Subdomain discovery & takeover
Find the subdomains you forgot before someone else does.
Subdomain takeover is mundane: a CNAME points at a SaaS vendor, the account gets closed, and the DNS record keeps pointing at a name anyone can claim. Then someone does, and your domain serves their content. Bastion discovers your subdomains continuously and flags the dangling ones while they're still just a cleanup task.
No card required to start. Plans from $25/month; first scan in about a minute.
How takeovers actually happen
The vendor outlives the record
Marketing trials a platform, the trial ends, the CNAME stays. Months later the target name is claimable by whoever asks — and your subdomain serves whatever they put there.
Discovery favors the attacker
Every certificate ever issued for a subdomain is public in CT logs. Attackers enumerate them systematically; most owners have never looked.
A takeover inherits your name
Content on a real subdomain of your domain passes casual inspection, can carry convincing phishing, and in some setups shares cookie scope with production.
Staging never got decommissioned
Preview deployments and test boxes get certificates too. They're part of your surface whether or not they're in your inventory.
How Bastion closes the gap
The same discovery, working for you
Continuous subdomain enumeration from certificate transparency logs — the attacker's primary source, pointed at your own estate. New names surface within days of their first cert.
Dangling CNAMEs flagged explicitly
DNS records pointing at unclaimed or deprovisioned targets are called out as findings with the evidence inline, so cleanup is a ticket rather than a hunt.
Alerts on every new name
A subdomain nobody told you about is a change worth hearing about the week it appears — not during an incident. How takeover works, in plain language →
Discovered hosts join the watch
Found subdomains get the same checks as everything else — TLS, headers, exposed services — so a forgotten box can't stay both forgotten and unmonitored.
Common questions
What is a subdomain takeover?
A subdomain takeover happens when a DNS record — usually a CNAME — points at an external service that no longer hosts your content, and an attacker claims that service name. Your subdomain then serves the attacker's content with your domain in the address bar. It's prevented by removing or repointing stale records, which requires knowing they exist.
Where does Bastion's subdomain list come from?
Primarily certificate transparency logs — the public record of every certificate issuance — plus DNS resolution of what's found. It's passive: no brute-force wordlists fired at your infrastructure, and discovery only runs for domains you've verified you own.
Can Bastion take down a hijacked subdomain?
No — remediation is a DNS change only you can make. What Bastion does is make the window small: dangling records are flagged while they're still unclaimed, and new subdomains are alerted as they appear.
See your domain the way an attacker enumerates it.
Verify ownership and the discovery starts with the first scan.
Start your 7-day trialNo card required to start. Cancel any time.