Sign up free

Subdomain Finder: Look Up a Domain's Subdomains

List the subdomains of a domain that appear in public certificate transparency logs.

About Subdomain Finder

A subdomain finder helps when you take over a website and need to know everything running under its domain, when you audit forgotten test and staging sites before they become a security risk, or when you research a competitor's product sites. Enter a domain and we search the public certificate transparency logs for certificates issued to it and its subdomains, using crt.sh, or Cert Spotter when crt.sh doesn't answer.

You get up to 3,000 subdomains, each with the date of its first certificate, when its latest one expires, the number of certificates, the issuer and whether a wildcard was used. The 60 with the newest certificates are resolved live, so you can see which still have an address and which no longer exist. Only names that have had a public HTTPS certificate appear. Nothing is brute-forced and the website itself is never contacted. Filter a long list, save it as CSV, and click a host to run a DNS Lookup or an IP to open its IP WHOIS record.

How to use Subdomain Finder

  1. 1
    Enter the domain

    Type the main domain, such as example.com. A subdomain you type is reduced to it.

  2. 2
    Click Find subdomains

    We search the certificate transparency logs, which can take up to half a minute for big domains.

  3. 3
    Review the list

    Narrow it down with the filter box and see which of the newest names still resolve.

  4. 4
    Save the results

    Copy the table, download it as CSV, or save the full result as JSON.

Why use Cubfile for this

  • Certificate transparency data

    Publicly trusted certificates are all logged, so names show up even when nothing links to them.

  • Up to 3,000 names

    Each with its first certificate date, latest expiry, certificate count, issuer and wildcard flag.

  • Newest 60 checked live

    See which recent subdomains still have an address and which no longer exist.

  • Passive only

    No brute-force guessing and no requests to the website itself.

FAQ

Subdomain Finder: questions and answers

How does the subdomain finder find subdomains?
It reads public certificate transparency logs, where every certificate from a public authority is recorded with the names it covers. It doesn't guess names or scan the server.
Why are some subdomains missing?
Only names that had a public HTTPS certificate appear. Internal names, sites without HTTPS and names covered only by a wildcard certificate such as *.example.com aren't listed one by one.
Does the subdomain finder send traffic to the website?
No. It reads the certificate logs and asks public DNS about the newest 60 names, so the website receives no requests from us.
What do the dates in the list mean?
First certificate is when the name first appeared in a certificate, and Expires is when its latest certificate runs out. A name whose certificate keeps being renewed is probably still in use. To check the certificate a subdomain serves right now, use the SSL Certificate Checker.
Is the subdomain finder free?
Yes. It needs no account and doesn't use your daily tasks, with an hourly allowance per visitor to prevent abuse. Results aren't stored.
Share Subdomain Finder with a friendIt runs in any browser, and they can try it without signing up.

Related tools

DNS DNS LookupLook up A, AAAA, CNAME, MX, NS, TXT, SOA, CAA and other DNS records.
WHOIS WHOIS LookupSee who registered a domain, when it was created and when it expires.
DNS DNS Propagation CheckerAsk a dozen public DNS resolvers at once to see whether a change has spread.
WHOIS Domain Availability CheckerCheck whether domains are still free to register, one or many at once.
DNS DNSSEC CheckerCheck whether a domain is signed with DNSSEC and validates correctly.
xnURL Punycode ConverterConvert Chinese and other international domain names to and from Punycode.
DNS Reverse DNS LookupFind the hostname behind an IP address from its PTR record.
SEO Broken Link CheckerCheck every link on a page and list the ones that are broken or redirected.