operate
DNS, Email Auth & Takeover Guard
DNSSEC, CAA, SPF/DKIM/DMARC — and dangling records that let someone claim your subdomain.

What you get
DNS and email auth, on the live domain
DNSSEC, CAA and wildcard records plus SPF, DKIM and DMARC are checked on the live domain — misconfigured DNS and spoofable email caught, not assumed.
Subdomain takeover, flagged
Dangling DNS records that would let someone else claim your subdomain are surfaced before they're exploited.
Dangling records that point to nothing
A CNAME aimed at a de-provisioned service is an open door: whoever re-registers that service can serve content from your subdomain. The guard flags records pointing at unclaimed targets alongside SPF, DKIM, DMARC, DNSSEC, and CAA gaps on the live domain.
How the guard works
- 1
ZipLoom queries your live DNS and email-auth records.
- 2
DNSSEC, CAA, SPF, DKIM and DMARC are validated.
- 3
Dangling records that invite subdomain takeover are flagged.
What this check inspects
CNAME and A records pointing at services that no longer exist — the dangling records that enable subdomain takeover.
SPF, DKIM, and DMARC, which decide whether anyone can send email as your domain.
CAA records, which control who may issue certificates for you.
Nameserver and DNSSEC configuration for the live domain.
What it means when this fails
A subdomain pointing at a de-provisioned service is an open invitation: whoever claims that service next serves content from your domain, with your name and your cookies in play. Missing email authentication is the same problem for your inbox — anyone can send invoices that appear to come from you.
Questions
- What is a subdomain takeover, concretely?
- You pointed blog.yourdomain.com at a hosting service and later deleted the site but not the DNS record. Someone else signs up for that service, claims the same hostname, and now controls a page on your domain.
- Why does DMARC matter if I don't send email?
- Because it stops other people sending as you. A domain with no policy is the easiest one to spoof in phishing.
- Is this a one-time check?
- No. DNS drifts as you add and remove services, so it's re-checked rather than assumed.
What it replaces
Better Stack Uptime
Uptime monitoring, on-call and status pages. Tells you it broke; doesn't roll the release back.
Checkly Starter
Synthetic API and Playwright browser checks. Team plan $64/mo for all regions.
Snyk Team
Per contributing developer, 5-seat minimum (~$1,500/yr entry). Code + dependency scanning; does not deploy your app.
ZipLoom Solo — all 28 features included
Deploy, security scan, and monitoring in one flat price. Guild $40/mo · Studio $70/mo · Business $299/mo.
Related features