Not cool. TIL: when you have a delegated zone to #
azure, in bind for example:
sub.example.com. IN NS ns1-05.azure-dns.com.
sub.example.com. IN NS ns2-05.azure-dns.net.
sub.example.com. IN NS ns3-05.azure-dns.org.
sub.example.com. IN NS ns4-05.azure-dns.info.
and in azure someone decommissioned the zone (but the delegation remains), then every dumbass can hijack sub.example.com. You don't have to prove that you're entitled to use sub.example.com.
That opens a wide door to for example phishing: login.sub.example.com is a good starting point.
Well done, Microsoft!