Skip to content

Subdomain Finder

Discover the names behind a domain through the public certificate logs, without sending it a single packet.

A registrable domain. Certificate logs are indexed by name, not by address.

About Certificate Transparency

Since 2018, every certificate a browser trusts must be published to public, append-only Certificate Transparency logs, and the names it covers are published with it. Searching those logs lists the subdomains a domain has certified over the years without sending a single packet to the domain itself: no port scan, no dictionary of guessed names, nothing the target can see, block or log.

Read the list as a history, not as an inventory. A name appears because a certificate was issued for it, which proves it existed on the day of issue, not that it resolves today. Wildcards are counted separately for the same reason: a wildcard is a pattern, and it hides exactly what it is meant to hide. The dates carry the real information. A name whose newest certificate expired two years ago is probably a decommissioned service, while one renewed last month is live. Staging, preprod and admin hosts are the usual find, and they are usually the ones nobody meant to publish.

Frequently asked questions

Does this scan my domain?
No. Nothing is sent to your domain or your servers. The certificates are read from public logs that certificate authorities are required to publish, so the search is invisible to the target and leaves nothing in your access logs.
A name is listed but does not resolve. Why?
A certificate proves a name was certified, not that it is still in service. The host may have been retired or renamed, or it may only resolve on an internal resolver. Confirm with a DNS lookup before concluding anything.
Can I keep a subdomain out of these logs?
Not while it holds a publicly trusted certificate: publication is a condition of being trusted. A wildcard certificate covers the name without naming it, which is the usual answer, and a private certificate authority stays out of the logs entirely.
Why are two sources shown?
crt.sh holds the full history but is frequently unavailable. Certspotter is reliable but only exposes the most recent issuances to an anonymous caller. When the second answers instead of the first, the page says so rather than passing a partial list off as a complete one.

Related tools

Go further

Network glossary: Reverse DNS, Anycast

Run a visual traceroute to this host