PASSIVE SUBDOMAIN SCAN

Subdomain Finder

Discover the subdomains of any domain from public certificate logs, then see which ones are live.

Passive lookup only: names come from public certificate transparency logs, so nothing is sent to the target's web servers. Results show subdomains that have had an HTTPS certificate issued, and may be incomplete. Only scan domains you own or have permission to assess.

How It Works

1 · Collect
Certificate logs

Every public HTTPS certificate is logged. We read those logs for names under your domain.

2 · Resolve
DNS check

Each name is looked up over DNS-over-HTTPS from your browser to see if it has an address.

Frequently Asked Questions

What is a subdomain?

A subdomain is a prefix added to a domain, such as blog.example.com or mail.example.com. Organisations use them for separate sites, apps, mail servers and internal tools.

Why would I look up subdomains?

Site owners use it to audit their own attack surface and find forgotten or abandoned hosts. It is also handy for checking what a migration left behind, or confirming a certificate was issued where you expect.

Why is a subdomain missing from the results?

This method only finds names that appeared on a public HTTPS certificate. Subdomains that never had a certificate, or that sit under a wildcard certificate, will not show up. No passive method finds everything.

What does “No record” mean?

The name appeared on a certificate at some point but currently has no DNS address. It may have been removed, or only exist on an internal network.

More Network Tools