Network & DNS

Subdomain Finder

Discover publicly known subdomains for any domain using certificate transparency logs and passive DNS.

Domain or URL only — e.g. example.com or https://example.com/page → checks example.com

About this tool

What is Subdomain Finder?

Find publicly known subdomains for any domain using certificate transparency logs and passive DNS data. Ideal for attack surface mapping.

subdomain findersubdomain enumerationsubdomain discoveryattack surface mappingsubdomain scanner

FAQ

Frequently asked questions

How does subdomain discovery work?

This tool queries certificate transparency logs (e.g. crt.sh) and passive DNS databases that index publicly observed DNS records.

Are all subdomains returned?

Only publicly observed subdomains are returned. Internal or recently created subdomains may not appear.

Why is subdomain enumeration useful for security?

Forgotten or unmanaged subdomains are common attack vectors — they may run outdated software or have misconfigured access controls.

Is subdomain discovery legal?

Querying public certificate transparency logs and passive DNS is legal. Active brute-force enumeration against a target you do not own may not be.

Related

automated security

Need continuous coverage?

PandaONE runs autonomous agents against your app, validates findings with proof, and opens fixes as pull requests.

Get started