Skip to content

Departed vendor still has records in our zone, nobody knows if any are still in use

TXT verifications, CNAMEs for SaaS tools and old DKIM keys often linger after a vendor switch. Harmless until they are not: a forgotten CNAME to an expired Heroku app or S3 bucket is direct takeover material.

Try this first

  1. 1List departed vendors by category (mail tool, marketing, helpdesk, analytics) and look up their verification patterns.
  2. 2Filter the zone for CNAMEs and TXT records that reference those vendors, plus old DKIM selectors no longer in use.
  3. 3Check each CNAME target: is it alive, who owns it? CNAME to e.g. heroku-app.herokudns.com where the app is gone = takeover risk.
  4. 4Remove or set TTL 60 with a 30-day observation window, watch for complaints.
  5. 5Log in your DNS changelog who removed what when, so you can trace back if something does break.

When to bring us in

If you have many vendor records and no overview, we can run a takeover scan and clean the zone without disrupting active integrations.

See also

None of the above fits?

Describe your situation below. We pass your input plus the steps you already saw to our AI and return tailored next-step advice. If it's too risky to DIY, we'll say so.

Who are you?

For the AI question we need your email and company, so we can follow up if the AI gets stuck, and to prevent abuse.

Limited to 2 questions per hour and 5 per day, kept lean so the AI stays useful. For more, contacting us directly works better for you and us.

Or skip the DIY entirely

Our Managed IT clients do not look these things up. One point of contact, a fixed monthly price, resolved within working hours.