Exposure and discovery
Subdomain finder
Find the subdomains of a domain by searching public certificate transparency logs for every unexpired certificate issued under it. The certificate transparency search is passive: it lists the names it finds and contacts none of them.
What this checks
- A search of crt.sh, a public certificate transparency search service, for unexpired certificates naming the domain or any name under it.
- Every name in those certificates that falls within the domain, up to 1,000.
- Wildcard entries such as
*.api.example.org, listed by the name they cover:api.example.org. - None of the names found is contacted. The search touches crt.sh, not your systems.
What the result means
Publicly trusted certificates are recorded in certificate transparency logs (RFC 6962), which anyone can search. Each name you have put on a certificate, for a staging site, a mail server or a service since retired, is public, and attackers read the same logs to find hosts to try.
Read the list as an inventory check. Each name should be one you recognise and still use. A name you do not recognise may be a service someone set up without telling you. One you no longer use may still have a DNS record pointing at a host or platform you have given up, which the dangling DNS checker looks for.
crt.sh is often busy. When it does not answer, the result says the search could not be completed, which is not the same as finding no names; try again in a few minutes.
Cyber Essentials and ISO 27001
A list of names from certificate transparency logs is technical evidence for an asset inventory under ISO/IEC 27001:2022 Annex A 5.9 Inventory of information and other associated assets: a way to find internet-facing services the inventory missed.
Cyber Essentials applies to the internet-connected devices and services in scope, so forgotten hosts matter when the scope is drawn. The organisation still has to own the inventory, decide which names are in scope, and retire services and their DNS records when they are no longer needed.
Scope and limitations
- It finds only names that have appeared in a publicly trusted certificate. It does not guess names, query DNS for them or read zone files.
- A wildcard certificate hides the individual names it covers; only the wildcard's base name is listed.
- Only unexpired certificates are searched, so names whose certificates have all expired are not shown. The list stops at 1,000 names.
- Results are reused for an hour, so a certificate issued in the last hour may not appear yet.
Related guides
Questions
- How does this subdomain finder work?
- It searches certificate transparency logs, the public record of certificates issued by publicly trusted certificate authorities, for names under the domain. It does not guess names or query the domain's DNS.
- Why is a subdomain I know about missing?
- It has not appeared under its own name in an unexpired, publicly trusted certificate. It may be covered by a wildcard certificate, use a private certificate or none at all, or have only expired certificates.
- Can I keep subdomains out of certificate transparency logs?
- Not with a publicly trusted certificate for that name: browsers expect those to be logged. A wildcard certificate keeps individual names out of the logs, at the cost of one key covering every name beneath it.
Related security tools
- Dangling DNS checker - Find a CNAME that points at a name that no longer exists.
- DNS checker - Look up a domain's A, AAAA, CNAME, MX, TXT, NS, SOA, CAA and DS records through public resolvers.
- Certificate checker - Read a site's TLS certificate: the names it covers, its issuer, validity and trust.
- Website security checker - Check a domain's DNS, email authentication, TLS, security headers and public technology in one pass.

