A subdomain is a hierarchical component of a DNS name located to the left of a higher-level domain, such as shop.example.it or blog.example.it. In these examples, shop and blog are sublabels relative to example.it. Subdomains allow for organizing services, applications, environments, or content without registering a new domain each time. They can be managed within the same DNS zone as the primary domain or delegated to different nameservers, depending on technical and organizational needs. This flexibility supports scalable and modular web architectures while maintaining centralized control over core domains.
Creation and Delegation
To create a subdomain, an DNS record—such as A, AAAA, or CNAME—is added to direct it to a service. An NS record can delegate the entire zone of the subdomain to another team or provider. In both cases, the target service must be configured to recognize the hostname: correct DNS alone is insufficient if the web server lacks the appropriate virtual host or certificate. A subdomain may therefore resolve to an active server but display an error or default content. Proper configuration ensures that traffic reaches intended services and avoids misrouting or exposure issues.
Organizations use subdomains to separate www, email, APIs, login pages, support, documentation, and testing environments. Separation can simplify management and routing, but does not automatically provide security isolation. A vulnerable application on a subdomain may impact the parent domain’s brand or cookies, depending on configurations and attributes. Cookies set at the parent domain level may be sent to multiple subdomains; for sensitive sessions, it is advisable to limit scope and apply appropriate settings. This practice helps mitigate cross-site scripting risks and unauthorized access.
Subdomains and Security
Each subdomain must have a responsible party, a defined purpose, and a decommissioning procedure. A record pointing to an inactive cloud service can create a dangling DNS or subdomain takeover if an attacker claims the resource from the provider. DNS inventories and periodic checks help identify orphaned endpoints. A forgotten subdomain may also retain exposed certificates, content, or credentials. When a project ends, the record should be removed or updated, and the destination verified. Regular audits ensure that outdated or unused subdomains do not pose security threats.
Cookies, CORS, Content Security Policy, and authentication policies must be evaluated for each subdomain. Using a subdomain does not guarantee that the browser treats it as an independent site in all contexts: registrable domain and same-site policy are distinct technical concepts. Configurations can affect access, isolation, and tracking. A security team should document which services are authorized to receive cookies and cross-origin requests. These policies help enforce secure communication and prevent unauthorized data sharing across domains.
SEO and Organization
From an SEO perspective, a subdomain may be treated as part of the same organization or as a distinct property depending on systems and signals. There is no rule that always favors subdomains over subfolders. The choice depends on infrastructure, governance, language, content, and maintenance ease. Canonical tags, sitemaps, internal links, and Search Console must be configured consistently. Moving a section between a subdomain and a folder constitutes a migration requiring redirects and monitoring. Proper implementation ensures continuity of search visibility and user experience.
In summary, a subdomain is a subordinate hostname that enables service separation or organization. Its management involves DNS, hosting, certificates, security, and maintenance. A clear structure and updated inventory prevent orphaned endpoints and inconsistent configurations. Effective governance ensures alignment with business goals while minimizing risks associated with misconfigurations or outdated resources.
← Full glossary