CRITICAL

Subdomain Takeover

What is it?

A subdomain has a CNAME pointing to a service (Vercel, Netlify, Heroku) where the target resource no longer exists. An attacker can claim it.

How to fix

Remove the dangling CNAME record from your DNS, or re-create the resource at the target service.

Scan for this vulnerability

Security Scanner automatically checks for this issue as part of its 70+ module scan. Try it free — no signup needed for the quick scan.

Check your app now →

Related reading