Aazure dns security issue

shai 1 Reputation point
2021-01-03T14:30:34.91+00:00

Hi,
I created a dns for an existing domain which is NOT in Azure.
The ns record is not pointing to azure dns but some other registrar.
than I added a record pointing to 1.1.1.1
if I go to a vm on azure which is OTHER azure's suscription than the one I created the a record.
and i query your ns server I get a result.

So what stopping someone else create a domain belongs to me and makes all vms in azure get resolve to a wrong IP?

Best regards,
Shai

xxxxx@testshaip:~$ nslookup

Default server: ns1-07.azure-dns.com
Address: 2603:1061::7#53

sss.sxxxx.info

Server: ns1-07.azure-dns.com
Address: 40.90.4.7#53

Name: sss.sxxxx.info
Address: 2.2.2.2

Azure DNS
Azure DNS
An Azure service that enables hosting Domain Name System (DNS) domains in Azure.
619 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. SaiKishor-MSFT 17,216 Reputation points
    2021-01-07T06:56:20.467+00:00

    @shai When someone does a DNS lookup for your domain, it will be forwarded to the name servers that are associated with the registrar and not any other nameservers. Therefore, the request will not make it to this nameserver ns1-07.azure-dns.com. However, in your case you are specifying the nameserver ns1-07.azure-dns.com while querying which is why you see the IP address that you configured but otherwise others wont be able to see that IP address. Hope this helps. Please let me know if you have any other questions/concerns. Thank you!