Subdomain Finder
Find a domain's subdomains using public Certificate Transparency logs (Certspotter and crt.sh). Free subdomain finder for auditing and authorised testing.
Find subdomains
Enter a domain to discover subdomains recorded in public Certificate Transparency logs.
What this subdomain finder does
Common use cases
- 1Mapping a domain's public attack surface
- 2Finding forgotten or staging subdomains
- 3Auditing your own subdomain sprawl
- 4Reconnaissance for authorised security testing
- 5Discovering services before a migration
- 6Checking what a domain exposes publicly
Related tools
About Certificate Transparency subdomain discovery
Certificate Transparency (CT) logs are public, append-only records of every TLS certificate issued. Because certificates name the hostnames they cover, CT logs are an excellent, passive source for discovering a domain's subdomains — no scanning required.
Note the limitation: CT only reveals subdomains that were issued a certificate. Internal hosts, or subdomains using wildcard certificates, may not appear. This tool queries public CT sources and is intended for auditing your own domains or authorised security testing.
More Free Tools Where This Came From
This utility is one of dozens of free, no-login tools for DNS, email, SEO and developers — all instant and private.
HostCloud.in · Pune, India · Serving 34,987+ Websites Since 2020
Got Questions? We Have Answers.
How does this subdomain finder work?
It queries public Certificate Transparency logs, which record every TLS certificate issued. Because certificates name their hostnames, the logs reveal subdomains passively — no scanning.
Does it find every subdomain?
No. CT logs only reveal subdomains that were issued their own certificate. Internal hosts, or subdomains under a wildcard certificate, may not appear.
Which sources does it use?
Certspotter as the reliable primary source, with crt.sh as a fallback. Both are public Certificate Transparency providers.
Is using this legal?
Yes — CT logs are public. Use it to audit your own domains or for authorised security testing; do not use findings against systems you are not permitted to test.
Why did I get no results?
The domain may have no certificates in the logs, use only wildcard certificates, or the CT source may be temporarily overloaded. Try again shortly.
Can I export the list?
Yes. Copy a single subdomain or the whole list with one click.
