Files
rengine/shared/utils/infra.py
T
Yogesh Ojha 48b16be96f style(correlation): terse comments
Collapse descriptive docstrings/comment blocks in the correlation engine
to single-line notes.
2026-05-31 08:03:20 +05:30

51 lines
1.1 KiB
Python

"""Detection of shared / managed DNS infrastructure (poor correlation keys)."""
_SHARED_NS_TOKENS = frozenset(
{
"cloudflare",
"awsdns",
"azure-dns",
"googledomains",
"ultradns",
"dnsmadeeasy",
"akamai",
"domaincontrol",
"registrar-servers",
"worldnic",
"name-services",
"cloudns",
"vercel-dns",
"wpengine",
"wixdns",
"squarespacedns",
"dnsimple",
"nsone",
}
)
_SHARED_NS_DOMAINS = frozenset(
{
"he.net",
"gandi.net",
"ovh.net",
"akam.net",
"name.com",
"digitalocean.com",
"linode.com",
}
)
def is_shared_nameserver(host: str | None) -> bool:
if not host:
return False
normalized = host.strip().lower().rstrip(".")
if not normalized:
return False
if any(token in normalized for token in _SHARED_NS_TOKENS):
return True
return any(
normalized == domain or normalized.endswith(f".{domain}")
for domain in _SHARED_NS_DOMAINS
)