Category
network security
Topic
DNS leak via former federal domain (bafl.de)
Audience
Public authorities, IT security officers & policymakers
Reading time
approx. 10 minutes

Netzpolitik.org has also analysed this case and drawn a connection to a parliamentary question on the topic of government domains. A technical analysis will follow shortly on our blog.

This blog post documents a particularly high-profile incident relating to the lack of management of federal domains: A former federal domain, which had been used for many years by the Federal Office for Migration and Refugees (BAMF), was acquired by Mint Secure GmbH in August 2025 and is apparently still being actively queried by the federal government’s internal systems to this day.

In August 2025, security experts at Mint Secure GmbH registered the domain bafl.de, which had previously been in use by the BAMF for over a decade and had, in the meantime, even fallen into the hands of dubious operators. DNS analyses show that the domain is still being used within internal infrastructures: systems belonging to the Federal Ministry of the Interior (BMI) and the BAMF are continuously sending DNS queries to the domain and its subdomains. The incident was reported to the Federal Office for Information Security (BSI) back in September 2025. Nevertheless, the queries are still ongoing to this day (as at 10 December 2025). The situation highlights the sensitivity of public authority IT systems and the urgent need to strengthen both organisational and technical requirements for digital sovereignty.

This is not the first security-related error in the BAMF’s domain management: as early as February 2025, Mint Secure GmbH gained administrative access to a (test) user management system at the agency by registering an expired domain.

Background on the BAFL

BAFL stands for the “Federal Office for the Recognition of Foreign Refugees”, the predecessor agency of today’s BAMF. The domain bafl.de served as its official website from at least 2000 to 2013. The Wayback Machine displays archived content from this period: web.archive.org/web/20250000000000*/http://www.bafl.de/bafl/

The following image shows an archived version from 2001 of the website at “bafl.de”, taken from the Internet Archive (archive.org):

Website des BAFL

In the years that followed, the website was continuously expanded until, from 2005 onwards, it was redirected to the new domain bamf.de. The following image shows an archived version from 2005 of the website at ‘bafl.de’, taken from the Internet Archive (archive.org):

Website des BAFL/BAMF 2005

A few years later, an automatic redirect was put in place, which remained in effect until at least 2013.

Weiterleitung von bafl.de auf bamf.de

Although bafl.de appears to have remained reserved for a few more years afterwards (presumably by the BAMF or on its behalf), it contained no active content. At some point, however, the domain expired and changed hands.

Was the domain in the hands of dubious operators for a time?

Between September 2022 and August 2024, a rather bizarre-looking website appeared on bafl.de (at least during the following period: 12 September 2022 to 8 August 2024, see web.archive.org/web/20240501000000*/bafl.de).

The website of the self-styled “Federal Alternative for the Recognition of Foreign Refugees” was found in the Internet Archive. The website also featured stock photos and presumably displayed AI-generated text. Furthermore, the website had no valid legal notice.

Dubiose bafl.de Website

A reverse image search of several images from the website at the time revealed that the same method had been used for numerous websites with very similar content and approaches. It is believed this was done to capitalise on potential SEO (search engine optimisation) benefits and subsequently link to dubious websites (such as gambling sites). This is particularly interesting in the case of domains such as bafl.de, as other federal or government websites also link to it. There are also documents on bund.de that contain references to bafl.de.

Reverse-Image-Search zur bafl.de Website
It is unclear whether the BAMF or other public authorities realised that the domain might be being misused or that misuse was being prepared, or whether they attempted during this period to take the domain offline or take action against the operators. However, the website was online in this form for at least approx. two years, and it would be surprising if no one at the BAMF or other public authorities had noticed this.

Purchase of the domain in 2025

The domain “bafl.de” was deleted on 30 July 2025 and was then put up for sale again following a 30-day Redemption Grace Period (RGP)
.

Redemption Grace Period (RGP) zu bafl.de
Mint Secure GmbH intended to purchase the domain after the 30 days had elapsed; however, it was snapped up more quickly by a domain grabber.

Anzeige zum Verkauf von bafl.de
Subsequently, however, the domain was sold again (see above) and was acquired by Mint Secure GmbH for €70.00 in August 2025, making it the current lawful owner of the domain.

Gebot für bafl.de

Initial analysis of the DNS logs

Following the acquisition of the domain, a DNS server was set up to enable a more detailed analysis of the data traffic relating to the domain “bafl.de”. DNS logs reveal which queries are made to which domains. Furthermore, responses to DNS queries can be retrieved. The screenshots shown here are extracts from the logs, as a full analysis and further publication will likely only take place once the issue has been resolved and will presumably be presented in more detail during a talk at 39c3 on the topic.

