Subdomain Finder
Discover all subdomains of any domain using Certificate Transparency logs. Free, no API key needed. Powered by crt.sh.
🔒 Powered by crt.sh — Certificate Transparency logs. Free, no API key needed. Results show domains that have had SSL certificates issued.
How to Use
Enter Domain Name
Type the root domain you want to find subdomains for — like example.com.
Start Search
Click Search to scan certificate transparency logs and other sources for subdomains.
View Subdomains
See all discovered subdomains with their status and IP addresses.
Export Results
Copy or download the subdomain list for further analysis.
About This Tool
Subdomains are like branches of a website — blog.example.com, api.example.com, staging.example.com, admin.example.com. Large organizations may have dozens or hundreds of subdomains, each potentially running different services. Our Subdomain Finder discovers all publicly visible subdomains of any domain using certificate transparency logs — the same technique used by security researchers worldwide.
What Are Subdomains?
A subdomain is a prefix added to a root domain. While example.com is the main domain, mail.example.com, shop.example.com and support.example.com are subdomains. Each subdomain can point to a completely different server running different software.
Subdomains serve different purposes: www for the main website, mail or webmail for email, api for API endpoints, blog or news for content sections, staging or dev for testing environments, admin for administrative interfaces, cdn for content delivery, m or mobile for mobile versions.
How Subdomain Discovery Works
Certificate Transparency (CT) logs are public records of all SSL/TLS certificates issued by certificate authorities. When an organization creates a new subdomain with HTTPS, a certificate is issued and recorded in public CT logs. Our tool queries these logs to find all certificates ever issued for a domain — revealing all subdomains that ever had SSL certificates.
This is public information — CT logs exist specifically to make certificate issuance transparent and prevent fraudulent certificates. No private data is accessed in subdomain discovery through CT logs.
Legitimate Uses
Security research: Organizations use subdomain enumeration as part of their own security audits — finding forgotten or exposed services before attackers do. Bug bounty programs: Security researchers participating in authorized bug bounty programs need subdomain lists to comprehensively test a target's attack surface. Competitive research: Understanding how a competitor organizes their web infrastructure (without unauthorized access). Website migration: When moving a large website, ensuring all subdomains are accounted for and migrated correctly.
Important Note
This tool finds publicly visible subdomains through legitimate data sources. It does not probe or attempt to access discovered subdomains. Using discovered subdomain information to attempt unauthorized access to systems is illegal and unethical. Use this tool responsibly and only for authorized security research or your own domains.
Why Use This Tool?
CT Log Search
Finds subdomains from certificate transparency logs.
Fast Discovery
Results appear quickly from public data sources.
Complete List
All discovered subdomains with IP information.
Always Free
No account needed. Search unlimited domains free.
Related Tools
DNS Lookup
Check DNS records for any domain — A, MX, TXT, NS and more.
Use Tool →WHOIS Lookup
Find domain registrar, expiry date and nameservers instantly.
Use Tool →IP Address Lookup
Find location, ISP and timezone for any IP address instantly.
Use Tool →Website Security Scanner
Check if any website is safe before visiting.
Use Tool →Frequently Asked Questions
Finding subdomains through certificate transparency logs queries public data — it is entirely legal. CT logs are public records by design. What you do with discovered information matters: unauthorized access to discovered systems is illegal. Use this tool for authorized research and your own domains.