Can CNAME Cloaking used to serve ads and tracks you?
Yes.
Example
they hide google-analytics domain via their own CNAME
Ads block tracker
- https://hostfiles.frogeye.fr/firstparty-trackers-hosts.txt
- https://hostfiles.frogeye.fr/firstparty-only-trackers-hosts.txt
Who is currently doing this?
Below are the 6 tracking companies that are currently using CNAME cloaking:
Solution?
- Use Firefox , Firefox for desktop does allow extensions to make DNS queries themselves, and extensions like uBlock Origin already apply their blocking rules to intermediary CNAMEs as well.
- Dont use Chromemium based brwoser, such as Opera, Brave, Mirosoft Edge.
References