DNS-Logs zu bafl.de

The screenshot above shows that the A record (i.e. the mapping of a server name to an IPv4 address) is being queried multiple times

 

Furthermore, there are queries for ‘localhost’ in the logs. Queries to localhost.domain.de usually indicate misconfigurations, for example when devices or applications automatically append a DNS search domain. They can also occur if internal DNS suffix lists are incorrectly configured, thereby extending localhost. These are often harmless DNS leaks from private networks. Overall, the causes are usually technically trivial, but should be reviewed if the queries occur with unusual frequency.

DNS-Logs zu bafl.de (localhost-Anfragen)

What is particularly striking about the DNS queries described is that they originate from the networks of federal authorities. For example, the network range 77.87.224.0/22 (from which most queries originate) can be unambiguously attributed to AS49234, the Federal Ministry of the Interior and Homeland (BMI).

ipinfo zu abrufenden IP-Adressen

Since September 2025, there have been thousands of such DNS queries. Some occur daily and automatically, whilst others appear to result from manual pings or queries to IT systems.

In the worst-case scenario, the domain bafl.de would have served as an uncontrolled technical entry point into the internal networks of the BMI and the BAMF. The ongoing DNS queries would have allowed attackers to identify internal hostnames, services and network structures, thereby gaining detailed information about the IT infrastructure. Manipulated DNS responses could potentially have redirected internal systems to external servers. This could have enabled the delivery of fake updates, manipulated configuration files or malicious content. Under unfavourable circumstances, it would even have been possible to execute code. Over a prolonged period, attackers could thus have gained persistent insight into the public authorities’ processes, systems and vulnerabilities. Overall, the incident could have led to significant technical and security-related damage for the concerned public authorities.

“This situation highlights the sensitivity of public authority IT systems and the urgent need to strengthen both organisational and technical foundations for digital sovereignty.”
Mint Secure GmbH

Timeline

  • Approx. 2000–2013: Use of the domain bafl.de by the BAMF and its predecessor agencies (possibly for a few further years)
  • Approx. September 2022 to August 2024: Hosting of a suspected fraudulent website by third parties
  • End of August 2025: Registration of the bafl.de domain by Mint Secure GmbH, followed by the set-up of a DNS server for technical analysis
  • 24 September 2025: Analysis of the logs and initial report to the BSI (CERT-Bund) regarding the daily receipt of DNS queries from federal networks
  • 25 September 2025: Confirmation of receipt by the BSI (CERT-Bund) and that the matter would be forwarded to the relevant authorities
  • 11 October 2025: Further enquiry to the BSI (CERT-Bund) regarding the status of the matter (as DNS queries continue to be sent from federal networks)
  • 22 October 2025: Letter from security@bamf.bund.de thanking the sender for the report and stating that they intend to look into the matter (presumably following prior notification from the BSI)
  • 4 November 2025: Further enquiry to the BAMF regarding the status (as DNS requests continue to be sent from federal networks)
  • 8 November 2025: Reply from security@bamf.bund.de stating that the matter would be dealt with
  • 3 December 2025: Further enquiry to security@bamf.bund.de and the BSI (CERT-Bund), as DNS queries were still being sent from federal networks
  • 10 December 2025: Publication of this blog post

Update 23 December 2025:

The domain “bafl.de” has been successfully transferred to the BAMF.

This and other cases illustrating the (in)security of government domains will be presented in more detail during a talk at the Chaos Computer Club’s 39c3.

How Mint Secure supports you

Expiring or former domains are an often-overlooked risk for public authorities and businesses. We support you with the following services:

🌐

Domain and DNS security audits

We check your domain portfolio for expiring, forgotten or misconfigured domains and DNS entries.

🏛️

Coordinated Vulnerability Disclosure for public authorities

We coordinate the responsible reporting of vulnerabilities with the BSI, CERTs and public authorities.

🛡️

Digital sovereignty consulting

We provide consulting services to public authorities and businesses on organisational and technical measures for sovereign, resilient IT infrastructures.

Conclusion

The bafl.de case demonstrates how long an expired federal domain can continue to have an impact within a public sector organisation’s internal infrastructure without being detected – ranging from years of use by dubious operators to thousands of DNS queries originating from the networks of the BMI and BAMF, even months after a responsible report had been made to the BSI.

The incident highlights how important systematic management of their own domain portfolios is for public authorities and businesses, particularly with regard to digital sovereignty and resilience.

Mint Secure supports public authorities and businesses in identifying such blind spots within their own IT infrastructure.
Talk to us.