Free Subdomain Finder

Enter any domain to list its subdomains — pulled from public certificate logs, with a live status for each. Instant, no signup.

Try:

How subdomains become discoverable

Whenever a website gets an SSL/TLS certificate from a public authority, that certificate is written to Certificate Transparency logs — an open, append-only record created so mis-issued certificates can be spotted. Each entry lists every hostname the certificate covers, so a certificate for api.example.com quietly announces that subdomain to anyone reading the logs.

This tool reads those logs for a domain, gathers the unique subdomain names, and then does an ordinary DNS lookup on each so you can see which are still live. It's completely passive — nothing is sent to the domain itself, and there's no scanning or brute-forcing involved.

Why it's worth knowing your subdomains

Most teams have more subdomains than they remember — old staging hosts, one-off tools, a service a former colleague set up. Each is a certificate that will eventually expire and a surface someone has to keep an eye on. Seeing the full list is the first step; being told when a new certificate appears is what keeps it from getting away from you. For the bigger picture — including the other ways to enumerate subdomains and what to do with the list — see our guide on how to find all subdomains of a domain.

That's what DomainChest does: add a domain once and it watches Certificate Transparency logs for new certificates on it and its subdomains — and tracks each certificate's expiry — then emails you before anything lapses or when something unexpected shows up.

Frequently asked questions

How does this subdomain finder work?

It queries public Certificate Transparency (CT) logs. Every publicly-trusted SSL/TLS certificate is recorded in these logs along with the hostnames it covers, so certificates issued for a domain's subdomains reveal those subdomains. We collect the unique names, then do a DNS lookup on each to show which ones currently resolve.

Is it free?

Yes — finding subdomains is completely free and needs no account. If you'd like to be alerted whenever a new certificate is issued for one of your subdomains, you can monitor a domain with a free DomainChest account.

Is this passive, or does it scan the domain?

It's fully passive. Nothing is sent to the target domain — the subdomains come from public certificate logs, and the only network activity is ordinary DNS resolution. There is no port scanning or brute-forcing.

Will it find every subdomain?

It finds every subdomain that has ever had a publicly-logged certificate, which covers most public HTTPS hosts. It won't find subdomains that have never been issued a public certificate — for example internal-only hosts, or those behind a wildcard certificate, which is why any wildcard names are listed separately.

Why do some subdomains show “No DNS”?

A certificate was issued for that hostname at some point, but it doesn't currently resolve to an IP address — the host may have been retired, moved, or never fully deployed. It's still useful to know these existed.

Why should I monitor my subdomains?

A certificate issued for a subdomain you didn't expect can be an early sign of a forgotten service or a misissued certificate. Watching CT logs means you learn about new certificates on your domains as they appear, rather than discovering them by accident.


Related tools: SSL Certificate Checker — check when a certificate expires — and WHOIS & DNS Lookupfor a domain's full record and live DNS.

Keep an eye on every subdomain's certificate

Store your domains in a chest, so you never forget one again.

Start free — 3 domains