without any visible indication.

Mitigation

Enable DNSSEC signing at your DNS provider. Most major providers (Cloudflare, AWS Route 53, Google Cloud DNS) support one-click DNSSEC activation.

View detailed dnssec gaps report

Detailed Security Reports

Each report includes full data tables, per-TLD breakdowns, and analysis methodology. Click through to explore the raw findings.

How DNS Security Analysis Works

DNS security findings are derived from automated analysis of gTLD zone files, the authoritative records that map domain names to their nameservers. The analysis pipeline processes zone data from every TLD zone file in the dataset, covering 289,748,175 domains as of the latest snapshot.

Analysis Methodology

  1. Zone file ingestion: Raw zone files are downloaded and parsed daily, extracting NS, A, AAAA, and DS (DNSSEC) records for domains across hundreds of gTLDs.
  2. Nameserver validation: Each nameserver hostname is checked against known provider databases, typo detection algorithms, and TLD risk classifications.
  3. Delegation health: NS records are cross-referenced with known expired, deleted, suspended, and lame nameserver indicators (e.g., "dns-expired.com", parking pages).
  4. DNSSEC coverage: DS record presence in zone files indicates DNSSEC signing. Adoption rates are computed per-TLD and globally.
  5. Provider concentration: Herfindahl-Hirschman Index (HHI) and single-provider market share are computed per-TLD to identify systemic concentration risk.

Understanding DNS Security Threats

What is a lame delegation?

A lame delegation occurs when a domain's NS records point to nameservers that don't actually serve DNS for that domain. This can happen when a domain expires, the hosting account is deleted, or nameserver records become stale. Lame delegations are defined in RFC 1912 Section 2.8 and represent one of the most common DNS misconfigurations.

What is nameserver typosquatting?

Nameserver typosquatting occurs when a domain's NS records contain misspelled versions of legitimate DNS provider hostnames, for example, "cloudflare.comm" instead of "cloudflare.com". If the typo domain is unregistered, an attacker can register it and gain full control over DNS resolution for every domain pointing to it, enabling phishing, email interception, and traffic hijacking.

Why does DNSSEC adoption matter?

DNSSEC (DNS Security Extensions, RFC 4033–4035) adds cryptographic signatures to DNS responses, allowing resolvers to verify that the response hasn't been tampered with. Without DNSSEC, domains are vulnerable to cache poisoning attacks where an attacker injects forged DNS responses to redirect users to malicious servers, all without any visible warning to the user.

What is DNS provider concentration risk?

When a large percentage of domains under a single TLD rely on one DNS provider, an outage or compromise at that provider becomes a single point of failure for the entire TLD. The 2016 Dyn DDoS attack demonstrated this risk, taking down major sites including Twitter, GitHub, and Netflix due to DNS provider concentration.

Check Your Domain's DNS Security

Use these free tools to audit your own domain's DNS configuration and identify potential vulnerabilities.

Data updated daily. Last snapshot: August 9, 2026

Data scope: Security findings are derived from analysis of the TLD zone files DNS Checker has access to. This covers hundreds of generic top-level domains including .com, .net, .org, .xyz, .io, and many more, plus the handful of country-code TLDs that publish zone data (.se and .nu via IIS, .ch and .li via SWITCH). Most ccTLDs do not publish zone files and are therefore absent (including large ones such as .cn, .ru, .uk, .de and .jp), as are infrastructure TLDs like .arpa. Figures should be read as covering the measurable surface, not the whole DNS.

Methodology: Findings are informational and based on automated analysis of nameserver records, delegation chains, and DNSSEC configurations. Not all findings represent active threats, some may reflect domains in transition, pending deletion, or intentional parking configurations.

References: RFC 1912 (DNS Operational Guidelines) · RFC 40334035 (DNSSEC) · RFC 5452 (DNS Resilience) · RFC 8914 (Extended DNS Errors)