About this tool
A subdomain finder that does one job, from public data, without asking you to sign up for anything.
What it does
Type a root domain, and this tool returns every subdomain of it that appears in public Certificate Transparency logs. Results are listed alphabetically, can be filtered, and can be copied to the clipboard. Subdomains whose names suggest a non-production or forgotten system are highlighted.
Where the data comes from
Results are read from crt.name, a public search interface over Certificate
Transparency logs. CT logs are append-only public records to which every domain name must be
submitted before a publicly trusted TLS certificate can be issued.
The tool performs no active scanning. It does not connect to the subdomains it lists, does not resolve their IP addresses, and does not probe for open ports or vulnerabilities. It reads a published dataset, in the same way a browser validates a certificate.
What we collect
Very little. Searches are cached so that repeated lookups are fast and so we do not exceed the upstream service's rate limit. See the privacy policy for specifics.
Why we built it
Most subdomain finders are either buried inside a larger security platform, gated behind a signup, or stripped down to a text box with no explanation of what the results mean. The interesting part of subdomain enumeration is not the list, it is knowing which entries on that list deserve attention. So this tool pairs the lookup with a glossary and a plain explanation of how the underlying data works.
Intended use
Auditing your own infrastructure, reviewing your organisation's attack surface, and authorised security testing. Reading public Certificate Transparency logs is not the same activity as attacking a system, but how you use the results matters, and the FAQ covers the legal questions in more detail.