Skip to content

Exposure and discovery

Subdomain finder

Find the subdomains of a domain by searching public certificate transparency logs for every unexpired certificate issued under it. The certificate transparency search is passive: it lists the names it finds and contacts none of them.

Checked from Ironfang Security's scanner address with the same low-impact limits as a scan. Nothing you enter is kept.

What this checks

What the result means

Publicly trusted certificates are recorded in certificate transparency logs (RFC 6962), which anyone can search. Each name you have put on a certificate, for a staging site, a mail server or a service since retired, is public, and attackers read the same logs to find hosts to try.

Read the list as an inventory check. Each name should be one you recognise and still use. A name you do not recognise may be a service someone set up without telling you. One you no longer use may still have a DNS record pointing at a host or platform you have given up, which the dangling DNS checker looks for.

crt.sh is often busy. When it does not answer, the result says the search could not be completed, which is not the same as finding no names; try again in a few minutes.

Cyber Essentials and ISO 27001

A list of names from certificate transparency logs is technical evidence for an asset inventory under ISO/IEC 27001:2022 Annex A 5.9 Inventory of information and other associated assets: a way to find internet-facing services the inventory missed.

Cyber Essentials applies to the internet-connected devices and services in scope, so forgotten hosts matter when the scope is drawn. The organisation still has to own the inventory, decide which names are in scope, and retire services and their DNS records when they are no longer needed.

Scope and limitations

Related guides

Questions

How does this subdomain finder work?
It searches certificate transparency logs, the public record of certificates issued by publicly trusted certificate authorities, for names under the domain. It does not guess names or query the domain's DNS.
Why is a subdomain I know about missing?
It has not appeared under its own name in an unexpired, publicly trusted certificate. It may be covered by a wildcard certificate, use a private certificate or none at all, or have only expired certificates.
Can I keep subdomains out of certificate transparency logs?
Not with a publicly trusted certificate for that name: browsers expect those to be logged. A wildcard certificate keeps individual names out of the logs, at the cost of one key covering every name beneath it.

Related security tools