Subdomain Takeover happens when an attacker gains control of a subdomain that still points to an external service or resource that is no longer in use.
It may sound like a complex cyberattack, but the cause is often surprisingly simple: an old DNS record was never removed.
Companies constantly create subdomains for websites, applications, development environments, support platforms, cloud services, and marketing campaigns. When one of these services is deleted, its DNS record should also be updated or removed. If that does not happen, the record may become a dangling DNS record.
That small configuration mistake can create an opportunity for someone else to claim the abandoned resource and serve content through your subdomain.
Let’s look at how subdomain takeover works, why it matters, and what you can do to prevent it.
Table of Contents
What Is Subdomain Takeover?
A subdomain is an additional part of a domain name.
For example:
example.com – main domain
blog.example.com – subdomain
support.example.com – subdomain
Companies often connect these subdomains to external platforms using DNS records.
For example, a business might create:
blog.example.com CNAME company-blog.hosting-service.com
The CNAME record tells DNS resolvers that blog.example.com should direct visitors to the external hosting service.
Everything works normally while the company controls company-blog.hosting-service.com.
The problem starts when the company deletes that external resource but leaves the CNAME record in its DNS zone.
The DNS record still exists, but its destination does not.
This is known as a dangling DNS record.
If the service provider allows another person to register or recreate the abandoned resource, an attacker may claim it. Because the original DNS record still points there, visitors to blog.example.com could now reach content controlled by the attacker.
That is a subdomain takeover.
Experience Industry-Leading DNS Speed with ClouDNS!
Ready for ultra-fast DNS service? Click to register and see the difference!
How Does Subdomain Takeover Happen?
A typical subdomain takeover follows a simple chain of events.
Imagine that a company creates store.example.com and connects it to a third-party e-commerce platform.
Later, the company closes the online store and deletes its account on that platform. However, nobody removes the DNS record for store.example.com.
The process may look like this:
- The company creates a subdomain.
- A DNS record points the subdomain to an external service.
- The company stops using and deletes that service.
- The DNS record remains active.
- The external resource becomes available for registration again.
- An attacker claims the abandoned resource.
- The company’s subdomain now directs visitors to the attacker’s content.
The attacker does not necessarily need access to the company’s DNS account or domain registrar.
The weakness exists because the legitimate DNS configuration continues pointing to a resource that the company no longer controls.
What DNS Records Can Be Affected?
CNAME records are commonly associated with subdomain takeover because organizations frequently use them to connect subdomains to cloud platforms, hosting services, CDNs, SaaS applications, and other third-party services.
However, other DNS configurations can also create risks.
An A record, for example, may point to an IP address that a company releases back to a cloud provider. If another customer later receives that IP address, the old DNS record could direct traffic to infrastructure outside the company’s control.
An abandoned NS delegation can be especially serious. If a subdomain delegates DNS management to nameservers that the organization no longer controls, another party could potentially gain control over DNS records beneath that subdomain.
The exact risk depends on the provider, record type, and configuration.
Why Is Subdomain Takeover Dangerous?
A forgotten subdomain may not seem important, especially if the company stopped using it years ago. But visitors still see the organization’s real domain name.
That trust creates several security risks.
1. Phishing
An attacker may create a fake login page or another deceptive website on the compromised subdomain.
A URL such as:
account.example.com
can look much more trustworthy than an unrelated domain, making phishing attempts more convincing.
2. Malware and Malicious Content
Attackers could use the subdomain to distribute unwanted or malicious content while benefiting from the reputation of the legitimate parent domain.
3. Cookie and Application Security Risks
Some websites configure cookies or security policies to apply across multiple subdomains.
Depending on the website’s configuration, control of one subdomain could therefore create additional security risks for users or connected applications.
4. Brand and Reputation Damage
Visitors usually do not know how a company’s internal DNS infrastructure works. They simply see the organization’s domain in their browser.
If a trusted subdomain suddenly contains scams, spam, or inappropriate content, users may blame the organization itself.
How to Detect a Potential Subdomain Takeover
Regular DNS audits are one of the simplest ways to reduce the risk.
Start by reviewing the DNS records in your zones and asking a few basic questions:
- Do we still use this subdomain?
- Does the target service still exist?
- Does our organization still control the destination?
- Which team or person owns this resource?
- Do we still need this DNS record?
Pay particular attention to records pointing to third-party platforms and cloud services.
You should also investigate subdomains that suddenly display provider error pages, “resource not found” messages, unexpected content, or other signs that the original service no longer exists.
For larger infrastructures, automated DNS monitoring and asset-management processes can make this much easier.
How to Prevent Subdomain Takeover
Prevention mainly comes down to keeping DNS records and the resources behind them synchronized.
Remove DNS Records Before Deleting Resources
When retiring a website, cloud application, storage bucket, or other external resource, review its DNS configuration first.
Remove or redirect the associated DNS record before releasing the resource whenever possible.
This prevents the DNS record from pointing to something that another user could later claim.
Keep an Inventory of Your DNS Records
Document what important DNS records point to and who owns the associated resources.
This is particularly useful for large organizations where different teams manage DNS, applications, and cloud infrastructure.
An inventory makes forgotten records easier to identify.
Audit DNS Zones Regularly
DNS configurations change over time.
Projects end. Employees leave. Applications move. Cloud resources disappear.
Schedule regular reviews of your DNS zones and remove records that no longer serve a purpose.
Monitor DNS and Infrastructure Changes
Monitoring can help identify unexpected DNS behavior and unavailable resources sooner.
Organizations with many domains and subdomains should consider automated checks instead of relying entirely on manual reviews.
Include DNS in Your Decommissioning Process
When a team removes a service, DNS cleanup should be part of the same process.
A simple checklist can prevent many problems:
Update DNS → verify the change → remove the external resource.
Treating DNS cleanup as part of the resource lifecycle makes dangling records far less likely.
Does DNSSEC Prevent Subdomain Takeover?
No. DNSSEC protects the authenticity and integrity of DNS responses, but it does not determine whether you still control the resource a DNS record points to.
A correctly signed DNS zone can still contain a dangling CNAME or another outdated record.
DNSSEC remains an important DNS security measure, but organizations still need proper DNS record management to prevent subdomain takeover.
Conclusion
Subdomain takeover often starts with something small: a DNS record everyone forgot about.
The best defense is good DNS hygiene. Know which subdomains you operate, understand what their records point to, monitor important services, and remove outdated records when resources are decommissioned.
The larger your DNS infrastructure becomes, the more important regular audits and clear ownership become.
A few minutes spent cleaning up an old DNS record can prevent a forgotten subdomain from becoming a security problem.