Business
Individual
Partners
Intelligence
How we work
Sign in Check my firm
Glossary › Patterns › Infrastructure
Reference · Pattern

Subdomain takeover risk on abandoned CNAME

Severity HighKind InfrastructureEffort to fix TrivialUpdated 29 Sep 2026By LeakTrace
Definition

A DNS CNAME record points to a third-party service (Heroku, S3, GitHub Pages, Zendesk, etc.) that no longer claims the subdomain, allowing anyone to register it and impersonate the parent domain.

What it is

When a subdomain is pointed at a third-party service via CNAME and that service is later decommissioned, the DNS record often survives the cleanup. If the third-party service allows anyone to claim the previously-used name, an attacker can register blog.<yourdomain>.com on that service and serve arbitrary content that appears, to browsers, to users, to email link previews, to be first-party content from your domain.

Why it matters

A takeover-owned subdomain is the highest-trust phishing platform available: it serves a real certificate for your domain, it renders in the browser as your brand, and it inherits any implicit trust the user gives your parent domain. Attackers use them for credential-harvesting phishing, for hosting malware payloads, and for evading enterprise URL-blocklists.

How anyone can check it

nslookup old.yourfirm.ca

A name that points to a service you no longer use can be claimed by someone else.

Remediation direction

Immediate: review every CNAME in your DNS zone, identify records pointing to third-party services, and verify the service still claims the name. Delete or re-claim any orphan. Longer term: process gate every third-party integration decommission with a DNS-cleanup checklist item.

LeakTrace does not perform the fix. In an assessment, every finding carries a step-by-step remediation for the firm’s IT provider.

See what is open from outside before anyone else does. Check my firm →