Subdomain Takeover Checker
SecurityCheck subdomains for potential takeover vulnerabilities via dangling CNAME records.
Check subdomains for potential takeover vulnerabilities via dangling CNAME records.
Get access to all 150+ tools with higher limits. Start with 100 free credits — no credit card required.
curl -X POST "https://krawly.io/api/v1/tools/subdomain-takeover/" \
-H "Content-Type: application/json" \
-H "Authorization: Bearer YOUR_API_KEY" \
-d '{"url": "https://example.com"}'Subdomain Takeover Checker scans common subdomains for dangling CNAME records that point to unclaimed third-party services like GitHub Pages, Heroku, AWS S3, etc.
Check DMARC, SPF, and DKIM DNS records for any domain to assess email authentication and prevent spoofing.
Find HTTP resources loaded on HTTPS pages. Detect active and passive mixed content issues.
Analyze Content Security Policy headers. Check for unsafe-inline, unsafe-eval, and wildcards.
Analyze cookies set by a website. Check Secure, HttpOnly, SameSite flags and compliance issues.