Delete records for services you no longer use. A subdomain pointing at an abandoned service can be claimed by somebody else and served under your name.

What gets left behind

Every service that ever asked you to add a record left one, and cancelling the service does not remove it.

A booking system, a mailing platform, a help desk, a verification for something you trialled once.

Each one added a line to your DNS, and the line remains after the account is closed.

Most of those are harmless clutter and a specific kind is not.

The dangerous kind

That sequence is a known and automated pattern rather than a theoretical risk. People scan for exactly this, claim the abandoned name at the service, and serve whatever they like on a subdomain of a real business.

Why it matters more than it sounds

Since a subdomain feels peripheral.

Anything appearing at a subdomain of your domain looks like you to a visitor, to a search engine, and to a browser.

It can be used to host something embarrassing, to collect information from people who trust the name, or to send email that appears to come from your business.

Your customers have no way to distinguish it from a page you built.

And the first you know about it is usually somebody asking why your site links to something odd.

A worked example

A business had trialled a help desk product in 2019 and added a subdomain pointing at it.

They cancelled after the trial and forgot the record entirely.

Four years later somebody claimed the abandoned name at that service and put a page on it.

Their own site was unaffected and the subdomain served somebody else's content under their business name for several weeks.

Deleting the record resolved it in minutes.

The whole exposure existed because a line in a settings page outlived the account it referred to.

Read the whole list

Which is the exercise and takes about fifteen minutes.

Open your DNS settings, wherever they live, and read every record.

For each one, ask what it is for and whether that thing still exists.

Records for services you recognise and use stay.

Records for services you cannot identify, or that you know you cancelled, are the ones to investigate.

Most small business domains have between eight and twenty records, so this is a readable list rather than a project.

Which records to look at hardest

Since some types matter more than others.

Anything pointing a subdomain at an external service by name is the category described above.

Anything pointing a subdomain at a numeric address is worth checking, since that server may no longer be yours.

Verification records for services you no longer use are clutter rather than risk, and can be removed.

Mail records are their own subject and should not be touched without knowing what they do.

When in doubt, note it and ask rather than deleting, since a wrongly deleted record can take a service offline.

Delete rather than leave

Which is the general rule.

A record with no purpose is a small risk and no benefit, so removing it is the correct action.

Before deleting, note what it was in your records, so that if something breaks you know what to restore.

Then wait a week before deleting the next batch, which makes any consequence traceable to a specific change.

Deleting fifteen records in one afternoon and discovering something broken is a considerably worse position.

Do it whenever you cancel something

Which prevents the accumulation.

Cancelling a service should include removing whatever record it asked you to add.

That is a step nobody includes because cancelling feels finished once the billing stops.

Add it to whatever list you keep, alongside removing the payment method and exporting anything you need.

One line in a process prevents the whole category.

Check the subdomains resolve to you

As a quick verification afterwards.

Type each subdomain you found into a browser and see what appears.

Your own content, an error, or nothing at all are all fine.

Somebody else's content, a login page you do not recognise, or a parked page is the finding.

That takes about a minute and confirms in practice what the list told you in theory.

Two of those checks disagreeing is itself the finding worth investigating.

Find out where your DNS actually lives

Which is the step before any of this and is frequently the harder question.

DNS can be managed at your registrar, at your host, at a separate provider, or at a service somebody added years ago, and only one of those is authoritative.

Editing records in the wrong place produces no effect at all, which people interpret as a caching delay and wait out for days.

The name server settings at your registrar tell you where the records are actually served from, and that is the place to make changes.

Write that down in the same document as the domain list, since it is the one piece of information that makes every future change straightforward.

The counter-case

Most stale records are harmless.

A verification line for a service that closed years ago does nothing at all, and the majority of what you find will be that.

There is also a genuine risk of removing something that is quietly load-bearing, particularly around mail, where the consequence is immediate.

And a domain with only four records has very little to audit and can be read in a minute.

Do it anyway, since that minute establishes what normal looks like for next time.

Read every DNS record, identify what each is for, check any subdomain pointing at an external service, and delete in small batches.

The fifteen minutes

  1. Open your DNS settings.
  2. Read every record.
  3. Ask what each is for.
  4. Flag any external service you left.
  5. Open each subdomain in a browser.
  6. Note before deleting.
  7. Delete in small batches.

Step four is the one with a real consequence attached, since a subdomain pointing at an abandoned account can be claimed by somebody else and served under your name.

How subdomains are treated generally is covered in subdomains, folders and what Google sees.


Frequently asked questions

What gets left behind?

Every service that asked you to add a record left one, and cancelling the service does not remove it. A booking system, a mailing platform, a trial you abandoned.

Which kind is dangerous?

A subdomain pointing at a service where your account is closed, leaving the name unclaimed. Somebody else can claim it and serve their content under your name.

Is that a real risk?

Yes, and an automated one. People scan for exactly this pattern, claim the abandoned name at the service, and serve whatever they like.

Why does a subdomain matter?

Anything at a subdomain of your domain looks like you to a visitor, a search engine, and a browser, and your customers cannot distinguish it from a page you built.

How do I check?

Open your DNS settings and read every record, asking what each is for. Most small business domains have between eight and twenty, so it is a readable list.

How should I delete?

Note what each record was first, then delete in small batches with a week between them, so any consequence is traceable to a specific change.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

Trialled a service years ago that asked for a DNS record?

Check whether that record is still there. An abandoned account leaves a name somebody else can claim.

Start a Conversation