Subdomain takeover vulnerabilities occur when a subdomain ( is pointing to a service (e.g. GitHub pages, Heroku, etc.) that has been removed or deleted. This allows an attacker to set up a page on the service that was being used and point their page to that subdomain. For example, if was pointing to a GitHub page and the user decided to delete their GitHub page, an attacker can now create a GitHub page, add a CNAME file containing, and claim

Security Impact

A successful subdomain takeover enables an attacker to serve content on the subdomain. If the subdomain is a child domain of the service’s basename, then the attacker can read and set cookies on the basename too – can set cookies for


Make sure to remove the DNS entry on the subdomain pointing to the deleted service to ensure that nobody can take it over.

