What this tool checks
- Subdomains found in Certificate Transparency logs
- Common names verified over DNS (www, mail, api, vpn, dev …)
- A or CNAME record of each subdomain
- Records that still resolve and ones that no longer do
How to use it
- 01
Enter your main domain (if you enter a subdomain, its parent domain is used).
- 02
Press Find; CT logs can take a few seconds.
- 03
Review and shut down subdomains you don't recognize or no longer use.
Technical details
Certificate transparency
Public certificate authorities must log every certificate they issue in public CT logs. So once you get a certificate for a subdomain, that name becomes permanently visible.
Subdomain takeover risk
Subdomains still pointing via CNAME to a deleted cloud resource (S3, Azure, Heroku…) can be claimed by someone else. Review the CNAME results with that in mind.
Coverage
Wildcard certificates (*.example.com) don't reveal individual subdomains. Brute-force name guessing is deliberately kept small in this tool.
Frequently asked questions
Will my internal server names show up?
Only if they received a public certificate or are listed in public DNS. Systems using an internal certificate authority won't appear.
The list shows subdomains we don't use — what now?
Delete the DNS record and shut down whatever it points to. Old records with CNAMEs to third-party services carry a takeover risk.
Can I stop this information from being visible?
CT logs are permanent. Using wildcard certificates or an internal CA for sensitive internal services reduces what is exposed.
Why are the results limited?
The table shows at most a few hundred subdomains and resolves DNS for the first entries. Full external attack surface analysis is part of our services.