NewAI Visibility tracking is here.Try free
Free · No signup

Subdomain Checker.

Every subdomain. Every alias. Every forgotten dev server.

Type a root domain and we enumerate every public subdomain — passive DNS, certificate transparency logs, brute-force resolution, and live HTTP probing — surfacing the shadow infrastructure you forgot you had.

1,467 lookups today
Try:
Enter a root domain to enumerate its public subdomains.
Use cases

Bookmark-worthy moments.

Four moments when knowing every subdomain on a root matters more than knowing any single one.

Map your own attack surface

Find the dev subdomain that's been live for two years, the staging environment indexed in Google, the legacy *.api.* that nobody owns anymore. You can't secure what you can't see.

Audit a competitor's footprint

Their subdomain list reveals their tech stack, their geos, their product lines, their experiments. One query = a quiet, complete map.

Catch shadow IT and forgotten infra

Marketing's old campaign site. The sales team's legacy demo box. The acquisition you forgot to migrate. All of them respond to DNS. All of them are findable.

Pre-acquisition diligence

Before you buy a company, see every public-facing system they actually run. Subdomain enumeration in 30 seconds = the diligence checklist most acquirers skip.

Crash course

How subdomain enumeration actually works.

The four sources we cross-reference — and why no single one is enough on its own.

There's no master directory of subdomains. DNS is hierarchical but unenumerable from the outside — you can't ask example.com "list every subdomain you have." Finding them all requires combining four independent data sources, then deduping and live-validating what you find.

Passive DNS captures every subdomain anyone in the world has ever resolved. Certificate transparency logs capture every subdomain that's ever been issued an HTTPS certificate (which, since 2018, is essentially all of them). Brute-force wordlists catch the conventional ones — api, dev, staging, admin, mail — that everyone names the same way. Live HTTP probing then trims the list down to subdomains that are actually responding right now.

This tool runs all four passes in parallel and presents a deduplicated list with status codes, server headers, and tech-stack fingerprints alongside each result. What you see is not just "these names exist" but "these endpoints are live, serving this stack, returning this response code."

Enumeration sources · quick reference

Passive DNS

Crowd-sourced resolver logs — captures every name anyone has ever resolved.

~78% of typical results
CT logs

Certificate transparency — every TLS cert ever issued, publicly logged.

crt.sh + Google CT
Brute force

12K-word wordlist of conventional subdomain names, resolved in parallel.

api, dev, staging, m, ...
Live probe

HTTP HEAD on every candidate to confirm it's actually responding.

200, 301, 403, ...
Tech detect

Server header + JS fingerprinting on each live subdomain.

nginx / Cloudflare / Vercel
Wildcard handling

Detects and excludes wildcards (*.example.com → everything resolves) to avoid noise.

Wildcard detected · filtered
FAQ

Asked. Answered.

Tool questions, topic questions — straight answers. Anything missing? Email hi@seonova.io and we'll fold it in.

  • Querying public sources (passive DNS, CT logs) and probing public DNS is the same activity Google performs every day. Brute-force resolution of public names is also fine. Note: any further action against discovered hosts — port scanning, login attempts, exploitation — needs explicit authorization.

Go further

Watch your subdomain attack surface 24/7.

SEONova Pro re-enumerates every domain you own daily and alerts the moment a new subdomain appears — whether it's a marketing campaign, a forgotten dev box, or something you didn't authorize. The free tool finds them once. The platform watches forever.

14-day Pro trialNo credit cardCancel anytime