MultiCmsManager

DNS changes

DNS change monitoring to catch hijacked domains

Whoever hijacks a domain doesn’t touch the website: they change the DNS. Visitors and your client’s email go elsewhere, while the original server keeps running.

The problem

The site is fine, but the domain points somewhere else.

A stolen login to the registrar is enough to change nameservers or MX records. The original site stays online and every uptime check on the server says all is well.

Meanwhile visitors see a copy of the site, or someone else reads your client’s email.

How it works

A snapshot of the DNS, compared every day.

  1. 1

    First reading

    When you add the site we save its nameservers and A, AAAA and MX records.

  2. 2

    Comparison

    Every day we read the records again and compare them with the known ones.

  3. 3

    Change alerts

    A new nameserver or a different MX triggers an alert, with before and after.

In detail

What we watch.

  • Nameservers: the strongest sign of a transfer or hijack
  • A and AAAA records: where the site really points
  • MX records: where your client’s mail is delivered
  • Before and after for every change, so you know at once whether it was planned

FAQ

Frequently asked questions

Will I be alerted about changes I make myself?

Yes, every change is reported with old and new values, so you can recognise the planned ones at a glance. A nameserver change is always critical.

Does DNS monitoring need the plugin?

No, DNS records are public and we read them from outside.

Try it on your clients’ sites.

During the beta we welcome agencies in small groups and set up the first sites together.