Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To find a website’s subdomains, combine several discovery sources—Certificate Transparency (CT), search engines, passive DNS, public DNS records, and authorized enumeration tools—then resolve each candidate with DNS. No public source guarantees a complete or current list: CT can contain historical names, passive databases have uneven coverage, and active guessing depends on its wordlist and resolver. Treat the result as a candidate inventory, not permission to test a host.

What counts as a subdomain?

A subdomain is a hostname beneath a registered domain. In blog.example.com, blog is the subdomain label and example.com is the parent domain. Organizations commonly use names such as www, api, mail, dev, staging, admin, and provider-specific hostnames.

The practical goal is usually to identify names that may belong in an organization’s asset inventory. Discovery does not prove that a hostname is live, owned by the organization, or in scope for a security assessment.

Why there is no guaranteed “all subdomains” list

DNS is distributed, and many names are never published in a directory. Different sources observe different portions of a domain at different times. A certificate may mention a hostname that was retired months ago; a passive-DNS service may have seen a record that no longer exists; a search engine may index a page without indexing its DNS history. Conversely, an internal or newly created name may appear in none of those sources.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use multiple sources, retain provenance and dates, and validate every candidate. The OWASP Web Security Testing Guide describes passive sources such as public DNS records, reverse DNS, search engines, passive DNS databases and Certificate Transparency logs, and distinguishes them from active techniques that query target DNS infrastructure.

Step 1: Start with passive discovery

Certificate Transparency logs

Public CT portals such as crt.sh let you search certificates containing a domain. Review exact names and wildcard entries. A certificate for *.example.com indicates that names under that wildcard could have been covered, but it does not reveal which names were actually deployed.

CT can expose development, staging, administrative and legacy names. It can also include certificates that have expired, been replaced or were issued for a service that is no longer connected to the domain. Record the certificate’s name and observation date, then perform DNS validation before treating it as a current asset.

Search engines and indexed references

Search the parent domain and likely hostname patterns. Queries such as site:example.com and site:*.example.com may surface indexed subdomains, documentation, status pages or links. Search results are incomplete and may reflect cached or historical pages, so use them as leads rather than proof of current DNS.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Passive DNS and public DNS information

Passive-DNS providers collect observations made by their sensors and resolvers. Coverage, retention and access differ by provider, and a record’s presence means only that it was observed in that dataset. Public DNS information, reverse-DNS data and other openly available records can add names missed by CT or search engines.

Collect evidence as you go

Keep a table with the candidate, source, first-seen or observation date when available, and notes. Normalize names to lowercase, remove a final dot (so API.Example.com. becomes api.example.com), and deduplicate before resolving.

Candidate Source Observed DNS status Scope/owner note
staging.example.com CT portal 2026-09-29 Not checked Confirm with domain owner
api.example.com Search result 2026-09-29 Not checked Record evidence URL internally

Step 2: Validate every candidate with DNS

Validation separates a name that appeared in a data source from one that currently returns DNS data. Check the candidate’s records and classify it as resolving, non-resolving or ambiguous. A resolving record still does not establish ownership or authorization.

Command-line checks

On systems with standard DNS utilities, query a specific record type:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
dig +noall +answer staging.example.com A
dig +noall +answer staging.example.com AAAA
dig +noall +answer staging.example.com CNAME
dig +noall +answer staging.example.com MX

On Windows, use:

nslookup staging.example.com

An A or AAAA response maps to an IP address. A CNAME points to another hostname and may reveal a hosted service dependency. An empty answer, NXDOMAIN, timeout or resolver error should be recorded precisely rather than collapsed into “does not exist.” Different resolvers can have different caches and visibility.

Resolve in a repeatable way

  1. Query the candidate through your organization’s approved resolver.
  2. Record the response type, returned values and UTC timestamp.
  3. Optionally repeat through a second approved resolver when results are ambiguous.
  4. Do not automatically follow an IP address with port scans, crawling or exploitation; obtain explicit authorization and confirm scope first.

Step 3: Use enumeration tools when authorized

Amass passive enumeration

OWASP identifies Amass and subfinder as subdomain-enumeration tools. Amass documents passive enumeration with:

amass enum --passive -d example.com

Passive mode aggregates configured data sources while reducing direct interaction with the target. Output depends on which sources are available and configured, so it is not an exhaustive guarantee. Check the installed version’s help and current project documentation before relying on additional flags.

