dnswatchdog.iodocs

All Issues

Complete reference of every issue DNS Watchdog can detect, viewable by category or by severity.

A complete reference of every issue type DNS Watchdog detects. Switch between viewing issues grouped by category or by severity.

Open Ports

IssueSeverityDescription
Port 21 (FTP)MediumFTP transmits credentials in plaintext
Port 22 (SSH)MediumRemote shell access exposed to the internet
Port 23 (Telnet)HighUnencrypted remote access protocol
Port 25 (SMTP)LowOpen mail relay risk if misconfigured
Port 53 (DNS)LowOpen DNS resolver, potential amplification vector
Port 80 (HTTP)InformationalStandard web port, redirect to HTTPS
Port 443 (HTTPS)InformationalStandard secure web port, expected
Port 135 (MS-RPC)MediumWindows RPC, frequently exploited
Port 389 (LDAP)HighDirectory service exposed unencrypted
Port 445 (SMB)HighRansomware and lateral movement target
Port 636 (LDAPS)MediumEncrypted directory service still exposed
Port 1433 (MSSQL)HighDatabase exposed to the internet
Port 1521 (Oracle)HighDatabase exposed to the internet
Port 2375 (Docker)CriticalUnauthenticated container API, full host compromise
Port 3306 (MySQL)HighDatabase exposed to the internet
Port 3389 (RDP)HighRemote desktop, common ransomware entry point
Port 5432 (PostgreSQL)HighDatabase exposed to the internet
Port 5601 (Kibana)HighLog dashboard with potential sensitive data
Port 5900 (VNC)HighRemote desktop with weak authentication
Port 6379 (Redis)HighOften unauthenticated, filesystem write risk
Port 6380 (Redis TLS)HighTLS-wrapped but still internet-exposed
Port 6443 (Kubernetes API)HighCluster management API exposed
Port 7474 (Neo4j)HighGraph database exposed to the internet
Port 9042 (Cassandra)HighDatabase exposed, often no auth by default
Port 9200 (Elasticsearch)HighSearch engine with potential sensitive data
Port 9300 (OpenSearch)HighSearch engine transport port exposed
Port 11211 (Memcached)HighNo auth, DDoS amplification abuse vector
Port 27017 (MongoDB)HighDatabase exposed to the internet

IP Addresses

IssueSeverityDescription
Inactive IPLowNo services detected, possible stale record
Unresponsive HostLowPorts open but no HTTP response
IP BlocklistedHighIP appears on threat intelligence blocklists

Certificates

IssueSeverityDescription
Expired CertificateHighCertificate past its validity period
Certificate Expiring SoonLowCertificate will expire within 30 days
Hostname MismatchMediumCertificate does not match the domain
Self-Signed CertificateMediumNot trusted by browsers or clients
Weak Certificate KeyMediumCryptographic key too short for modern security

HTTP

IssueSeverityDescription
HTTP 404 ErrorLowResource not found, possible stale DNS
HTTP 4xx ErrorLowClient error, possible misconfiguration
HTTP 5xx ErrorLowServer error, service may be down
HTTP ErrorLowNo HTTP response: connection refused, timed out or dropped
Authentication RequiredInformationalEndpoint requires credentials
Weak TLS VersionMediumDeprecated TLS 1.0 or 1.1 negotiated
No HTTPS RedirectMediumHTTP traffic not redirected to HTTPS

DNS

IssueSeverityDescription
Dangling SubdomainHighCNAME target no longer resolves, unconfirmed takeover risk
CNAME TakeoverCriticalTarget confirmed claimable by fingerprint, active takeover risk
Broken DelegationHighDelegated nameservers do not resolve
Zone Not AuthoritativeHighPublic delegation does not point at this zone
Delegated SubdomainInformationalDNS managed by external nameservers
Broken DNS RedirectLowRedirect target unreachable or erroring

Email Authentication

IssueSeverityDescription
Invalid SPF RecordMediumSPF record has syntax errors
SPF Exceeds Lookup LimitMediumMore than 10 DNS lookups in SPF
Overly Permissive SPFHigh+all allows any server to send as your domain
SPF Deprecated PTRLowUses deprecated ptr mechanism
SPF Missing Catch-AllMediumNo terminal all mechanism
Missing SPF RecordMediumZone has MX but no SPF record
Invalid DKIM RecordMediumDKIM record has errors or invalid key
DKIM Key RevokedLowPublic key revoked (empty p= tag)
Missing DKIM RecordLowZone has MX but no DKIM record
Invalid DMARC RecordMediumDMARC record has syntax errors
Missing DMARC RecordMediumZone has MX but no DMARC policy
Invalid MTA-STS RecordLowMTA-STS record missing or malformed
Invalid MX RecordHighMX target does not resolve, email will bounce

BIMI

IssueSeverityDescription
BIMI Requires an Enforced DMARC PolicyMediumBIMI record present but DMARC not enforced
Invalid BIMI RecordLowBIMI record malformed or insecure
Invalid BIMI Logo (SVG)LowLogo does not meet the SVG Tiny P/S profile
Invalid BIMI Mark CertificateLowVMC/CMC invalid, expired, or mismatched
BIMI Logo UnreachableLowLogo URL could not be retrieved over HTTPS
BIMI Mark Certificate UnreachableLowCertificate URL could not be retrieved over HTTPS

Content

IssueSeverityDescription
Problematic Screenshot ContentMediumManually flagged page content, possible compromise or abuse

Critical

Active security risk requiring immediate action — direct compromise or takeover possible.

