Attack surface
Origin server exposure check
Names in your DNS that point straight at your server let anyone go around your CDN or web firewall.
Check this on your own domain now. It is free with a DomainGuard account and works on any domain. The check reads only what your domain publishes, and gives you a report you can send to whoever runs your website.
What we look at
When your site is behind a CDN, we look up names in your domain that often hold the server's own address (mail, ftp, cpanel, dev, staging, origin and the like), your mail servers, your known subdomains and the addresses in your SPF record. We list the ones that point at a public address outside any CDN. We only read DNS; we don't connect to the server.
Why it matters to your business
The CDN only protects the site if nobody can reach the server any other way. If mail or ftp still points at the web server, anyone who reads your DNS has its address and can skip the firewall, the rate limits and the DDoS protection you're paying for.
How to fix it
- Check each listed name. If it's the web server, route it through the CDN or move that service to a different machine.
- Set the web server's firewall to accept web traffic only from the CDN's addresses. Cloudflare, Fastly and CloudFront all publish theirs.
- If the server's address has been public for a while, consider moving it to a new one after the changes above.
If you would rather not touch DNS or server settings yourself, forward this page and your report to whoever manages your website, or ask us to do it.
