October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run ScanOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
Certificate Transparency

How to Find Subdomains of a Domain: A Practical, Authorized Workflow

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To find subdomains reliably, combine several sources rather than trusting one tool: search Certificate Transparency logs and public indexes, enumerate permitted DNS candidates, then resolve, normalize and validate every result. A certificate entry or dataset record is only a clue; it does not prove that a hostname is live, owned by the organization or in scope for testing.

This workflow is intended for domains you own or are explicitly authorized to assess. Record the exact domain, allowed techniques and query limits before you begin. OWASP treats subdomain discovery as attack-surface identification and recommends validating and documenting assets before further testing.

1. Define scope before discovering anything

Write down the registrable domain (for example, example.com), any approved subsidiaries or external services, and the activities allowed by the engagement. Discovery can create traffic to systems that were not intended to be tested, so confirm whether passive collection, DNS queries, wordlists, permutation attempts and takeover checks are permitted.

  • Keep the target domain and approved name patterns in a scope file.
  • Set resolver, rate and concurrency limits supplied by the owner or engagement rules.
  • Store the source and validation status for every hostname.
  • Do not treat a discovered name as permission to log in, scan ports or exploit a service.

OWASP’s Attack Surface Identification guidance says discovered assets should be validated and documented before further testing.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

2. Start with passive Certificate Transparency research

Certificate Transparency (CT) logs record publicly issued TLS certificates. Searching them is a fast, low-impact way to find names such as api.example.com, staging.example.com or older regional hosts that are not obvious from the main website.

Using crt.sh

  1. Open crt.sh.
  2. Search for %.example.com (replace the domain).
  3. Export or copy every DNS name, including wildcard names.
  4. Keep the certificate date and issuer where available; they help identify historical entries.

OWASP also names Merklemap and SSLMate’s Cert Spotter as CT portals. CT coverage depends on certificate issuance and the availability of the log search service; OWASP notes that crt.sh can experience downtime or high latency.

CT results are historical evidence, not live DNS answers. A certificate may have expired, been replaced, or covered a name that never served a public application. The OWASP guide states: “Information gathered from CT logs should be validated to confirm ownership and relevance before further testing activities.”

3. Add search engines and public indexes

Search engines can reveal hostnames in indexed pages, documentation, JavaScript, error messages and links. Try queries such as:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • site:example.com
  • site:*.example.com (support varies by engine)
  • "subdomain.example.com" for a specific candidate
  • site:example.com -www to reduce results for the main host

Public asset indexes and internet search engines can supply additional passive clues. Their records may be stale, incomplete or subject to access limits, so preserve the service name and retrieval date with each result. Reverse-IP data can also show co-hosted names, but shared hosting means a result may belong to another customer; ownership must be confirmed.

4. Enumerate DNS candidates when active queries are allowed

Passive sources cannot expose every name. For an authorized assessment, use established tools and a carefully chosen wordlist or permutation set.

Amass and subfinder

OWASP’s tool list includes Amass and subfinder for subdomain discovery. Run them only against approved domains and respect provider, resolver and engagement limits. Different tools use different passive providers and DNS strategies, so their outputs will overlap but are not identical.

DNS resolvers and high-volume helpers

Use dig, host or nslookup for direct checks. OWASP also lists dnsx, MassDNS, dnsrecon and related utilities. High-volume tools can produce false positives under wildcard DNS or resolver failure, so speed is not a substitute for validation.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Wordlists and permutations

Test names likely for the organization, such as dev, staging, vpn, mail, portal and regional labels, plus combinations like dev-api or us-east. Keep the list proportional to the scope. A wordlist can miss an unusual name, while an enormous list can create unnecessary traffic and hit DNS limits.

5. Normalize, deduplicate and resolve every candidate

Merge CT, search, index and enumeration output before deciding what is real.

  1. Convert names to a consistent case and remove a final dot (for example, normalize API.Example.com. to api.example.com).
  2. Remove names outside the authorized parent domain.
  3. Deduplicate while retaining all source references.
  4. Resolve each candidate with an approved resolver.
  5. Record A, AAAA, CNAME, NS and MX answers, response codes and the time checked.
  6. Check the resulting IP or provider relationship before labeling the asset as owned and relevant.

A name found in CT or a dataset can be stale, wildcard-related or otherwise unconfirmed. DNS resolution is a separate validation step; a successful answer still does not prove that the organization controls the service behind it.

Simple command-line validation

For one candidate, these commands show current DNS answers without performing application testing:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
dig +noall +answer api.example.com A AAAA CNAME
host -t CNAME api.example.com
nslookup -type=NS example.com

For a file called candidates.txt, resolve names one at a time and save the output:

while read -r name; do
  printf '%st' "$name"
  dig +short "$name" A "$name" AAAA "$name" CNAME | tr 'n' ' '
  printf 'n'
done < candidates.txt > resolved.tsv

Wildcard DNS can make every guessed name appear to resolve. Compare a random, clearly nonexistent label with your candidates; identical answers indicate that you must detect and filter the wildcard before counting a result as meaningful.

