A security researcher said an expired nameserver domain allowed her to take control of DNS responses for several neglected ENUM zones, exposing a weakness in infrastructure once intended to help route telephone calls over the internet.

The date for the account is 2026-08-21. In a detailed post on lina.sh, the researcher described buying the expired domain enum.org.uk for 5€ after finding that three e164.arpa zones were delegated to two nameservers, one of which no longer resolved and the other of which depended on the expired domain. The affected zones were listed as 0.9.2.e164.arpa, 6.4.2.e164.arpa and 7.4.2.e164.arpa, corresponding when reversed to country calling codes +290, +246 and +247: Saint Helena, the British Indian Ocean Territory, including Diego Garcia, and Ascension Island.

ENUM, according to the post, was designed in the early 2000s to map telephone numbers into DNS names under e164.arpa. A carrier could query the relevant DNS name and receive records indicating whether a number could be reached through SIP or another internet-based calling path. The researcher wrote that the system “never really took off” and is now largely dormant, but because it uses DNS, control of a delegated nameserver can still determine the answers returned for lookups beneath that zone.

The post said the immediate security concern was not merely cosmetic control of old domains. If a carrier made an ENUM lookup for one of the affected numbers, whoever controlled the nameserver could theoretically return routing information of their choosing. The researcher described a possible man-in-the-middle scenario in which a call could be directed through an attacker-controlled SIP server before being connected onward to the intended recipient, while appearing normal to the parties on the call.

After discovering the issue, the researcher said she reported it through multiple channels to the British government but received no reply. Q Misell, identified in the post as a researcher at the Max Planck Institute for Informatics, later reported the matter to RIPE on her behalf. The post says RIPE declined to intervene because e164.arpa delegations are governed through an ITU-T committee at United Nations level.

The researcher initially logged traffic only for the Saint Helena zone and observed no queries during a full day. She then retained the domains and used them for personal services, believing the system was unused. Later, after checking logs for all three zones, she found hundreds of thousands of ENUM queries. Because ENUM encodes telephone numbers by reversing their digits into DNS labels, the logs contained full phone numbers, timestamps and resolver source IP addresses.

According to the account, almost none of the activity involved Saint Helena. The queries were concentrated in the Diego Garcia and Ascension Island zones, with source IP addresses described as mostly American. The researcher concluded that she had inadvertently logged large volumes of lookup data for calls to military bases and warned that a malicious actor could have abused the same weakness more aggressively.