This is the multi-page printable view of this section. Click here to print.

Return to the regular view of this page.

Domain Takeovers

Information on how specific services protect (or don’t) against domain takeovers (DTO)

Domain Takeovers

Domain takeovers or subdomain takeovers occur when DNS records are not properly updated or removed when a service is moved or shut down. Best case the domain just doesn’t work anymore. Worst case a threat actor can leverage 3rd party services to serve malicious content using your domain / brand.

1 - Firebase

Firebase domain takeovers

Currently, Firebase protects against domain takeovers by requiring each domain to have a unique CNAME or TXT record on the affected domain.

Firebase DNS Settings

2 - Squarespace

Squarespace domain takeovers

Currently, Squarespace protects against domain takeovers by requiring each domain to have a unique CNAME record on the affected domain.

Squarespace DNS Settings