Network

Subdomain Finder

The Subdomain Finder discovers subdomains by searching Certificate Transparency logs through crt.sh, returning a deduplicated, sorted list. Discovery is entirely passive — it reads public certificate records and sends no traffic to the target domain.

Last updated · Free, no signup

Loading interactive Subdomain Finder…

How does passive subdomain discovery work?

Passive subdomain discovery searches public Certificate Transparency records for hostnames that have appeared on certificates issued for a domain. It can reveal documented services, old environments, and naming patterns without probing each candidate host or connecting to the target infrastructure.

This page queries crt.sh, deduplicates the returned names, and caches results to protect the public service. Coverage is limited to names present in certificate logs: internal hosts, services without public certificates, and names excluded through certificate patterns may not appear. A discovered hostname is not proof that it remains live.