Subdomain takeover begins with abandoned ownership

Subdomain takeover is the same failure with a name: an abandoned service, a record still pointing at it, and somebody else registering the far end.

The result is an attacker hosting content on a genuine subdomain of your organisation, with a valid certificate, which is close to ideal for phishing. The defensive work is unexciting: know what records exist, and remove the record as part of decommissioning rather than afterwards.

More on DNS and domains