Exposing DNS Security Gaps
Automated detection of leaked credentials and private keys in public DNS records.
$ dig TXT aridos.co.uk ...
;; ANSWER SECTION:
aridos.co.uk. 3600 IN TXT "you wanna see it? the thing you have been chasing me around the galaxy for? say please, pretty please, with sugar on."
$ dig TXT admiralgroup.co.uk | grep lastpass
The Hall of Fame
Categories of DNS chaos, mined from real domain records.
Ctrl+C, Ctrl+V Disasters
System administrators who accidentally pasted the wrong thing into the TXT record field. The DNS gods are not impressed.
Cryptographic Nightmares
Private keys, JWTs, and enterprise secrets broadcast to the entire internet via DNS. Sleep tight.
Easter Eggs
Hidden messages and surprises tucked away in DNS records for curious explorers.
SEO Hacks & Easter Eggs
Creative DNS usage ranging from AI-targeted llms.txt to hidden messages for anyone who knows where to look.
Formatting Catastrophes
Zone files, RTF documents, and BIND syntax copy-pasted verbatim into TXT value fields. DNS is not a word processor.
Admin Search History
Instead of pasting the verification token, these admins pasted the Google search URL they used to look it up. The entire search query β in global DNS β forever.
DNS β Website
XML sitemaps, Facebook Pixel scripts, HTML meta tags, robots.txt files β all placed in DNS TXT records by admins who confused their DNS zone with their web server.
Pure Chaos
Records that defy easy categorisation. Hundreds of letter As. Counting to twenty. An 8-level HTML entity escaping loop. Legal demands served to the Wayback Machine. Truly unhinged.
One Character Away
A missing `1`, a leading hyphen, `xxx` prefix, or Microsoft Word smart-quotes β and your entire email security policy is silently ignored by every mail server on earth.
The AI Era
We have moved from pasting Google search URLs into DNS to pasting Microsoft Copilot chat URLs. A perfect archaeological record of how humans interact with AI assistants.
Ancient Relics
DNS records frozen in time. A CVS commit tag from 2002. A developer named mhealey. Internet archaeology, preserved in the global zone file for over two decades.
Most Unhinged Records
Pasted the entire 123-Reg dashboard UI
The administrator accidentally pasted the entire UI text of the 123-Reg DNS management dashboard into the TXT record, inβ¦
Published both public AND private RSA keys to DNS
In a catastrophic security blunder, aicompass.co.uk published both their BEGIN PUBLIC KEY and BEGIN RSA PRIVATE KEY to tβ¦
Doctor Who quote hidden in DNS
A sysadmin hid a quote from River Song (Doctor Who) deep in their DNS zone, almost certainly knowing that only the most β¦
Tried to command the internet via DNS TXT record
The admin tried to manually instruct the internet to create an ALIAS record by typing `027ltd.co.uk ALIAS apex-loadbalanβ¦