---
id: "subdomain-takeover"
kind: "glossary-term"
title: "subdomain takeover"
language: "en"
category: "Security and abuse"
updated: "2026-10-04T14:01:23Z"
canonical: "https://tldlog.com/glossary/subdomain-takeover/"
translations:
  es: "https://tldlog.com/es/glosario/toma-control-subdominio/"
  de: "https://tldlog.com/de/glossar/subdomain-takeover/"
  fr: "https://tldlog.com/fr/glossaire/prise-controle-sous-domaine/"
  it: "https://tldlog.com/it/glossario/subdomain-takeover/"
  pt-BR: "https://tldlog.com/pt/glossario/tomada-subdominio/"
  ru: "https://tldlog.com/ru/glossariy/zakhvat-poddomena/"
  zh-Hans: "https://tldlog.com/zh/cihui/ziyuming-jieguan/"
---

# subdomain takeover

An attack that exploits a forgotten DNS record. A subdomain still points to an outside service, such as a cloud host, that the owner has stopped using. An attacker claims that resource and then controls what the subdomain shows. Such leftover records are called dangling DNS.

## related terms

- [subdomain](https://tldlog.com/glossary/subdomain/)
- [CNAME record](https://tldlog.com/glossary/cname-record/)
- [Sitting Ducks attack](https://tldlog.com/glossary/sitting-ducks/)
- [DNS hijacking](https://tldlog.com/glossary/dns-hijacking/)
- [expired domain takeover](https://tldlog.com/glossary/expired-domain-takeover/)
