To find a website’s subdomains, combine several discovery sources—Certificate Transparency (CT), search engines, passive DNS, public DNS records, and authorized enumeration tools—then resolve each candidate with DNS. No public source guarantees a complete or current list: CT can contain historical names, passive databases have uneven coverage, and active guessing depends on its wordlist and resolver. Treat the result as a candidate inventory, not permission to test a host.
What counts as a subdomain?
A subdomain is a hostname beneath a registered domain. In blog.example.com, blog is the subdomain label and example.com is the parent domain. Organizations commonly use names such as www, api, mail, dev, staging, admin, and provider-specific hostnames.
The practical goal is usually to identify names that may belong in an organization’s asset inventory. Discovery does not prove that a hostname is live, owned by the organization, or in scope for a security assessment.
Why there is no guaranteed “all subdomains” list
DNS is distributed, and many names are never published in a directory. Different sources observe different portions of a domain at different times. A certificate may mention a hostname that was retired months ago; a passive-DNS service may have seen a record that no longer exists; a search engine may index a page without indexing its DNS history. Conversely, an internal or newly created name may appear in none of those sources.
#1 Best Overall
Use multiple sources, retain provenance and dates, and validate every candidate. The OWASP Web Security Testing Guide describes passive sources such as public DNS records, reverse DNS, search engines, passive DNS databases and Certificate Transparency logs, and distinguishes them from active techniques that query target DNS infrastructure.
Step 1: Start with passive discovery
Certificate Transparency logs
Public CT portals such as crt.sh let you search certificates containing a domain. Review exact names and wildcard entries. A certificate for *.example.com indicates that names under that wildcard could have been covered, but it does not reveal which names were actually deployed.
CT can expose development, staging, administrative and legacy names. It can also include certificates that have expired, been replaced or were issued for a service that is no longer connected to the domain. Record the certificate’s name and observation date, then perform DNS validation before treating it as a current asset.
Search engines and indexed references
Search the parent domain and likely hostname patterns. Queries such as site:example.com and site:*.example.com may surface indexed subdomains, documentation, status pages or links. Search results are incomplete and may reflect cached or historical pages, so use them as leads rather than proof of current DNS.
Passive DNS and public DNS information
Passive-DNS providers collect observations made by their sensors and resolvers. Coverage, retention and access differ by provider, and a record’s presence means only that it was observed in that dataset. Public DNS information, reverse-DNS data and other openly available records can add names missed by CT or search engines.
Collect evidence as you go
Keep a table with the candidate, source, first-seen or observation date when available, and notes. Normalize names to lowercase, remove a final dot (so API.Example.com. becomes api.example.com), and deduplicate before resolving.
| Candidate | Source | Observed | DNS status | Scope/owner note |
|---|---|---|---|---|
| staging.example.com | CT portal | 2026-09-29 | Not checked | Confirm with domain owner |
| api.example.com | Search result | 2026-09-29 | Not checked | Record evidence URL internally |
Step 2: Validate every candidate with DNS
Validation separates a name that appeared in a data source from one that currently returns DNS data. Check the candidate’s records and classify it as resolving, non-resolving or ambiguous. A resolving record still does not establish ownership or authorization.
Command-line checks
On systems with standard DNS utilities, query a specific record type:
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →dig +noall +answer staging.example.com A
dig +noall +answer staging.example.com AAAA
dig +noall +answer staging.example.com CNAME
dig +noall +answer staging.example.com MX
On Windows, use:
nslookup staging.example.com
An A or AAAA response maps to an IP address. A CNAME points to another hostname and may reveal a hosted service dependency. An empty answer, NXDOMAIN, timeout or resolver error should be recorded precisely rather than collapsed into “does not exist.” Different resolvers can have different caches and visibility.
Resolve in a repeatable way
- Query the candidate through your organization’s approved resolver.
- Record the response type, returned values and UTC timestamp.
- Optionally repeat through a second approved resolver when results are ambiguous.
- Do not automatically follow an IP address with port scans, crawling or exploitation; obtain explicit authorization and confirm scope first.
Step 3: Use enumeration tools when authorized
Amass passive enumeration
OWASP identifies Amass and subfinder as subdomain-enumeration tools. Amass documents passive enumeration with:
amass enum --passive -d example.com
Passive mode aggregates configured data sources while reducing direct interaction with the target. Output depends on which sources are available and configured, so it is not an exhaustive guarantee. Check the installed version’s help and current project documentation before relying on additional flags.