Active enumeration and brute force

Active methods query the target’s DNS infrastructure or test guessed labels from a wordlist. They can find names absent from public datasets, but results depend on the resolver, wildcard DNS behavior, wordlist quality and rate limits. The OWASP guidance warns: “Active techniques directly query the target’s DNS infrastructure and may generate logs on the target systems.” Use active enumeration only when the written engagement permits it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Subfinder and similar tools

Subfinder is another tool listed by OWASP for discovering subdomains from passive sources. Its findings likewise depend on enabled providers and their current coverage. Export its output into the same normalized inventory, then resolve and review each name instead of treating tool output as a final list.

Compare discovery methods

Method Can reveal Main limitation Interaction
Certificate Transparency Names included in publicly logged certificates Historical, wildcard and certificate-only names may not be current DNS assets Passive; validate with DNS
Passive DNS and search Previously observed names and indexed references Coverage varies by source, time and domain Generally passive; retain provenance
Passive-mode tools Aggregated results from configured sources Provider access and configuration determine coverage Lower direct interaction
Active DNS or brute force Names found by queries or label guesses May generate logs; never guaranteed complete Use only within written scope

Step 4: Review ownership, scope and risk

For an assessment, mark whether the asset owner confirms each hostname is in scope. Discovery alone grants no permission to probe or exploit it. Keep evidence separate from conclusions: “seen in CT” is not the same as “active production host.”

Check for dangling DNS records

A record can continue pointing to a deprovisioned cloud or third-party resource. Such a dangling dependency can create subdomain-takeover risk. Domain administrators should compare the DNS record with the provider account and service inventory, remove stale records, and investigate unexpected CNAME targets through the responsible service owner. Do not attempt to claim or modify a third-party resource without explicit authorization.

Maintain the inventory

For each name, retain the hostname, source, observation date, DNS status, record values, owner, environment, and scope decision. Re-run passive collection and DNS validation on a schedule appropriate to the organization’s change rate. Retire entries only with an explanation, because a “non-resolving” result may be temporary.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshooting common results

A CT name does not resolve

That is expected for retired certificates, abandoned environments or names that were never deployed. Keep the evidence, label it non-resolving, and avoid presenting it as a live asset.

A wildcard makes every guessed name resolve

Some DNS configurations return the same address for arbitrary labels. Compare the answer with a deliberately random, authorized test label and document wildcard behavior. A positive response alone does not prove that the specific application exists.

Different resolvers disagree

Check TTLs, caching, DNSSEC-related errors, split-horizon DNS and resolver policy. Record which resolver produced each result and retry after the relevant TTL rather than choosing the answer that is most convenient.

The tool returns few or no names

Verify that passive data providers are configured and available, that the domain is entered correctly, and that the installed version’s syntax matches its documentation. Combine the tool with CT, search and passive-DNS sources; no single tool is exhaustive.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Active queries trigger alerts

Stop if the activity is outside the engagement plan. Coordinate with the system owner, document the approved source IP and rate, and use passive collection when active interaction is not authorized.

Or skip the browser setup

Subdomain discovery itself does not require screenshots, but if you need a visual record of a discovered web host, ScreenshotNeo can capture it with one request. Its cleanup step accepts cookie or consent banners and removes more than 60 known consent platforms, newsletter popups and chat widgets before the shot; each step can be disabled. Bot checks or CAPTCHAs, blank pages, timeouts, failed loads and cache hits are not billed, and the response identifies the result with X-Page-Verdict and X-Billed headers. It also provides an MCP server for AI agents with take_screenshot, get_page_info and capture_pdf.

See the ScreenshotNeo documentation for parameters. A direct call is:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://example.com -o shot.webp

The free plan includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000. Sign up for the free ScreenshotNeo plan.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Frequently asked questions

Can I find subdomains without permission?

Passive public-source research may be lawful in some contexts, but authorization requirements vary. Do not use discovery as a pretext for probing systems, and follow the domain owner’s policy and your engagement scope.

Does a certificate prove a subdomain is active?

No. It proves that a name appeared in a certificate record. DNS validation and owner confirmation are still required.

Should I publish the discovered names?

Usually not without the owner’s approval. Treat hostnames, record values and environment labels as operational information and protect the inventory accordingly.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.