Cloud DNS and domain security guide for SaaS
Secure a SaaS domain and cloud DNS with registrar account protection, accurate ownership, safe record changes, dangling-DNS cleanup, DNSSEC planning and a tested recovery path.
In this guide
What does DNS and domain security cover?
Domain security protects the registrar account, authoritative DNS zone, records and cloud resources that make a SaaS service reachable. A strong baseline secures domain ownership, inventories records and owners, removes stale references, and tests recovery before changing DNSSEC or nameservers. DNSSEC can help validate DNS responses when configured correctly, but it does not secure a compromised registrar account or replace application security.
Inventory domains, zones, records and dependent services
List registered domains, subdomains, DNS providers, authoritative nameservers, certificates and cloud resources that records point to. Assign a business and technical owner, purpose and expiry or review date to each non-obvious record. Include marketing campaigns, preview environments, verification records, mail delivery and third-party SaaS connections.
Protect the registrar account as a critical identity
Use multi-factor authentication, unique credentials and a controlled recovery address. Restrict account access to named people, review delegated users and API tokens, enable available domain locks and alerts, and keep renewal and ownership contacts current. A DNS operator account and a registrar account may be separate; protect both and understand how account recovery works.
Document the safe change and emergency recovery path
Record who can approve nameserver, delegation, DNSSEC and high-impact record changes, how a second person verifies them, and how to revert safely. Keep access to the account and recovery instructions available during an incident without placing credentials in a public runbook. Test the contact path before an outage.
| Domain or record | Target and purpose | Owner and registrar access | Expiry or review date | Recovery evidence |
|---|---|---|---|---|
| Primary production domain | ||||
| Customer-facing subdomain | ||||
| Third-party verification record |
How do you prevent DNS misdirection and subdomain takeover?
Remove records when their cloud resource is retired
When deleting a load balancer, storage website, application, verification endpoint or vendor integration, check for DNS records that still point to it. Remove the stale record or safely reclaim the target before a different party can claim the resource. Microsoft describes dangling DNS records as a possible subdomain takeover path; the exact exposure depends on the provider and resource lifecycle.
Require an owner and expiry for temporary subdomains
Use an inventory or automated discovery process to find records that are missing an owner, no longer resolve as intended or point to an unclaimed service. Set expiry dates for preview and campaign records, verify ownership before linking a new resource, and include DNS cleanup in infrastructure decommissioning. Do not assume a record is safe because the parent domain is controlled.
Review mail records and service verification changes carefully
Protect MX, SPF, DKIM, DMARC and domain-verification records through the same change review as application records. Confirm the exact value with the receiving service through a trusted channel, check for conflicting or obsolete records, and monitor mail authentication results after a change. Avoid broad permissions that let a routine deploy alter the whole zone.
When should a SaaS team enable DNSSEC?
Understand DNSSEC's benefit and operational dependency
DNSSEC adds a chain of signatures that validating resolvers can use to detect altered or invalid DNS data. It does not encrypt DNS queries, stop every phishing attack, or prevent an attacker with registrar control from changing the domain configuration. Decide based on provider support, operational maturity and the team's ability to maintain the signing chain.
Test the full delegation chain before and after signing
Confirm the DNS provider, registrar and parent zone support the required DNSSEC records and key workflow. Follow provider instructions for publishing the DS record, verify from independent validating resolvers, and monitor for validation failures. AWS warns that a broken chain can make a signed domain fail to resolve for validating clients, so schedule and review the change carefully.
Include key rollover and recovery in the operations plan
Name the owner for key-signing and rollover events, document provider-managed versus customer-managed steps, and make emergency access available. Test the procedure in a non-production domain when possible. Keep a safe response for signing errors that restores valid resolution without leaving a stale delegation behind.
Cloud DNS and domain security FAQs
Does DNSSEC prevent a domain registrar takeover?
No. DNSSEC helps validating resolvers verify signed DNS data, but the registrar account and domain registration still need strong identity protection, access review, renewal controls and recovery procedures.
What is a dangling DNS record?
It is a record that points to a resource that has been removed or is no longer controlled by the intended organization. If a provider allows someone else to claim that resource, the stale subdomain can become a takeover path. Confirm the provider's resource lifecycle and remove or reclaim the record promptly.
Should every subdomain have DNSSEC configured separately?
DNSSEC is configured through the zone's signing and delegation chain; the exact setup depends on the DNS provider and zone structure. Follow the authoritative provider and registrar instructions, then independently verify the chain instead of copying settings between providers.
How often should DNS records be reviewed?
Review high-impact records during changes and incident exercises, and periodically scan the full inventory for unknown owners, stale targets and expired temporary uses. The cadence should reflect domain criticality, provider lifecycle and how often teams create or retire cloud resources.
Related practical guides
Related issue guides
Sources and publication record
Draft prepared 27 September 2026; engineering, security and editorial review pending · Sources checked .
- Do You Have a Domain Name? Here's What You Need to KnowInternet Corporation for Assigned Names and Numbers
- Preventing Dangling DNS Entries and Avoiding Subdomain TakeoverMicrosoft Learn
- Configuring DNSSEC Signing in Amazon Route 53Amazon Web Services