Developer Tools/ Subdomain Finder

Subdomain Finder

Discover all subdomains of any domain using Certificate Transparency logs. Free, no API key needed. Powered by crt.sh.

FreeCertificate Transparencycrt.sh PoweredDownload ResultsNo Sign-up
Try:

🔒 Powered by crt.sh — Certificate Transparency logs. Free, no API key needed. Results show domains that have had SSL certificates issued.

Was this helpful?
Share:

How to Use

1

Enter Domain Name

Type the root domain you want to find subdomains for — like example.com.

2

Start Search

Click Search to scan certificate transparency logs and other sources for subdomains.

3

View Subdomains

See all discovered subdomains with their status and IP addresses.

4

Export Results

Copy or download the subdomain list for further analysis.

About This Tool

Subdomains are like branches of a website — blog.example.com, api.example.com, staging.example.com, admin.example.com. Large organizations may have dozens or hundreds of subdomains, each potentially running different services. Our Subdomain Finder discovers all publicly visible subdomains of any domain using certificate transparency logs — the same technique used by security researchers worldwide.

What Are Subdomains?

A subdomain is a prefix added to a root domain. While example.com is the main domain, mail.example.com, shop.example.com and support.example.com are subdomains. Each subdomain can point to a completely different server running different software.

Subdomains serve different purposes: www for the main website, mail or webmail for email, api for API endpoints, blog or news for content sections, staging or dev for testing environments, admin for administrative interfaces, cdn for content delivery, m or mobile for mobile versions.

How Subdomain Discovery Works

Certificate Transparency (CT) logs are public records of all SSL/TLS certificates issued by certificate authorities. When an organization creates a new subdomain with HTTPS, a certificate is issued and recorded in public CT logs. Our tool queries these logs to find all certificates ever issued for a domain — revealing all subdomains that ever had SSL certificates.

This is public information — CT logs exist specifically to make certificate issuance transparent and prevent fraudulent certificates. No private data is accessed in subdomain discovery through CT logs.

Legitimate Uses

Security research: Organizations use subdomain enumeration as part of their own security audits — finding forgotten or exposed services before attackers do. Bug bounty programs: Security researchers participating in authorized bug bounty programs need subdomain lists to comprehensively test a target's attack surface. Competitive research: Understanding how a competitor organizes their web infrastructure (without unauthorized access). Website migration: When moving a large website, ensuring all subdomains are accounted for and migrated correctly.

Important Note

This tool finds publicly visible subdomains through legitimate data sources. It does not probe or attempt to access discovered subdomains. Using discovered subdomain information to attempt unauthorized access to systems is illegal and unethical. Use this tool responsibly and only for authorized security research or your own domains.

Why Use This Tool?

🔍

CT Log Search

Finds subdomains from certificate transparency logs.

Fast Discovery

Results appear quickly from public data sources.

📋

Complete List

All discovered subdomains with IP information.

🆓

Always Free

No account needed. Search unlimited domains free.

Related Tools

Frequently Asked Questions

Finding subdomains through certificate transparency logs queries public data — it is entirely legal. CT logs are public records by design. What you do with discovered information matters: unauthorized access to discovered systems is illegal. Use this tool for authorized research and your own domains.