What the public logs publish
Hostnames collected passively from Certificate Transparency logs, without probing the target. Good for finding forgotten dashboards and old environments. Free, no signup, 5 checks a day.
5 free checks a day. No signup, no key.
Passive reading, not probing
Certificate Transparency
Every public certificate is logged, and those logs are the read-only source this check reads. Names are discovered passively — nothing probes the target, so nothing is hidden by a firewall or noticed in an access log.
Two sources, two kinds of evidence
Certificate logs name hosts that hold certificates; the host-search fallback reads an aggregated dataset instead. The sheet says which one answered, because they are not the same evidence.
The wildcard blind spot
A *.domain certificate publishes no hostnames at all. If the domain uses one, this check sees zero subdomains — that is a blind spot, not a clean finding, and it is labelled as such.
What it is not
These are the names the public internet has seen, not the full inventory. Anything internal, unlisted or never certificated simply does not appear.