Public subdomains
Public hostnames found passively in Certificate Transparency data, without probing the target. Free, no signup, 5 checks a day.
You can open any section directly with a domain in the URL query string, then share that result page with someone else.
How to read this result
These notes explain what the check is showing, where the data comes from and what the main blind spots are.
Certificate Transparency
Every public certificate is logged, and those logs are the read-only source this check reads. Names are discovered passively — nothing probes the target, so nothing is hidden by a firewall or noticed in an access log.
Two sources, two kinds of evidence
Certificate logs name hosts that hold certificates; the host-search fallback reads an aggregated dataset instead. The sheet says which one answered, because they are not the same evidence.
The wildcard blind spot
A *.domain certificate publishes no hostnames at all. If the domain uses one, this check sees zero subdomains — that is a blind spot, not a clean finding, and it is labelled as such.
What it is not
These are the names the public internet has seen, not the full inventory. Anything internal, unlisted or never certificated simply does not appear.