DNS Dangling CNAME & Cloud Subdomain Takeover Fingerprint Checker
Scan DNS CNAME records for dangling aliases pointing to decommissioned AWS S3 buckets, GitHub Pages, Heroku, Azure Apps, Shopify, and Cloudflare zones. Match canonical response fingerprints and prevent hostile subdomain takeovers.Documentation & FAQs ↓
Subdomain Takeover CNAME Signature & Dangling DNS Checker
Cloud orphan asset detection, fingerprint regex matching, CLI verification commands & DNS remediation playbook.
Target Host & CNAME Record
Response body precisely matches the known Heroku App orphan fingerprint. An attacker can register this resource to claim full HTTP control & SSL certificates!
Signature & Fingerprint Profile
"Heroku | No such app"# 1. Query live DNS CNAME resolution: dig +nocmd docs.company.com CNAME +noall +answer # 2. Inspect HTTP headers & response signature: curl -sI -H "Host: docs.company.com" https://company-docs.herokuapp.com/ # 3. Check for specific takeover fingerprint pattern: curl -sL -H "Host: docs.company.com" https://company-docs.herokuapp.com/ | grep -i "Heroku | No such app"
Remediation Action Playbook
- Immediate DNS Purge: Delete the CNAME record for
docs.company.comfrom Cloudflare or your authoritative nameserver immediately to stop traffic rerouting. - Asset Reclamation: Claim the app name on Heroku and link the custom domain, or remove the DNS entry from your nameserver zone.
- Continuous CI/CD Audit: Implement automated teardown hooks to ensure ephemeral cloud test environments delete DNS records upon pull-request merge.
Cloud Provider Signature Reference Database (12 Providers)
| Provider | Canonical CNAME | HTTP Code | Error Signature Fingerprint | Severity |
|---|---|---|---|---|
| GitHub Pages | .github.io | 404 | "There's nothing here yet." | HIGH |
| AWS S3 Bucket | .s3.amazonaws.com, .s3-website-, .s3-website. | 404 | "<Code>NoSuchBucket</Code>" | CRITICAL |
| Heroku App | .herokuapp.com, .herokudns.com | 502 | "Heroku | No such app" | CRITICAL |
| Shopify Store | shops.myshopify.com | 404 | "Sorry, this shop is currently unavailable." | HIGH |
| Azure Web Apps | .azurewebsites.net, .trafficmanager.net, .cloudapp.net | 404 | "404 Web Site not found." | CRITICAL |
| Fastly CDN | .fastly.net | 500 | "Fastly error: unknown domain" | HIGH |
| Surge.sh Static | .surge.sh | 404 | "project not found" | HIGH |
| Bitbucket Cloud | .bitbucket.io | 404 | "Repository not found" | MEDIUM |
| Ghost(Pro) Blogging | .ghost.io | 404 | "The thing you were looking for is no longer here" | MEDIUM |
| Pantheon Web Ops | .pantheonsite.io | 404 | "The gods are wise, but do not know of the site which you seek." | HIGH |
| Zendesk Help Center | .zendesk.com | 404 | "Help Center Closed" | MEDIUM |
| WordPress.com Hosted | .wordpress.com | 404 | "Do you want to register" | MEDIUM |
Step-by-Step Instructions
4 Steps to CompletionEnter the fully qualified domain name (FQDN) or subdomain you want to audit (e.g., docs.example.com).
Select whether to inspect CNAME canonical alias chains, Cloudflare proxy status, or target HTTP status response codes.
Run the scan to query DNS-over-HTTPS records and match targets against the fingerprint database.
Review the vulnerability risk rating (Safe, Warning, or High Risk) and follow the specific vendor mitigation steps.
Practical Use Cases & Real-World Scenarios
Multi-Provider Fingerprint Signature Engine
Cross-references CNAME destinations against known takeover signatures for over 40 cloud services including AWS S3, GitHub Pages, Heroku, Netlify, and Azure Web Apps.
Dangling DNS Resolution & NXDOMAIN Audit
Queries authoritative DNS over HTTPS (DoH) providers (Cloudflare, Google) to detect orphaned aliases pointing to non-existent target domains.
HTTP Error Response Fingerprinting
Identifies classic takeover error pages such as 'There's nothing here, yet' (GitHub), 'NoSuchBucket' (AWS S3), and 'No such app' (Heroku).
Remediation & Secure DNS Configuration Guide
Provides actionable step-by-step remediation directives to delete stale DNS records or claim orphaned cloud tenants before malicious actors exploit them.
Frequently Asked Questions
What is a subdomain takeover vulnerability?↓
Why are dangling CNAMEs dangerous for brand security and SEO?↓
Which cloud services are most vulnerable to dangling CNAME takeovers?↓
How do Cloudflare and modern DNS providers prevent subdomain takeovers?↓
What is the immediate fix for a vulnerable dangling CNAME?↓
15 Best Penetration Testing Tools in 2026
Dive deeper into the foundational technical concepts behind this tool on our editorial blog. Includes comprehensive hardware benchmarks, case studies, and best practices.
Found this tool helpful? Share it with colleagues & friends:
100% free, private in-browser utility with zero server uploads.
