What it is
When a subdomain is pointed at a third-party service via CNAME and that service is later decommissioned, the DNS record often survives the cleanup. If the third-party service allows anyone to claim the previously-used name, an attacker can register blog.<yourdomain>.com on that service and serve arbitrary content that appears, to browsers, to users, to email link previews, to be first-party content from your domain.
Why it matters
A takeover-owned subdomain is the highest-trust phishing platform available: it serves a real certificate for your domain, it renders in the browser as your brand, and it inherits any implicit trust the user gives your parent domain. Attackers use them for credential-harvesting phishing, for hosting malware payloads, and for evading enterprise URL-blocklists.
How anyone can check it
nslookup old.yourfirm.caA name that points to a service you no longer use can be claimed by someone else.
Remediation direction
Immediate: review every CNAME in your DNS zone, identify records pointing to third-party services, and verify the service still claims the name. Delete or re-claim any orphan. Longer term: process gate every third-party integration decommission with a DNS-cleanup checklist item.
LeakTrace does not perform the fix. In an assessment, every finding carries a step-by-step remediation for the firm’s IT provider.