Hacker News new | ask | show | jobs
by eriknstr 3580 days ago
I began investigating DNS records to determine if there was some way there to conclusively ascertain that dropboxmail.com was legitimately owned by Dropbox. I could not find a way to determine this through DNS.

Next, I went to dropboxmail.com in my web browser, which redirected me to a page on dropbox.com [0] assuring me that dropboxmail.com was owned by dropbox.com.

[0]: https://www.dropbox.com/en/help/217

1 comments

The redirection is not a valid way to test ownership as an attacker can easily redirect.