About Subdomain Finder
A subdomain finder helps when you take over a website and need to know everything running under its domain, when you audit forgotten test and staging sites before they become a security risk, or when you research a competitor's product sites. Enter a domain and we search the public certificate transparency logs for certificates issued to it and its subdomains, using crt.sh, or Cert Spotter when crt.sh doesn't answer.
You get up to 3,000 subdomains, each with the date of its first certificate, when its latest one expires, the number of certificates, the issuer and whether a wildcard was used. The 60 with the newest certificates are resolved live, so you can see which still have an address and which no longer exist. Only names that have had a public HTTPS certificate appear. Nothing is brute-forced and the website itself is never contacted. Filter a long list, save it as CSV, and click a host to run a DNS Lookup or an IP to open its IP WHOIS record.
How to use Subdomain Finder
- 1Enter the domain
Type the main domain, such as example.com. A subdomain you type is reduced to it.
- 2Click Find subdomains
We search the certificate transparency logs, which can take up to half a minute for big domains.
- 3Review the list
Narrow it down with the filter box and see which of the newest names still resolve.
- 4Save the results
Copy the table, download it as CSV, or save the full result as JSON.
Why use Cubfile for this
- Certificate transparency data
Publicly trusted certificates are all logged, so names show up even when nothing links to them.
- Up to 3,000 names
Each with its first certificate date, latest expiry, certificate count, issuer and wildcard flag.
- Newest 60 checked live
See which recent subdomains still have an address and which no longer exist.
- Passive only
No brute-force guessing and no requests to the website itself.