Back to Blog

How to stop fake SSL certificates and DNS hijacks – simple checklist

How to stop fake SSL certificates and DNS hijacks – simple checklist
October 8, 2026|David Velarde RoblesDavid Velarde Robles

Hook: Why a fake Google site could hurt your business tomorrow

Imagine a customer typing the correct address of a well‑known website, only to land on a look‑alike that looks perfectly legitimate. That’s what happened this week when attackers hijacked a few country‑code top‑level domains (ccTLDs) and minted fraudulent SSL certificates for Google and several other organisations. The browsers didn’t raise any warnings, so visitors could be tricked into entering passwords, credit‑card numbers or other sensitive data.

If a similar trick were used against your own online shop, you could lose customers, damage your reputation, and even face legal consequences. The good news is that the attack relied on a few technical steps that you can monitor and block with a simple checklist. Below we explain the threat in plain language and give you practical actions you can take today.

What a DNS hijack is – explained for a non‑technical business owner

Domain Name System (DNS) is the phone book of the internet. When someone types yourshop.nl into a browser, DNS translates that human‑readable name into the numeric IP address where your website lives.

A DNS hijack occurs when an attacker gains control over the DNS records for a domain. They can change the record that points yourshop.nl to a different IP address – one they own. Visitors are then sent to the attacker’s server instead of yours, even though the address in the browser bar looks unchanged.

In the recent incident, the attackers first took over the DNS zones of a few ccTLDs (for example .gh for Ghana). With that control they could issue new DNS entries for any domain that used those extensions. Once the traffic was redirected, they asked a Certificate Authority (the organisation that issues SSL certificates) to create a fake HTTPS certificate for the targeted domain. Because the certificate appeared valid, browsers displayed the familiar padlock icon and did not warn the user.

The result? A perfectly convincing copy of a trusted site that could harvest login credentials, payment details, or spread malware – all without the usual “your connection is not private” warning.

Three‑step checklist to stop a fake SSL certificate and DNS hijack

1. Verify the SSL certificate for your online store (small business) regularly

  • What to look for: Click the padlock icon in the address bar and view the certificate details. Check that the Issued to field matches your exact domain (including any sub‑domains) and that the Issued by field is a trusted Certificate Authority you have authorised.
  • How to automate it: Use a monitoring tool that alerts you when a new certificate appears for any of your domains. Many services can send an email or Slack notification the moment a certificate is issued.

2. Monitor DNS changes and Certificate Transparency (CT) logs

  • DNS monitoring: Set up alerts with your domain registrar or a third‑party service that notifies you of any change to your DNS records (A, CNAME, MX, etc.). Even a single unexpected change should trigger a review.
  • CT log monitoring: Certificate Transparency is a public log of every SSL certificate that is issued. By watching these logs for your domains you can spot unauthorised certificates the moment they are created. Services exist that scan the logs and send you a warning if a new certificate appears for yourshop.nl or any related domain you own.

3. Publish restrictive CAA (Certification Authority Authorization) records

  • What CAA does: A CAA DNS record tells the world which Certificate Authorities are allowed to issue certificates for your domain. If an attacker tries to obtain a certificate from an unauthorised CA, the request will be rejected.
  • How to implement: Add a CAA record to your DNS zone that lists only the CA(s) you actually use (for example, “letsencrypt.org” or “digicert.com”). This is a simple text line in your DNS settings and can be added in minutes.

Following these three steps creates multiple layers of defence: you’ll notice a rogue certificate, you’ll be alerted to any DNS tampering, and you’ll make it harder for an attacker to obtain a certificate even if they temporarily control your DNS.

A small‑business illustration: the local bakery’s online shop

Consider Bakkerij De Zon, a neighbourhood bakery that recently added an online ordering page at bakkerijdeszon.nl. The owner, Marieke, isn’t a tech expert, but she knows that customers need to feel safe when they type in their credit‑card details.

  1. Certificate check: Marieke uses a low‑cost monitoring service that emails her whenever a new SSL certificate is issued for bakkerijdeszon.nl. One morning she receives a notice that a certificate was created by an unfamiliar CA. She immediately contacts her hosting provider, confirms the certificate is not hers, and revokes it.
  2. DNS alert: The same service also watches the DNS records. When a change to the A‑record appears (pointing the domain to a different IP), Marieke gets a text message. She discovers that the change was made by a compromised employee account and restores the correct record.
  3. CAA protection: By adding a CAA record that only allows “letsencrypt.org”, any future attempt by an attacker to get a certificate from another CA will be automatically rejected, even if they manage to hijack the DNS again.

Because Marieke follows the checklist, her customers continue to see the trusted padlock icon and feel confident ordering fresh bread online. The bakery avoids a potentially costly breach and keeps its reputation intact.

FAQ

Q: How can I tell if my website’s SSL certificate is fake?
A: Click the padlock, view the certificate details, and verify that the domain name matches exactly what you own and that the issuing authority is one you recognise. If you see a different domain (e.g., yourshop.com instead of yourshop.nl) or an unknown CA, treat it as suspicious.

Q: Do I need to monitor every sub‑domain I own?
A: Yes. Attackers often target less‑visible sub‑domains (like shop.yourshop.nl or login.yourshop.nl) because they are less likely to be checked regularly. Include all active sub‑domains in your CT‑log and DNS‑change monitoring.

Q: My website only gets traffic from Dutch browsers – do I still need to worry about Chrome’s automatic blocking?
A: Chrome’s blocking helped in the recent incident, but it only protects Chrome users and only after the browser has identified the rogue certificate. Other browsers (Firefox, Edge, Safari) may still show a green padlock. Relying on browser‑side protection alone leaves a gap; the checklist gives you control regardless of the visitor’s browser.

Closing: Let us help you stay one step ahead

Keeping an eye on SSL certificates, DNS records, and CAA settings can feel like a full‑time job, especially when you’re busy running your business. IT Move NL’s Security & Protection service takes care of the technical details for you. We provide:

  • Ongoing SSL certificate management and real‑time alerts
  • Continuous monitoring of Certificate Transparency logs for every domain you own
  • Automated DNS‑change notifications and CAA‑record configuration

To get started, we’re offering a free security health‑check for your website. We’ll review your current setup, point out any gaps, and show you how the three‑step checklist can be applied without disrupting your daily operations.

Protect your customers, protect your brand – reach out today and let us handle the security so you can focus on what you do best.


Sources:

David Velarde Robles
David Velarde Robles

He/Him · AWS Certified Solutions Architect | Cloud Engineer @ Essent

Cloud Engineer at Essent B.V. with 10+ years of experience in the tech industry. AWS Certified, passionate about serverless architectures, Infrastructure as Code, and DevOps. Proficient in TypeScript, Python, and Terraform. Based in Amersfoort, Netherlands.

>

STAY IN THE LOOP

// Cloud, AI & DevOps insights — straight to your inbox.

>

No spam. Unsubscribe anytime.

Share this article:

Need help with your cloud infrastructure?

Our team of experts is ready to help you navigate the complexities of modern cloud architecture.

Get in Touch