Attack surface
Subdomain takeover check
A DNS record still pointing at a hosted service you stopped using can be claimed by someone else, who then serves pages on your domain.
Check this on your own domain now. It is free with a DomainGuard account and works on any domain. The check reads only what your domain publishes, and gives you a report you can send to whoever runs your website.
What we look at
Once a day we follow each subdomain's CNAME record to where it ends. If it ends at a service like GitHub Pages, Heroku, S3 or Azure, we check whether that service still has anything set up for the name: the name no longer exists, or the service shows its own "nothing here" page. We load that page once and only count it when both the record and the page agree.
Why it matters to your business
Anyone can sign up at those services and claim a name that's been released. Whoever does gets a working page at your subdomain, under your name and inside your cookies' reach, which is a ready-made phishing site.
How to fix it
- Delete the DNS record for the subdomain if you no longer use the service.
- Or set the service back up under the same name, so it is yours again.
If you would rather not touch DNS or server settings yourself, forward this page and your report to whoever manages your website, or ask us to do it.
Keep an eye on it
A one-off check tells you how things stand today. On Starter and up, DomainGuard re-checks the domains it watches every day and alerts you in the app when something important changes, so you hear about it before a customer does.
