Arsenly
Tools
Free Tools
Pricing
Resources
Sign in Get started
← All tools

Subdomain Takeover Scanner

Web Security Audit

Resolve CNAME chains, match ~30 takeover-prone services, detect dangling targets and verify with a live fingerprint.

What is Subdomain Takeover Scanner?

Subdomain Takeover Scanner checks whether a hostname delegates (via CNAME) to a third-party service - S3, GitHub Pages, Heroku, Azure, Netlify, Shopify, Fastly and ~30 more - whose backing resource is no longer claimed, a condition that lets an attacker serve content on the victim’s subdomain.

For each host it resolves the full CNAME chain (so multi-hop delegations are caught), matches every hop against the service library, checks whether the final target is NXDOMAIN (a classic dangling signal), and verifies live candidates by fetching the page and matching the service’s error-page fingerprint.

Every result gets a ranked verdict - vulnerable / likely / review / safe - with the evidence and, for real candidates, the exact method to claim the resource. Paste a whole subdomain list (up to 50) straight from Subdomain Discovery.

What it does

  • CNAME-chain analysis - follows multi-hop delegations to the final third-party target.
  • ~30 service signatures - S3, GitHub, GitLab, Heroku, Azure, Netlify, Shopify, Fastly, Pantheon, Zendesk and more.
  • NXDOMAIN dangling detection - flags targets whose backing resource no longer resolves.
  • Live fingerprint check - confirms candidates against each service’s takeover error page.
  • Ranked verdict + claim method - vulnerable / likely / review / safe, with how to claim it.
  • Bulk - scan up to 50 hosts in parallel; copy or export the report.

Where it fits in your workflow

  • Turn dangling-CNAME findings from DNS recon into confirmed takeovers.
  • Sweep an enumerated subdomain list for high-impact, easy wins.
Use Subdomain Takeover Scanner

Run it from your dashboard.

Create free account Sign in Use via API

At a glance

CategoryWeb Security Audit
RunsServer-side
Token cost 5 / run (free tier)
Access Pro
Status● Live

Frequently asked questions

A host matched a fingerprint - is it definitely takeover-able?

A match is a strong lead, but always confirm by checking the service’s claim process. Some fingerprints overlap with not-yet-provisioned but owned resources - that is why the tool separates “vulnerable” (confirmed) from “review”.

Is it legal to claim the resource?

Only act on assets you are authorised to test. Confirming a takeover on someone else’s subdomain without permission is out of scope and can be unlawful.

Explore more tools →