Resolve CNAME chains, match ~30 takeover-prone services, detect dangling targets and verify with a live fingerprint.
Subdomain Takeover Scanner checks whether a hostname delegates (via CNAME) to a third-party service - S3, GitHub Pages, Heroku, Azure, Netlify, Shopify, Fastly and ~30 more - whose backing resource is no longer claimed, a condition that lets an attacker serve content on the victim’s subdomain.
For each host it resolves the full CNAME chain (so multi-hop delegations are caught), matches every hop against the service library, checks whether the final target is NXDOMAIN (a classic dangling signal), and verifies live candidates by fetching the page and matching the service’s error-page fingerprint.
Every result gets a ranked verdict - vulnerable / likely / review / safe - with the evidence and, for real candidates, the exact method to claim the resource. Paste a whole subdomain list (up to 50) straight from Subdomain Discovery.
A match is a strong lead, but always confirm by checking the service’s claim process. Some fingerprints overlap with not-yet-provisioned but owned resources - that is why the tool separates “vulnerable” (confirmed) from “review”.
Only act on assets you are authorised to test. Confirming a takeover on someone else’s subdomain without permission is out of scope and can be unlawful.