---
id: "domain-shadowing"
kind: "glossary-term"
title: "domain shadowing"
language: "en"
category: "Security and abuse"
updated: "2026-10-04T14:01:23Z"
canonical: "https://tldlog.com/glossary/domain-shadowing/"
translations:
  es: "https://tldlog.com/es/glosario/domain-shadowing/"
  de: "https://tldlog.com/de/glossar/domain-shadowing/"
  fr: "https://tldlog.com/fr/glossaire/domain-shadowing/"
  it: "https://tldlog.com/it/glossario/domain-shadowing/"
  pt-BR: "https://tldlog.com/pt/glossario/domain-shadowing/"
  ru: "https://tldlog.com/ru/glossariy/domain-shadowing/"
  zh-Hans: "https://tldlog.com/zh/cihui/yuming-yinying/"
---

# domain shadowing

An attack in which criminals who have broken into a domain owner's registrar or DNS account quietly add their own subdomains. The main website keeps working, so the owner notices nothing, while the new subdomains borrow the domain's good reputation to host phishing or malware.

## related terms

- [subdomain](https://tldlog.com/glossary/subdomain/)
- [registrar account takeover](https://tldlog.com/glossary/registrar-account-takeover/)
- [DNS hijacking](https://tldlog.com/glossary/dns-hijacking/)
- [domain reputation](https://tldlog.com/glossary/domain-reputation/)
- [maliciously registered vs compromised domain](https://tldlog.com/glossary/maliciously-registered-domain/)
