Subdomain Takeover Scanner
Detect dangling CNAME records pointing to unclaimed GitHub Pages, Heroku, Azure, Netlify, S3, and 25 more services
DNS-over-HTTPS only — no port scans, no direct connection to subdomains unless confirming a finding
How it works
1Probe 60+ common subdomains (www, api, staging, blog, dev, cdn, mail…) for CNAME records via DNS-over-HTTPS
2Match each CNAME target against 28 service fingerprints — GitHub Pages, Heroku, Netlify, Vercel, Azure, S3, Shopify, Fastly, Zendesk, and more
3For matched CNAMEs, HTTP-confirm by fetching the subdomain and checking for unclaimed service body fingerprints
4For unrecognised CNAMEs, check if the CNAME target has a live A record — if not, it's a dangling pointer attackers could claim