Subdomain Takeover Risk

High Severity Technical Guide

Vulnerability Description

A subdomain takeover occurs when an organization has a DNS record (typically a CNAME record) pointing to an external service provider (such as GitHub Pages, AWS S3, Heroku, or Zendesk) that has been deleted or unclaimed. An attacker can register an account with that provider and claim the subdomain, enabling them to host malicious code under your official brand name.

Remediation Guide

To resolve this vulnerability, follow these config changes or developer practices:

1. Regularly audit your DNS records to identify dangling CNAMEs. 2. Remove any DNS records pointing to deleted or inactive third-party hosts immediately. 3. Verify and claim subdomains in external services before creating DNS records.

Verify Your Fix

After applying the remediation, run an external attack-surface scan to verify that the vulnerability is no longer detected by WebScanify.

Is your website vulnerable?

Run a free security scan now to identify missing headers, outdated JS, and other deployment vulnerabilities.