How does passive subdomain discovery work?
Passive subdomain discovery searches public Certificate Transparency records for hostnames that have appeared on certificates issued for a domain. It can reveal documented services, old environments, and naming patterns without probing each candidate host or connecting to the target infrastructure.
This page queries crt.sh, deduplicates the returned names, and caches results to protect the public service. Coverage is limited to names present in certificate logs: internal hosts, services without public certificates, and names excluded through certificate patterns may not appear. A discovered hostname is not proof that it remains live.