Active enumeration and brute force
Active methods query the target’s DNS infrastructure or test guessed labels from a wordlist. They can find names absent from public datasets, but results depend on the resolver, wildcard DNS behavior, wordlist quality and rate limits. The OWASP guidance warns: “Active techniques directly query the target’s DNS infrastructure and may generate logs on the target systems.” Use active enumeration only when the written engagement permits it.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallSubfinder and similar tools
Subfinder is another tool listed by OWASP for discovering subdomains from passive sources. Its findings likewise depend on enabled providers and their current coverage. Export its output into the same normalized inventory, then resolve and review each name instead of treating tool output as a final list.
Compare discovery methods
| Method | Can reveal | Main limitation | Interaction |
|---|---|---|---|
| Certificate Transparency | Names included in publicly logged certificates | Historical, wildcard and certificate-only names may not be current DNS assets | Passive; validate with DNS |
| Passive DNS and search | Previously observed names and indexed references | Coverage varies by source, time and domain | Generally passive; retain provenance |
| Passive-mode tools | Aggregated results from configured sources | Provider access and configuration determine coverage | Lower direct interaction |
| Active DNS or brute force | Names found by queries or label guesses | May generate logs; never guaranteed complete | Use only within written scope |
Step 4: Review ownership, scope and risk
For an assessment, mark whether the asset owner confirms each hostname is in scope. Discovery alone grants no permission to probe or exploit it. Keep evidence separate from conclusions: “seen in CT” is not the same as “active production host.”
Check for dangling DNS records
A record can continue pointing to a deprovisioned cloud or third-party resource. Such a dangling dependency can create subdomain-takeover risk. Domain administrators should compare the DNS record with the provider account and service inventory, remove stale records, and investigate unexpected CNAME targets through the responsible service owner. Do not attempt to claim or modify a third-party resource without explicit authorization.
Rank #4
Maintain the inventory
For each name, retain the hostname, source, observation date, DNS status, record values, owner, environment, and scope decision. Re-run passive collection and DNS validation on a schedule appropriate to the organization’s change rate. Retire entries only with an explanation, because a “non-resolving” result may be temporary.
Recommended Free Tools
Troubleshooting common results
A CT name does not resolve
That is expected for retired certificates, abandoned environments or names that were never deployed. Keep the evidence, label it non-resolving, and avoid presenting it as a live asset.
A wildcard makes every guessed name resolve
Some DNS configurations return the same address for arbitrary labels. Compare the answer with a deliberately random, authorized test label and document wildcard behavior. A positive response alone does not prove that the specific application exists.
Different resolvers disagree
Check TTLs, caching, DNSSEC-related errors, split-horizon DNS and resolver policy. Record which resolver produced each result and retry after the relevant TTL rather than choosing the answer that is most convenient.
The tool returns few or no names
Verify that passive data providers are configured and available, that the domain is entered correctly, and that the installed version’s syntax matches its documentation. Combine the tool with CT, search and passive-DNS sources; no single tool is exhaustive.
Free tools Windows power users keep installed
One-click scans. No signup required.
Best Value
- Used Book in Good Condition
Active queries trigger alerts
Stop if the activity is outside the engagement plan. Coordinate with the system owner, document the approved source IP and rate, and use passive collection when active interaction is not authorized.
Or skip the browser setup
Subdomain discovery itself does not require screenshots, but if you need a visual record of a discovered web host, ScreenshotNeo can capture it with one request. Its cleanup step accepts cookie or consent banners and removes more than 60 known consent platforms, newsletter popups and chat widgets before the shot; each step can be disabled. Bot checks or CAPTCHAs, blank pages, timeouts, failed loads and cache hits are not billed, and the response identifies the result with X-Page-Verdict and X-Billed headers. It also provides an MCP server for AI agents with take_screenshot, get_page_info and capture_pdf.
See the ScreenshotNeo documentation for parameters. A direct call is:
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://example.com -o shot.webp
The free plan includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000. Sign up for the free ScreenshotNeo plan.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Frequently asked questions
Can I find subdomains without permission?
Passive public-source research may be lawful in some contexts, but authorization requirements vary. Do not use discovery as a pretext for probing systems, and follow the domain owner’s policy and your engagement scope.
Does a certificate prove a subdomain is active?
No. It proves that a name appeared in a certificate record. DNS validation and owner confirmation are still required.
Should I publish the discovered names?
Usually not without the owner’s approval. Treat hostnames, record values and environment labels as operational information and protect the inventory accordingly.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

