Cloudflare
Security & compliance
Releases
Code quality
Wildcard DNS record widens the attack surface
Part of the DNS & origin exposure check · fix arrives as a guide
What it is
The zone contains a wildcard DNS record, so every unlisted subdomain resolves.
Why it matters
It answers for names you never created, which makes subdomain enumeration meaningless as a defence and can route traffic for a name you did not intend to serve. Certificate and cookie scoping problems tend to follow.
How to fix it
Replace the wildcard with explicit records for the subdomains you actually use. Where a wildcard is genuinely required for customer subdomains, keep it proxied and confirm the origin rejects unknown hosts.
Run them all on your app
Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.