Məzmuna keç
7/24 Təcili Cavab Xətti
az
Xidmətlər
Həllər
Tədqiqat
Şirkət
AlətlərTrust Center

Subdomain Finder

A forgotten test environment, an old admin panel or a retired campaign site are attackers' favorite targets. Knowing your subdomains is the first step in managing your attack surface.

Bu məzmun hazırda yalnız ingilis dilində təqdim olunur.

Queries are not stored. The tools use public information only; client-side tools never send your data anywhere.

What this tool checks

  • Subdomains found in Certificate Transparency logs
  • Common names verified over DNS (www, mail, api, vpn, dev …)
  • A or CNAME record of each subdomain
  • Records that still resolve and ones that no longer do

How to use it

  1. 01

    Enter your main domain (if you enter a subdomain, its parent domain is used).

  2. 02

    Press Find; CT logs can take a few seconds.

  3. 03

    Review and shut down subdomains you don't recognize or no longer use.

Technical details

Certificate transparency

Public certificate authorities must log every certificate they issue in public CT logs. So once you get a certificate for a subdomain, that name becomes permanently visible.

Subdomain takeover risk

Subdomains still pointing via CNAME to a deleted cloud resource (S3, Azure, Heroku…) can be claimed by someone else. Review the CNAME results with that in mind.

Coverage

Wildcard certificates (*.example.com) don't reveal individual subdomains. Brute-force name guessing is deliberately kept small in this tool.

Frequently asked questions

Will my internal server names show up?

Only if they received a public certificate or are listed in public DNS. Systems using an internal certificate authority won't appear.

The list shows subdomains we don't use — what now?

Delete the DNS record and shut down whatever it points to. Old records with CNAMEs to third-party services carry a takeover risk.

Can I stop this information from being visible?

CT logs are permanent. Using wildcard certificates or an internal CA for sensitive internal services reduces what is exposed.

Why are the results limited?

The table shows at most a few hundred subdomains and resolves DNS for the first entries. Full external attack surface analysis is part of our services.