IssueCategoryDescription
Port 2375 (Docker)Open PortsUnauthenticated container API, full host compromise
CNAME TakeoverDNSTarget confirmed claimable by fingerprint, active takeover risk

High

Serious exposure or failed security control requiring prompt remediation.

IssueCategoryDescription
Port 23 (Telnet)Open PortsUnencrypted remote access protocol
Port 389 (LDAP)Open PortsDirectory service exposed unencrypted
Port 445 (SMB)Open PortsRansomware and lateral movement target
Port 1433 (MSSQL)Open PortsDatabase exposed to the internet
Port 1521 (Oracle)Open PortsDatabase exposed to the internet
Port 3306 (MySQL)Open PortsDatabase exposed to the internet
Port 3389 (RDP)Open PortsRemote desktop, common ransomware entry point
Port 5432 (PostgreSQL)Open PortsDatabase exposed to the internet
Port 5601 (Kibana)Open PortsLog dashboard with potential sensitive data
Port 5900 (VNC)Open PortsRemote desktop with weak authentication
Port 6379 (Redis)Open PortsOften unauthenticated, filesystem write risk
Port 6380 (Redis TLS)Open PortsTLS-wrapped but still internet-exposed
Port 6443 (Kubernetes API)Open PortsCluster management API exposed
Port 7474 (Neo4j)Open PortsGraph database exposed to the internet
Port 9042 (Cassandra)Open PortsDatabase exposed, often no auth by default
Port 9200 (Elasticsearch)Open PortsSearch engine with potential sensitive data
Port 9300 (OpenSearch)Open PortsSearch engine transport port exposed
Port 11211 (Memcached)Open PortsNo auth, DDoS amplification abuse vector
Port 27017 (MongoDB)Open PortsDatabase exposed to the internet
IP BlocklistedIP AddressesIP appears on threat intelligence blocklists
Expired CertificateCertificatesCertificate past its validity period
Dangling SubdomainDNSCNAME target no longer resolves, unconfirmed takeover risk
Broken DelegationDNSDelegated nameservers do not resolve
Zone Not AuthoritativeDNSPublic delegation does not point at this zone
Overly Permissive SPFEmail Authentication+all allows any server to send as your domain
Invalid MX RecordEmail AuthenticationMX target does not resolve, email will bounce

Medium

Material misconfiguration or weakened control that should be investigated.

IssueCategoryDescription
Port 21 (FTP)Open PortsFTP transmits credentials in plaintext
Port 22 (SSH)Open PortsRemote shell access exposed to the internet
Port 135 (MS-RPC)Open PortsWindows RPC, frequently exploited
Port 636 (LDAPS)Open PortsEncrypted directory service still exposed
Hostname MismatchCertificatesCertificate does not match the domain
Self-Signed CertificateCertificatesNot trusted by browsers or clients
Weak Certificate KeyCertificatesCryptographic key too short for modern security
Weak TLS VersionHTTPDeprecated TLS 1.0 or 1.1 negotiated
No HTTPS RedirectHTTPHTTP traffic not redirected to HTTPS
Invalid SPF RecordEmail AuthenticationSPF record has syntax errors
SPF Exceeds Lookup LimitEmail AuthenticationMore than 10 DNS lookups in SPF
SPF Missing Catch-AllEmail AuthenticationNo terminal all mechanism
Missing SPF RecordEmail AuthenticationZone has MX but no SPF record
Invalid DKIM RecordEmail AuthenticationDKIM record has errors or invalid key
Invalid DMARC RecordEmail AuthenticationDMARC record has syntax errors
Missing DMARC RecordEmail AuthenticationZone has MX but no DMARC policy
BIMI Requires an Enforced DMARC PolicyBIMIBIMI record present but DMARC not enforced
Problematic Screenshot ContentContentManually flagged page content, possible compromise or abuse

Low

Limited-impact hardening or operational issue to address when convenient.

IssueCategoryDescription
Port 25 (SMTP)Open PortsOpen mail relay risk if misconfigured
Port 53 (DNS)Open PortsOpen DNS resolver, potential amplification vector
Inactive IPIP AddressesNo services detected, possible stale record
Unresponsive HostIP AddressesPorts open but no HTTP response
Certificate Expiring SoonCertificatesCertificate will expire within 30 days
HTTP 404 ErrorHTTPResource not found, possible stale DNS
HTTP 4xx ErrorHTTPClient error, possible misconfiguration
HTTP 5xx ErrorHTTPServer error, service may be down
HTTP ErrorHTTPNo HTTP response: connection refused, timed out or dropped
Broken DNS RedirectDNSRedirect target unreachable or erroring
SPF Deprecated PTREmail AuthenticationUses deprecated ptr mechanism
DKIM Key RevokedEmail AuthenticationPublic key revoked (empty p= tag)
Missing DKIM RecordEmail AuthenticationZone has MX but no DKIM record
Invalid MTA-STS RecordEmail AuthenticationMTA-STS record missing or malformed
Invalid BIMI RecordBIMIBIMI record malformed or insecure
Invalid BIMI Logo (SVG)BIMILogo does not meet the SVG Tiny P/S profile
Invalid BIMI Mark CertificateBIMIVMC/CMC invalid, expired, or mismatched
BIMI Logo UnreachableBIMILogo URL could not be retrieved over HTTPS
BIMI Mark Certificate UnreachableBIMICertificate URL could not be retrieved over HTTPS

Informational

Expected or contextual observation for awareness only.

IssueCategoryDescription
Port 80 (HTTP)Open PortsStandard web port, redirect to HTTPS
Port 443 (HTTPS)Open PortsStandard secure web port, expected
Authentication RequiredHTTPEndpoint requires credentials
Delegated SubdomainDNSDNS managed by external nameservers

On this page