Subdomain Takeover Scanner

Detect dangling CNAME records pointing to unclaimed GitHub Pages, Heroku, Azure, Netlify, S3, and 25 more services

DNS-over-HTTPS only — no port scans, no direct connection to subdomains unless confirming a finding

How it works

1Probe 60+ common subdomains (www, api, staging, blog, dev, cdn, mail…) for CNAME records via DNS-over-HTTPS
2Match each CNAME target against 28 service fingerprints — GitHub Pages, Heroku, Netlify, Vercel, Azure, S3, Shopify, Fastly, Zendesk, and more
3For matched CNAMEs, HTTP-confirm by fetching the subdomain and checking for unclaimed service body fingerprints
4For unrecognised CNAMEs, check if the CNAME target has a live A record — if not, it's a dangling pointer attackers could claim