Glossary

Subdomain Takeover — Detection and Prevention

Takeover happens when status.yourdomain.com still CNAMEs to GitHub or S3 you deleted — an attacker claims that bucket or repo and suddenly hosts a phishing page on your subdomain.

How Subdomain Takeovers Happen

You tear down the Heroku app but leave the CNAME. Someone else creates a new app with the same target name. Now they control your hostname.

High-Risk Services

Classic sinks:

How to Prevent Subdomain Takeovers

  1. Delete DNS when you kill the cloud resource
  2. Audit CNAMEs quarterly — boring but cheap
  3. Run our dangling scan when you inherit a zone

Scan your zone for takeover bait

Open Dangling Records →