§ Subdomains — discovery

What the public logs publish

Hostnames collected passively from Certificate Transparency logs, without probing the target. Good for finding forgotten dashboards and old environments. Free, no signup, 5 checks a day.

5 free checks a day. No signup, no key.

Try one:
§ Reference — what this check means

Passive reading, not probing

01

Certificate Transparency

Every public certificate is logged, and those logs are the read-only source this check reads. Names are discovered passively — nothing probes the target, so nothing is hidden by a firewall or noticed in an access log.

02

Two sources, two kinds of evidence

Certificate logs name hosts that hold certificates; the host-search fallback reads an aggregated dataset instead. The sheet says which one answered, because they are not the same evidence.

03

The wildcard blind spot

A *.domain certificate publishes no hostnames at all. If the domain uses one, this check sees zero subdomains — that is a blind spot, not a clean finding, and it is labelled as such.

04

What it is not

These are the names the public internet has seen, not the full inventory. Anything internal, unlisted or never certificated simply does not appear.