Synthetic Industry

Troubleshooting guide · updated 2026-10-11

Old DNS records that point at services you no longer use: why to remove them safely

A record that still points at a cancelled service can let someone else claim that name. Learn what dangling DNS is, how to review a zone, and which old-looking records must stay.

What a dangling record is

A dangling record is an entry in your DNS that points to a service or resource that no longer exists, such as a hostname at a cancelled booking tool, a trial site or an old host. Microsoft's documentation describes the worst case for its own cloud: the resource is deleted, the alias record stays, and someone else registers the same resource name and receives traffic sent to your subdomain. CNAME records are especially exposed, and Microsoft notes that the risk extends to mail records.

Microsoft's page is about Azure, and the details of how a name can be claimed differ between providers. The principle, that a record pointing at something you no longer control is a liability, does not. That generalisation is our reading, not something that page claims.

Why it matters for a small business

Microsoft lists what a takeover can lead to: control of the content on your subdomain, harvesting of cookies, phishing from an address that looks like yours and, for mail records, receiving email meant for you. A valid certificate does not help, because whoever holds the subdomain can obtain one. For a small business the likelier harm is quieter: a stale alias that shows a parked page or error under your brand, and a zone nobody can read with confidence.

Review the zone, record by record

List every record in the zone, and for each one write down what it is for, who owns it and whether it is still used. For every alias, ask whether its target still exists and is yours. Microsoft recommends keeping a service catalogue of endpoints and application owners, and making "remove the DNS entry" part of the checklist when a service is cancelled. A small business can do the same with a one-page table.

  • Record: name, type, target, purpose, owner and last confirmed date.
  • For each alias, resolve the target and check it answers and belongs to you.
  • For each record you cannot explain, ask who created it before deleting it.

Old-looking records that must stay

Many records look obsolete and are not. Microsoft 365 needs a verification TXT record, an Autodiscover CNAME, mail routing records and exactly one SPF record. Email authentication keys often sit in CNAME or TXT records under unfamiliar names. Mark mail, authentication and verification records as not to be touched until an owner confirms each, and never delete a record you cannot identify without a recorded previous value that lets you put it back.

  • Keep mail routing, SPF, DKIM and DMARC records unless an owner says otherwise.
  • Keep verification records for any service you still use.
  • Record the old value of anything you remove.

Where this fits

There is no single fixed-price job for a one-off tidy of old records. The quarterly unused-record review is part of the standing domain responsibility, a published test price of £95 a month that has not been tested with buyers, where you approve every change and your DNS holder applies it. If a stale record is the reason a website name has stopped working, the bare-domain and www repair covers that case. If you suspect a name has already been taken over, treat it as a security matter and speak to your provider first.

Sources and limits

  • Microsoft: Prevent dangling DNS entries and avoid subdomain takeover Checked 2026-10-11.
    • A dangling DNS entry is a record that points to a deprovisioned resource, CNAME records are especially vulnerable, and removing the record at decommissioning is the preventive step.
    • A valid certificate does not protect a taken-over subdomain, and the risk extends to MX records.
  • Microsoft 365: external DNS records Checked 2026-10-11.
    • Microsoft 365 requires a verification TXT record, an Autodiscover CNAME, an MX record and a single SPF TXT record for email.