Subdomain Finder — Free Online Subdomain Discovery
A subdomain finder discovers hostnames beneath a root domain by querying certificate transparency logs, passive DNS and OSINT sources, and resolving DNS records — revealing external attack surface without active brute force when using passive enumeration methods.
Enter a root domain (e.g., example.com) and click Scan. ScanSuite queries crt.sh for certificate transparency entries, runs Subfinder passive enumeration, merges results, and resolves A, AAAA, and CNAME records. The free tier discovers up to 50 subdomains using passive sources only — no brute force, HTTP probing, or takeover detection.
Subdomain enumeration maps the hostnames associated with a root domain — revealing web applications, staging environments, mail servers, CDNs, and forgotten services that expand an organization's attack surface. Security teams, penetration testers, and asset owners use subdomain discovery to find shadow IT, validate DNS hygiene, and prioritize external exposure before adversaries do.
ScanSuite's free subdomain finder combines certificate transparency search (crt.sh), Subfinder passive source aggregation, and DNS resolution in a browser-based workflow. The free PUBLIC_FREE policy uses passive discovery only — no wordlist brute force, permutations, HTTP probing, or subdomain takeover checks. Premium ScanSuite unlocks active enumeration, live web service detection, port scanning on discovered hosts, takeover risk assessment, and continuous monitoring.
ScanSuite's free subdomain finder discovers hostnames via certificate transparency (crt.sh), Subfinder passive enumeration, and DNS resolution — up to 50 results with no signup. Premium unlocks brute force, permutations, HTTP probing, takeover detection, and continuous monitoring for comprehensive attack surface management.
Frequently Asked Questions
- What is an online subdomain finder?
- An online subdomain finder discovers hostnames beneath a root domain using certificate transparency logs, passive OSINT sources, and DNS resolution — accessible from a web browser without installing Subfinder, Amass, or other CLI tools. ScanSuite's free tier uses crt.sh for Certificate Transparency search, Subfinder for passive source aggregation, and DNS resolution for A, AAAA, and CNAME records. Results include discovered subdomain names, resolution status, IP addresses, and the sources that surfaced each hostname.
- How does the ScanSuite subdomain finder work?
- Enter a root domain and click Scan. ScanSuite validates the domain, queries crt.sh for TLS certificates listing subdomains in Subject Alternative Name fields, runs Subfinder to aggregate passive sources like DNS archives and search engines, merges and deduplicates findings, then resolves DNS records for each unique hostname. Discovery events stream to your browser in real time. The completed report shows discovered, resolved, and active HTTP counts with a detailed subdomain table and shareable 24-hour public URL.
- What is certificate transparency and crt.sh?
- Certificate Transparency (CT) is a public logging system where certificate authorities publish every TLS certificate they issue. The crt.sh service searches these logs, revealing subdomains listed in certificate SAN fields — often including staging, internal, and forgotten hostnames. CT search is passive: it queries public logs rather than sending traffic to the target's DNS or web servers. This makes crt.sh one of the most effective passive subdomain discovery sources available on ScanSuite's free tier.
- What is Subfinder and how is it used here?
- Subfinder is an open-source passive subdomain discovery tool that queries dozens of public sources including DNS history databases, search engines, threat intelligence feeds, and code repositories. On ScanSuite's free tier, Subfinder runs in passive mode only — aggregating publicly available subdomain hints without active wordlist brute forcing. Results merge with crt.sh findings and undergo DNS resolution to confirm which hostnames currently resolve.
- Does the free subdomain finder use brute force?
- No. The free PUBLIC_FREE policy explicitly disables brute force enumeration, permutations, HTTP probing, port scanning, and takeover detection. Free discovery relies exclusively on passive sources (crt.sh and Subfinder) plus DNS resolution. Brute force wordlist scanning and permutation engines are Premium features requiring an authenticated ScanSuite subscription.
- Does the free tool detect subdomain takeover?
- No. Subdomain takeover detection analyzes dangling CNAME records pointing to deprovisioned cloud resources (S3 buckets, Azure endpoints, GitHub Pages, etc.). This requires Premium ScanSuite. The free tier maps discovered hostnames and DNS records but does not assess takeover risk. For dedicated takeover scanning, see our Premium subdomain takeover tool at /scan/subdomain-takeover.