6. Keep an evidence and ownership record

A useful inventory distinguishes what was observed from what was verified. Suggested columns are:

Rank #4
RJ45 Crimp Tool Kit for Cat5 Cat5e Cat6, Ethernet Crimpeing Tool Kit
  • What You Get: 148-in-1 Network Tool Kit for Cat5/Cat5e/Cat6. Includes 1PCS ethernet crimper,1PCS rj45 cable tester,1PCS mini wire stripper,1PCS flatscrewdriver, 1PCS cross screwdriver, 1PCS wire cutter plier, 1PCS punch-down tool,100PCS cable zip ties, 20 cat5 connectors,20 relief boots and 1PCS rj45 tool bag—everything needed for convenient work
  • Attention Please: The rj45 connectors within rj45 crimp tool kit are regular connectors, not pass through connectors
  • Why Choose Us: Fast, reliable ethernet crimp tool with steel body construction for durability with ergonomic comfort grips. Ratchet safety-release and a blade-guard on cutting and stripping knives reduce risk of injury
  • Improve Work Efficiency: Professional Network Ethernet Crimper, Save Time and Effort. 3-in-1 ethernet crimping/cutting/stripping tool, which is good for rj45, rj11, rj12 connectors, and suitable for 6 and 8 position modular plugs/connectors
  • Professional Network Cable Tester: Tests double-twisted cables 1-8, detecting wrong connections, short circuits, and open circuits. Compatible with RJ45, RJ11, Cat5, Cat5e and Cat6 ethernet Cable. Powered by a 9V battery (not included)
Field What to record
Hostname Normalized fully qualified name
Source CT portal, search result, tool, wordlist or dataset
First/last seen Dates supplied by the source or your checks
DNS status Resolves, NXDOMAIN, timeout or wildcard
Records A, AAAA, CNAME, NS and MX values as applicable
Ownership and relevance Confirmed, plausible or unconfirmed, with the reason
Scope status In scope, excluded or awaiting owner confirmation

This prevents a historical certificate name from being presented as a current asset and makes later remediation or retesting reproducible.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

7. If your goal is subdomain-takeover detection

Takeover work requires more than finding a dangling-looking record. OWASP’s Subdomain Takeover guidance describes three stages: enumerate, fingerprint likely services and manually validate.

  1. Resolve candidates and filter for CNAME, NS or MX records that point to third-party infrastructure.
  2. Compare the target with the provider’s documented unclaimed-resource behavior or a known service fingerprint.
  3. Manually verify that the resource is actually unclaimed and that the organization owns the parent name.
  4. Report the evidence and avoid registering, claiming or modifying the resource unless the written engagement explicitly authorizes that action.

A dangling CNAME or automated fingerprint is a lead, not a confirmed vulnerability. False positives occur when a provider returns a generic error, when an account is private, or when DNS and application state are out of sync.

8. Choosing methods and understanding coverage

Method Can surface Main limitation Best use
CT search Names in publicly logged certificates, including historical hosts Not proof of current DNS; depends on issuance and search availability Fast passive starting point
Search engines Indexed pages and references Incomplete and stale indexing Supplementing passive sources
Wordlist/permutation DNS Guessed names that answer currently Candidate quality, wildcard handling and query limits Authorized active discovery
Passive DNS and asset indexes Names collected from underlying datasets Coverage, freshness, access and API limits vary Additional clues
Manual DNS lookup Current records for a known candidate Does not discover unknown names Validation and triage

No cited technique guarantees a complete, current inventory. Describe your results as the output of the sources and time window you used, not as every subdomain that exists.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

9. Troubleshooting common discovery problems

“crt.sh returns nothing or is slow”

Retry later, use another CT portal named by OWASP, and continue with search engines and approved DNS methods. A portal outage is not evidence that the domain has no certificates.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

“The candidate resolves, but the site is blank”

Separate DNS proof from application availability. Record the DNS answer, then check ownership with the asset owner. Do not classify a blank response as a takeover without manual provider-specific validation.

“Thousands of random names resolve”

Test for wildcard DNS, compare answers for a random label, and filter identical wildcard responses. Reduce concurrency and confirm resolver behavior.

“Different tools disagree”

Compare their data sources, timestamps, wildcard handling and resolver settings. Preserve both outputs, then resolve the disputed names yourself.

“A name points to a cloud or SaaS provider”

That is a relationship to investigate, not proof of ownership or vulnerability. Confirm the business owner, service account and intended scope before any further action.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Or skip the browser setup

If you need screenshots of discovered hosts for an inventory record, ScreenshotNeo provides a website screenshot API and MCP server. It accepts cookie and consent banners before capture and removes more than 60 known consent platforms, newsletter popups and chat widgets; bot checks, blank pages, timeouts, failed loads and cache hits are not billed, with the result identified by X-Page-Verdict and X-Billed headers. Its MCP tools let Claude, Cursor and other MCP clients call take_screenshot, get_page_info and capture_pdf.

One request returns an image or PDF:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://example.com -o shot.webp

Python:

import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://example.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)

Node.js:

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://example.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

See the ScreenshotNeo documentation for the 63 capture options, including full-page lazy-image loading, CSS selectors, device presets, dark mode, PDFs, custom CSS and JavaScript, clicks, waits, blocked resources, headers, cookies, geolocation, resizing, caching, signed links, webhooks, bulk capture and usage reporting. The Free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000. Create a free ScreenshotNeo account.

Frequently Asked Questions

Can I find every subdomain with one command?

No. Sources have different coverage and freshness, and no cited technique guarantees a complete current list. Combine passive clues, permitted DNS enumeration and validation.

Does a CT hostname prove that a service is live?

No. It proves that the name appeared in certificate history. Resolve it and confirm ownership and relevance separately.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Is a dangling CNAME automatically a subdomain takeover?

No. It is a lead requiring provider-specific fingerprinting and manual confirmation.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.