DNS record checker

DNS is where an external estate is actually defined. Everything an attacker enumerates starts here, and most of the surface that turns out to be exposed was published in a DNS record years ago and never revisited.

What this page checks

How it runs

This page performs a live lookup against the domain you enter and returns the result in the browser. Nothing is installed and no credential is needed.

Where this sits in Maphra

A single lookup answers a question about one name you already knew about. Maphra starts from a domain and works outward the way an attacker would: enumerating subdomains, resolving infrastructure, fingerprinting live services and attributing each discovered asset back to the organisation that owns it. Takeover-prone records are checked on every discovered asset rather than the handful somebody thought to test, and DNS hygiene is one of the standing checks in its comprehensive security analysis.

Questions

What is a dangling DNS record?
A record that still points at infrastructure which no longer exists — most often a CNAME aimed at a cloud resource that was deleted. Anyone who can claim that resource inherits the name, which is why takeover-prone records are checked on every asset Maphra discovers rather than on request.

A one-off check tells you about one asset today. Maphra runs this continuously across everything it discovers, and a walkthrough uses your own domain rather than a sample.