DNS Dangling CNAME & Cloud Subdomain Takeover Fingerprint Checker

Scan DNS CNAME records for dangling aliases pointing to decommissioned AWS S3 buckets, GitHub Pages, Heroku, Azure Apps, Shopify, and Cloudflare zones. Match canonical response fingerprints and prevent hostile subdomain takeovers.Documentation & FAQs ↓

DNS Dangling CNAME & Cloud Subdomain Takeover Fingerprint Checker — Interactive Console
Runs locally in your browser • Instant output

Subdomain Takeover CNAME Signature & Dangling DNS Checker

Cloud orphan asset detection, fingerprint regex matching, CLI verification commands & DNS remediation playbook.

Target Host & CNAME Record

HTTP Response Body / Error Snippet:
Common Vulnerability Scenarios
CRITICAL: SUBDOMAIN TAKEOVER DETECTEDSeverity: CRITICAL

Response body precisely matches the known Heroku App orphan fingerprint. An attacker can register this resource to claim full HTTP control & SSL certificates!

Signature & Fingerprint Profile

ServiceHeroku App
HTTP Code502
CNAME Pattern.herokuapp.com
RemediationDNS Zone Purge
Exact Fingerprint String:"Heroku | No such app"
CLI Verification Commands (dig & curl)
# 1. Query live DNS CNAME resolution:
dig +nocmd docs.company.com CNAME +noall +answer

# 2. Inspect HTTP headers & response signature:
curl -sI -H "Host: docs.company.com" https://company-docs.herokuapp.com/

# 3. Check for specific takeover fingerprint pattern:
curl -sL -H "Host: docs.company.com" https://company-docs.herokuapp.com/ | grep -i "Heroku | No such app"

Remediation Action Playbook

  1. Immediate DNS Purge: Delete the CNAME record for docs.company.com from Cloudflare or your authoritative nameserver immediately to stop traffic rerouting.
  2. Asset Reclamation: Claim the app name on Heroku and link the custom domain, or remove the DNS entry from your nameserver zone.
  3. Continuous CI/CD Audit: Implement automated teardown hooks to ensure ephemeral cloud test environments delete DNS records upon pull-request merge.

Cloud Provider Signature Reference Database (12 Providers)

ProviderCanonical CNAMEHTTP CodeError Signature FingerprintSeverity
GitHub Pages.github.io404"There's nothing here yet."HIGH
AWS S3 Bucket.s3.amazonaws.com, .s3-website-, .s3-website.404"<Code>NoSuchBucket</Code>"CRITICAL
Heroku App.herokuapp.com, .herokudns.com502"Heroku | No such app"CRITICAL
Shopify Storeshops.myshopify.com404"Sorry, this shop is currently unavailable."HIGH
Azure Web Apps.azurewebsites.net, .trafficmanager.net, .cloudapp.net404"404 Web Site not found."CRITICAL
Fastly CDN.fastly.net500"Fastly error: unknown domain"HIGH
Surge.sh Static.surge.sh404"project not found"HIGH
Bitbucket Cloud.bitbucket.io404"Repository not found"MEDIUM
Ghost(Pro) Blogging.ghost.io404"The thing you were looking for is no longer here"MEDIUM
Pantheon Web Ops.pantheonsite.io404"The gods are wise, but do not know of the site which you seek."HIGH
Zendesk Help Center.zendesk.com404"Help Center Closed"MEDIUM
WordPress.com Hosted.wordpress.com404"Do you want to register"MEDIUM
Advertisement

Step-by-Step Instructions

4 Steps to Completion
1Phase 1

Enter the fully qualified domain name (FQDN) or subdomain you want to audit (e.g., docs.example.com).

2Phase 2

Select whether to inspect CNAME canonical alias chains, Cloudflare proxy status, or target HTTP status response codes.

3Phase 3

Run the scan to query DNS-over-HTTPS records and match targets against the fingerprint database.

4Phase 4

Review the vulnerability risk rating (Safe, Warning, or High Risk) and follow the specific vendor mitigation steps.

Practical Use Cases & Real-World Scenarios

Enterprise Security Audits & Red Team Scans
Audit corporate root and subdomains to eliminate dangling records left behind after marketing campaign teardowns and cloud migrations.
Bug Bounty Hunters & Vulnerability Research
Rapidly verify candidate subdomain takeover vectors and confirm whether an alias target is unclaimed.
Cloud Migration & Decommissioning Verification
Confirm that migrating from Heroku or GitHub Pages to Next.js or Cloudflare Workers left no orphaned legacy DNS pointers.
Related Editorial Guide on AnshuTechy15 Best Penetration Testing Tools in 2026
Read Tutorial →
Share With Your Community

Found this tool helpful? Share it with colleagues & friends:

100% free, private in-browser utility with zero server uploads.