Free tool · no signup

Find every subdomain attackers can see

Enumerate a domain's subdomains from ten passive OSINT sources — certificate logs, passive DNS and more — resolved live with CDN detection. The same engine that powers our paid audits, free to run.

Why subdomain enumeration is step one

Before an attacker touches your main site, they map everything attached to your domain. The homepage is usually hardened; the subdomains are where the soft targets live — a staging server someone spun up and forgot, an old admin panel, a marketing microsite on an unpatched CMS. Enumeration is free reconnaissance, and it is the first thing anyone serious does.

This tool shows you the same list they would build, so you can find the forgotten host before they do. It is entirely passive — nothing is sent to your servers — and it confirms which subdomains actually resolve rather than padding the count with dead records.

Common questions

How does this subdomain finder work?
It queries ten passive sources — certificate-transparency logs, passive DNS databases, urlscan, Wayback and more — merges the results, then resolves each candidate live to confirm which are actually up. It also filters out wildcard-DNS false positives, which is why the count is real rather than inflated.
Is finding subdomains legal?
Yes. Everything here comes from public sources — certificate logs are a public, append-only record by design, and passive DNS is aggregated from resolvers worldwide. Nothing in this tool sends traffic to the target domain; it reads what the internet already published.
Why do subdomains matter for security?
Every subdomain is a potential way in. The ones that get sites breached are usually the forgotten ones: a staging server with no authentication, an old admin panel, a dev environment pointing at production data. Attackers enumerate subdomains first for exactly this reason, so seeing your own list is the first step to defending it.
It found fewer subdomains than another tool. Why?
This tool only shows subdomains that resolve live right now, and it discards wildcard-DNS false positives. Tools that report a bigger number often count historical records that no longer exist or every label a catch-all DNS zone happily answers. A smaller list of real, reachable hosts is more useful than a long list of ghosts.
What is a CDN flag?
It means the subdomain resolves to a content-delivery network like Cloudflare or Fastly rather than directly to your own server. That is usually good — the CDN shields the origin — but a subdomain NOT behind the CDN may be exposing your real server IP.

Keep reading

See what attackers see — free

Run the free passive check on your domain. No login, no impact on your site, results in seconds.

Passive recon only. No login, and no impact on your site. Deeper testing needs domain verification.

Ready for the full manual audit? See transparent pricing →