Takeover risk

Surge subdomain takeover.

A subdomain still pointing at a Surge account that no longer exists is not untidy. It is claimable.

What it looks like

A subdomain on your domain has a CNAME record pointing at a surge.sh target, and loading that subdomain returns Surge's unclaimed page rather than a working site. The visible signature is a page containing text along the lines of "project not found".

Both signals are needed. A CNAME pointing at Surge is completely normal when the service is in use. It only matters when the target is no longer claimed.

Why it can be taken over

Surge projects are trivially created and claimed, which makes an abandoned record here easy to capture.

What an attacker gets

  • Content served from your subdomain, on your domain, usually with a valid certificate that Surge issues automatically.
  • A phishing address that passes every check a cautious person would run, because it genuinely is your domain.
  • Access to any cookie your main site scopes to the parent domain, which can include session data.

How to fix it

Remove the record. Surge is commonly used for quick demos, so these records are usually left from a one-off that nobody remembers.

The full removal steps for any provider are in the dangling record guide.

Stopping the next one

These appear whenever a hosted service is trialled and dropped, so a single cleanup does not settle it. The habit worth building is deleting the DNS record in the same sitting as the cancellation, because those are separate actions and only one of them is on anyone's mind.

Related

Check yours

See whether anything on your domain points nowhere.

The free subdomain check finds every name still resolving and confirms which targets are unclaimed.

Other services with the same risk

Each has its own detection signature and removal steps.

Microsoft Azure · Amazon CloudFront · Ghost · Netlify · Kajabi · Zendesk

All 24 in this set