Subdomain Finder
Find subdomains from Certificate Transparency logs (crt.sh, certspotter) — every hostname a CA has ever issued a certificate for, deduplicated and sorted.
Enumerates subdomains from Certificate Transparency logs (crt.sh, certspotter) — every HTTPS cert ever issued publicly. Wildcard certs are expanded to the base name. Only reflects names a CA has issued a certificate for.
Enumerate a domain’s subdomains
Query Certificate Transparency logs for google.com and see every subdomain that has ever had an HTTPS certificate issued.
Requires completing the human-verification widget first. Results reflect names a CA has issued a certificate for.
FAQ
What are Certificate Transparency logs?
Public, append-only logs where Certificate Authorities submit every certificate they issue. Because they’re public, they reveal all the hostnames a private company has ever secured with HTTPS.
Why don’t I see every subdomain?
Only subdomains that have had an HTTPS certificate issued appear. Names served without TLS, or over wildcard certs (which are collapsed to the base name), won’t show.
Is it legal to enumerate subdomains?
This data is already public. Still, use it responsibly and only for assessment of domains you own or are authorized to test — it’s reconnaissance, not an attack.
Why does it need human verification?
Bulk CT queries against public logs could be abused for scraping, so a bot check (Cloudflare Turnstile) is required before each lookup.