dnsspof
F
7/100
craigslist.org

Critical single point of failure — Nameservers and web origin in one ASN.

NS 6 web 1 MX 2 CDN no DNSSEC no

Network dependency map

each block is one resolved endpoint, coloured by Autonomous System
DNS
Web
Mail
  • AS22414 CRAIGS-NET-1 - Craigslist, Inc.×9

Findings

7
critical network Nameservers and web origin in one ASN

Authoritative DNS and the web origin both live in AS22414 (CRAIGS-NET-1 - Craigslist, Inc.). One BGP withdrawal or network outage removes name resolution and the origin together — with DNS gone there is no failover path. This is exactly how Facebook took itself fully offline in 2021.

7 endpoints
  • ns1a.craigslist.org → 208.82.237.71 · AS22414 CRAIGS-NET-1 - Craigslist, Inc. · US
  • ns1f.craigslist.org → 208.82.238.71 · AS22414 CRAIGS-NET-1 - Craigslist, Inc. · US
  • ns2a.craigslist.org → 208.82.237.72 · AS22414 CRAIGS-NET-1 - Craigslist, Inc. · US
  • ns2f.craigslist.org → 208.82.238.72 · AS22414 CRAIGS-NET-1 - Craigslist, Inc. · US
  • ns9a.craigslist.org → 208.82.237.79 · AS22414 CRAIGS-NET-1 - Craigslist, Inc. · US
  • ns9f.craigslist.org → 208.82.238.79 · AS22414 CRAIGS-NET-1 - Craigslist, Inc. · US
  • craigslist.org → 208.82.237.129 · AS22414 CRAIGS-NET-1 - Craigslist, Inc. · US

Move authoritative DNS onto a wholly independent network so resolution survives an origin-network outage.

high dns All nameservers in one ASN

Every nameserver lives in AS22414 (CRAIGS-NET-1 - Craigslist, Inc.). A single BGP or network failure there takes the whole domain offline — the failure mode behind the 2016 Dyn outage.

6 endpoints
  • ns1a.craigslist.org → 208.82.237.71 · AS22414 CRAIGS-NET-1 - Craigslist, Inc. · US
  • ns1f.craigslist.org → 208.82.238.71 · AS22414 CRAIGS-NET-1 - Craigslist, Inc. · US
  • ns2a.craigslist.org → 208.82.237.72 · AS22414 CRAIGS-NET-1 - Craigslist, Inc. · US
  • ns2f.craigslist.org → 208.82.238.72 · AS22414 CRAIGS-NET-1 - Craigslist, Inc. · US
  • ns9a.craigslist.org → 208.82.237.79 · AS22414 CRAIGS-NET-1 - Craigslist, Inc. · US
  • ns9f.craigslist.org → 208.82.238.79 · AS22414 CRAIGS-NET-1 - Craigslist, Inc. · US

Add a secondary DNS provider on a different ASN.

medium dns All nameservers in one country

Every nameserver geolocates to US. Regional connectivity, regulatory, or disaster events become correlated failures.

6 endpoints
  • ns1a.craigslist.org → 208.82.237.71 · AS22414 CRAIGS-NET-1 - Craigslist, Inc. · US
  • ns1f.craigslist.org → 208.82.238.71 · AS22414 CRAIGS-NET-1 - Craigslist, Inc. · US
  • ns2a.craigslist.org → 208.82.237.72 · AS22414 CRAIGS-NET-1 - Craigslist, Inc. · US
  • ns2f.craigslist.org → 208.82.238.72 · AS22414 CRAIGS-NET-1 - Craigslist, Inc. · US
  • ns9a.craigslist.org → 208.82.237.79 · AS22414 CRAIGS-NET-1 - Craigslist, Inc. · US
  • ns9f.craigslist.org → 208.82.238.79 · AS22414 CRAIGS-NET-1 - Craigslist, Inc. · US

Spread nameservers across regions, or use an anycast provider with global PoPs.

medium web Single web origin IP

The site resolves to exactly one IP with no CDN in front. That host is a hard single point of failure.

1 endpoints
  • craigslist.org → 208.82.237.129 · AS22414 CRAIGS-NET-1 - Craigslist, Inc. · US

Put the origin behind a CDN/anycast layer, or publish multiple origins across networks.

medium mail Mail concentrated in one ASN

All MX hosts resolve into AS22414 (CRAIGS-NET-1 - Craigslist, Inc.). Mail is queue-and-retry tolerant, but a sustained network failure still blocks delivery.

2 endpoints
  • mxicorpa.craigslist.org → 208.82.237.80 · AS22414 CRAIGS-NET-1 - Craigslist, Inc. · US
  • mxicorpa.craigslist.org → 208.82.237.81 · AS22414 CRAIGS-NET-1 - Craigslist, Inc. · US

Publish MX records pointing at independently-networked mail infrastructure.

low web No CDN in front of the origin

The origin is directly exposed: no anycast absorption, no edge caching, and the origin IP is visible for targeted attack.

Front the site with a CDN (Cloudflare, Fastly, CloudFront, …).

low dns DNSSEC not enabled

No DS record at the parent: responses are not cryptographically authenticated and can be forged by an on-path attacker or a poisoned resolver.

Enable DNSSEC signing and publish a DS record at the registrar. (Automate key rollover — misconfigured DNSSEC can itself cause outages.)

DNS records

Nameserversns1a.craigslist.org
ns1f.craigslist.org
ns2a.craigslist.org
ns2f.craigslist.org
ns9a.craigslist.org
ns9f.craigslist.org
A208.82.237.129
MX10 mxicorpa.craigslist.org
SOAns1f.craigslist.org. hostmaster.craigslist.org. 2026072802 10800 1800 2419200 300
CAA2 record(s) present
DNSSECunsigned
TXT5 record(s)

Scan history

  • F2026-08-01 00:57 UTCscore 7 · 1 network
  • F2026-08-01 00:57 UTCscore 7 · 1 network
  • F2026-08-01 00:57 UTCscore 7 · 1 network
  • F2026-08-01 00:57 UTCscore 7 · 1 network
  • F2026-08-01 00:53 UTCscore 7 · 1 network
  • F2026-07-30 10:50 UTCscore 7 · 1 network
  • F2026-07-30 10:50 UTCscore 7 · 1 network
  • F2026-07-30 10:50 UTCscore 7 · 1 network

← scan another domain