All Security Checks
Infrastructure CheckA08:2021

Domain Hijacking Detection

Detect subdomain takeover vulnerabilities and domain registration security issues.

Domain hijacking and subdomain takeover occur when DNS records point to deprovisioned services. Our scanner checks for dangling DNS records, subdomain takeover vectors across common cloud providers, and domain registration security settings.

What This Scanner Does

Enumerates subdomains and checks CNAME records for dangling pointers to deprovisioned services (AWS S3, Azure, GitHub Pages, Heroku, etc.). Checks domain registration for transfer lock status and registrar security settings.

Why It Matters

Subdomain takeover lets attackers host content on your subdomain, which they can use for phishing, cookie theft (same-origin), or serving malware with your brand's trust. It is surprisingly common in organizations that spin up and decommission cloud services frequently.

Common Findings

  • Dangling CNAME pointing to deprovisioned S3 bucket
  • Subdomain pointing to unclaimed GitHub Pages
  • Domain transfer lock not enabled
  • Expired service with active DNS record

OWASP Top 10 Coverage

A08:2021Software & Data Integrity Failures

Run This Check on Your Site

Get a full security report with AI-powered fix suggestions in 30 seconds. No setup required.

Related Security Checks