Your DNS records changed and nobody here did it

Whoever controls DNS controls mail, web traffic and certificate issuance for everything under the domain. CISA issued an emergency directive on exactly this in 2019, after attackers changed DNS records to intercept traffic and obtain valid certificates. Treat it as an account compromise at the registrar or DNS provider first.

Trigger. Mail stops arriving, a site resolves somewhere unexpected, a certificate appears that nobody requested, or the registrar emails about a change nobody made.

The first 75 minutes2 of 5 expire
038 min75
  1. 01

    Export the zone and the change history

    by 10 minexpires

    The current zone file, the provider's audit log of who changed what and when, and the registrar's record of any nameserver or contact change. Screenshots are fine if there is no export.

  2. 02

    Lock down the registrar and DNS accounts

    by 20 minexpires

    Reset passwords, remove unknown users and API keys, enforce MFA, and turn on registrar lock, and registry lock if your registrar offers it.