Subdomain Takeover
A new tool extracted from the codebase.
Last reviewed by the Radiatus Cloud team
Need this done properly for your business?
Radiatus delivers secure cloud, DevOps & compliance engineering.
Check for dangling subdomains
A subdomain takeover happens when a subdomain’s DNS still points to a service, a cloud host, a platform, that has been decommissioned, letting someone claim that service and control content on your subdomain. This checker helps you find such dangling DNS entries on your own domains.
Why dangling DNS is a risk
When you stop using a hosted service but leave the DNS record pointing at it, the underlying resource can sometimes be re-registered by someone else, who then serves content from your subdomain, which carries your domain’s trust. This is used for phishing and to bypass protections that trust your domain. It is easy to create by forgetting to remove a DNS record during cleanup.
The defence
The defence is DNS hygiene: remove DNS records when you decommission the service they point to, and audit periodically for records pointing at unclaimed resources. Checking for dangling entries catches them before someone else does. This is for defensive assessment and education around systems you own or protect, or for authorised security testing and awareness, not for targeting others. It runs entirely in your browser, so nothing you enter is uploaded, which matters when the input concerns your own security posture.
Related tools
- User Agent Parser — Parse a User-Agent string into browser, engine, operating system and device. Explains why UA strings are unreliable and what to use instead.
- QR Code Generator — Generate QR codes for URLs, text, Wi-Fi and contact details. Adjustable error correction and size, produced entirely in your browser.
- Credit Card Validator — Validate a card number with the Luhn algorithm and identify the issuing network from its prefix. Runs locally, nothing is transmitted.
- Text Case Converter — Convert text between camelCase, PascalCase, snake_case, kebab-case, CONSTANT_CASE, Title Case and sentence case. Runs entirely in your browser.
Frequently Asked Questions
What is a subdomain takeover?
When a subdomain’s DNS still points to a decommissioned service, letting someone else claim that service and serve content on your subdomain.
Why is it dangerous?
Because content on your subdomain carries your domain’s trust, so it can be used for convincing phishing or to bypass protections that trust your domain.
How does it happen?
By leaving a DNS record pointing at a hosted service after you stop using it, so the underlying resource can be re-registered by someone else.
How do I prevent it?
Remove DNS records when decommissioning the service they point to, and audit periodically for records pointing at unclaimed resources.
Is my input uploaded?
No. It runs entirely in your browser.
Privacy & Security
Processed locally.
About This Tool
This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
User Agent Parser
UtilityParse a User-Agent string into browser, engine, operating system and device. Explains why UA strings are unreliable and what to use instead.
QR Code Generator
UtilityGenerate QR codes for URLs, text, Wi-Fi and contact details. Adjustable error correction and size, produced entirely in your browser.
Credit Card Validator
UtilityValidate a card number with the Luhn algorithm and identify the issuing network from its prefix. Runs locally, nothing is transmitted.