Subdomains

Public subdomains

Public hostnames found passively in Certificate Transparency data, without probing the target. Free, no signup, 5 checks a day.

Tip

You can open any section directly with a domain in the URL query string, then share that result page with someone else.

5 free checks a day. No signup, no key.

Examples
Notes

How to read this result

These notes explain what the check is showing, where the data comes from and what the main blind spots are.

01

Certificate Transparency

Every public certificate is logged, and those logs are the read-only source this check reads. Names are discovered passively — nothing probes the target, so nothing is hidden by a firewall or noticed in an access log.

02

Two sources, two kinds of evidence

Certificate logs name hosts that hold certificates; the host-search fallback reads an aggregated dataset instead. The sheet says which one answered, because they are not the same evidence.

03

The wildcard blind spot

A *.domain certificate publishes no hostnames at all. If the domain uses one, this check sees zero subdomains — that is a blind spot, not a clean finding, and it is labelled as such.

04

What it is not

These are the names the public internet has seen, not the full inventory. Anything internal, unlisted or never certificated simply does not appear.