dotvitals

A wildcard record answers for every subdomain

InfoHigh confidencedns.records.wildcard-present

What this check looks for

Any name under this domain resolves, including ones you never created. Typos, old links and names invented by other people all point at your server.

Why it matters

A wildcard makes it impossible to tell a real subdomain from a mistake, and it hands anyone a working hostname under your brand to use in a link. It is also frequently deliberate, which is why this is information rather than a fault.

What it costs your score

This check never deducts. It reports a fact — or reports that something could not be verified — and is shown on the report without moving the score.

Severity
info
Default confidence
high
Status when triggered
info
Deduction
0 points
Family cap
none
Category
DNS
Module
Dns records
Fix owned by
dns host
In the ruleset since
2026.09

How the whole score is calculated

Technical detail

A lookup for ‹probed name›, a name that should not exist, returned ‹addresses›. RFC 1034 §4.3.3 defines wildcard records; they answer for any name at that level with no more specific record. A wildcard is a legitimate design for multi-tenant platforms and a common accident on shared hosting. Check that the address it answers with is a host you control and that it does not serve a certificate or a login page for names you never intended to exist.

Standards and references

Test this on your domain

Run the check that produces this finding, on its own, against any domain.

Open the dns records checker

Other dns records checks