Cloudflare Security & compliance Releases Code quality

Wildcard DNS record widens the attack surface

Part of the DNS & origin exposure check · fix arrives as a guide

What it is

The zone contains a wildcard DNS record, so every unlisted subdomain resolves.

Why it matters

It answers for names you never created, which makes subdomain enumeration meaningless as a defence and can route traffic for a name you did not intend to serve. Certificate and cookie scoping problems tend to follow.

How to fix it

Replace the wildcard with explicit records for the subdomains you actually use. Where a wildcard is genuinely required for customer subdomains, keep it proxied and confirm the origin rejects unknown hosts.

Run them all on your app

Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.