DomainScan enumerates every discoverable subdomain via Certificate Transparency logs and a curated brute-force list, resolves each one, and flags CNAMEs that point to unclaimed resources on 30+ known-vulnerable services. The Subdomain Enum + Attack Surface capability runs on Pro and above; the Free tier scans two domains continuously so you can pilot the check on a live property before rolling it out.
All questions
How does DomainScan detect subdomain takeover risk?
Read the full guide
What Is a Subdomain Takeover? (And Why Microsoft Had 670 of Them)
Subdomain takeover is the class of bug where a `CNAME` points to a service you already gave up — like an old S3 bucket, an expired Azure Cloud App, or a decommissioned Heroku dyno. An attacker registers the abandoned resource, and now they serve traffic from your subdomain.