8

SUBDOMAIN TAKEOVER

The Definitive Guide

8 chapters Last updated 21 September 2026 Free to read, no account

A subdomain pointing at a service you cancelled is not untidy. With several providers it is claimable, and whoever claims it controls what is served from your address, on your domain, usually with a valid certificate.

Most writing on this is either a vulnerability disclosure or a tool README. Very little explains how these appear in ordinary businesses, which is by cancelling a trial and forgetting the DNS record.

This guide covers the mechanism, how to find every instance on a domain you own, what each provider does differently, and how to stop new ones appearing.

In this guide you will learn:

  • What makes a dangling record claimable rather than merely broken
  • How to enumerate every subdomain you own, without guessing
  • Which providers release names and which block reclaiming
  • What an attacker actually gains, including cookie scope
  • How to check a whole portfolio rather than one domain
  • The habit that stops new ones appearing

Contents

1

What a dangling record is

The two conditions, and why only one of them is a problem.

2

How they appear in real businesses

Trials, campaigns, redesigns, and the action nobody takes afterwards.

3

Finding every subdomain you own

Certificate transparency, and why guessing names is unnecessary.

4

Confirming a takeover risk

The CNAME is not enough. What the second signal is.

5

What an attacker gains

Content, certificates, cookies, and why phishing here is convincing.

6

Provider by provider

Which release names, which verify domains, which block reclaiming.

7

Fixing and preventing

One DNS deletion, and the habit that stops the next one.

8

Watching a portfolio

Doing this once settles nothing. What ongoing looks like.

Chapter 1

What a dangling record is

The two conditions, and why only one of them is a problem.

What a dangling record is

This chapter is not written yet. Drop the prose into guide-bodies/<body>.html and rebuild.

Chapter 2

How they appear in real businesses

Trials, campaigns, redesigns, and the action nobody takes afterwards.

How they appear in real businesses

This chapter is not written yet. Drop the prose into guide-bodies/<body>.html and rebuild.

Chapter 3

Finding every subdomain you own

Certificate transparency, and why guessing names is unnecessary.

Finding every subdomain you own

This chapter is not written yet. Drop the prose into guide-bodies/<body>.html and rebuild.

Chapter 4

Confirming a takeover risk

The CNAME is not enough. What the second signal is.

Confirming a takeover risk

This chapter is not written yet. Drop the prose into guide-bodies/<body>.html and rebuild.

Chapter 5

What an attacker gains

Content, certificates, cookies, and why phishing here is convincing.

What an attacker gains

This chapter is not written yet. Drop the prose into guide-bodies/<body>.html and rebuild.

Chapter 6

Provider by provider

Which release names, which verify domains, which block reclaiming.

Provider by provider

This chapter is not written yet. Drop the prose into guide-bodies/<body>.html and rebuild.

Chapter 7

Fixing and preventing

One DNS deletion, and the habit that stops the next one.

Fixing and preventing

This chapter is not written yet. Drop the prose into guide-bodies/<body>.html and rebuild.

Chapter 8

Watching a portfolio

Doing this once settles nothing. What ongoing looks like.

Watching a portfolio

This chapter is not written yet. Drop the prose into guide-bodies/<body>.html and rebuild.

Check yours

See where your own domain stands.

Everything in this guide, checked on your domain in about ten seconds. Free, no account, every finding shown in full.