Free Tool
4.9/5

Free Subdomain Finder

Discover all subdomains of any domain via Certificate Transparency logs. Auto-categorized (api, mail, dev, cdn, admin), CSV export, built for SEO + competitor audits.

Queries Certificate Transparency logs via crt.sh, typically returns in 1-5 seconds.

Track which subdomain links convert

Wrap subdomain CTAs in Flyn short links to see traffic, geo, and device breakdowns per subdomain, discover which infrastructure actually drives revenue.

Shorten for free

How to Find Subdomains in 3 Steps

Step 1: Enter a domain, Subdomain Finder screenshot
1

Enter a domain

Type the domain you want to scan (e.g., example.com, no http:// or www. needed). The tool queries Certificate Transparency logs server-side.

Step 2: Review categorized subdomains, Subdomain Finder screenshot
2

Review categorized subdomains

See every discovered subdomain auto-tagged by purpose (api, mail, dev, cdn, admin, content). Summary cards show total count, category breakdown, and most-common type at a glance.

Step 3: Filter, search, or export, Subdomain Finder screenshot
3

Filter, search, or export

Filter by category (e.g., find all dev/staging subdomains in one click), search by name, copy the full list, or export to CSV for spreadsheet analysis.

How Certificate Transparency Reveals Subdomains

Certificate Transparency (CT) is a Google-led standard that requires every SSL/TLS certificate issued by trusted Certificate Authorities (Let's Encrypt, DigiCert, Sectigo, GlobalSign, etc.) to be logged in public, append-only, tamper-proof logs. CT was created in 2013 to detect mis-issued certificates, situations where a CA accidentally or maliciously issues a certificate for a domain to the wrong party.

The side effect that makes CT useful for subdomain discovery: every subdomain that ever obtained a public HTTPS certificate becomes permanently visible in CT logs. Browsers refuse to trust certificates that aren't logged in CT, so any modern HTTPS subdomain shows up. There's no opt-out; CT logging is mandatory for trusted certificates since April 2018.

This tool queries crt.sh, a free public search interface to CT logs operated by Sectigo. We send a domain query, parse the certificate records, extract every subdomain hostname found in certificate Subject Alternative Names (SANs), deduplicate, and categorize. The whole process takes 1-5 seconds for typical domains.

CT discovers significantly more subdomains than DNS brute-forcing because it captures historical data, certificates issued years ago for subdomains that have since been decommissioned. This is invaluable for SEO audits (find forgotten subdomains hurting your domain authority), competitive intelligence (see all infrastructure a competitor has ever exposed), and security assessments (map the historical attack surface).

Subdomain Category Reference

The 12 categories this tool auto-classifies subdomains into, based on common naming conventions across the web.

CategoryWhat it meansCommon examples
mainMain / www subdomain, the canonical site rootwww.example.com, example.com
apiAPI endpoints, REST, GraphQL, or RPC backendsapi.example.com, gql.example.com, v2.api.example.com
appApplication interfaces, customer-facing web appsapp.example.com, dashboard.example.com
adminAdmin / management interfaces (often access-controlled)admin.example.com, manage.example.com, control.example.com
authAuthentication / SSO / login servicesauth.example.com, sso.example.com, login.example.com
emailMail servers and email-related infrastructuremail.example.com, smtp.example.com, mx.example.com
cdnContent delivery / static assets / mediacdn.example.com, static.example.com, assets.example.com
contentBlog, news, marketing contentblog.example.com, news.example.com, marketing.example.com
supportDocumentation, help center, knowledge basedocs.example.com, help.example.com, support.example.com
devDevelopment / staging / test environmentsdev.example.com, staging.example.com, beta.example.com, test.example.com
transferFile transfer protocolsftp.example.com, sftp.example.com
otherUncategorized, usually product names, regions, or campaign-specific subdomainsus.example.com, uk.example.com, project-x.example.com

Common Subdomain Audit Use Cases

Competitor infrastructure audit

Discover competitor product lines, regional sites, partner integrations, and internal tools, all from public CT data. No login or scraping required.

Find your own forgotten subdomains

Old marketing campaigns, abandoned A/B tests, retired internal tools, old subdomains accumulate forever in CT logs. Audit and clean up to consolidate domain authority.

Pre-acquisition due diligence

Before acquiring a company, audit their full subdomain footprint to spot hidden infrastructure, security risks, and brand sprawl that would carry over post-deal.

SEO sitemap completeness check

Compare CT-discovered subdomains against your XML sitemaps to ensure every active subdomain is properly indexed and optimized.

Phishing / lookalike domain monitoring

Discover sub-subdomains using your brand (paypal-secure-login.malicious.com pattern) by scanning suspicious parent domains.

Bug bounty / penetration testing scope

Map the attack surface of an authorized target. CT-based discovery is the gold standard for passive subdomain enumeration in security assessments.

Why Use Flyn's Subdomain Finder?

CT-based discovery

Queries Certificate Transparency logs, finds 99% of public-facing subdomains, including historical ones.

12-category auto-tagging

Every subdomain classified as api / mail / dev / cdn / admin / content / etc. for instant overview.

Stateless + private

Domain queries hit crt.sh directly, nothing is logged or persisted on our servers.

CSV export

Full audit data with category tags for spreadsheet analysis, client reports, or further tooling.

Frequently Asked Questions

What is a subdomain finder?

A subdomain finder is a tool that discovers all subdomains belonging to a domain. For example, given example.com, it finds api.example.com, mail.example.com, blog.example.com, dev.example.com, every named subdomain that has been used publicly. SEO teams use subdomain finders to audit competitor infrastructure, find their own forgotten subdomains, and discover content opportunities. Security teams use them to map attack surfaces.

How does this tool find subdomains?

We query Certificate Transparency (CT) logs via crt.sh. CT is a public, append-only log of every SSL/TLS certificate ever issued by trusted certificate authorities. When a site issues an HTTPS certificate for a subdomain (which every modern site does), that subdomain becomes publicly discoverable in CT logs forever. This method finds significantly more subdomains than DNS brute-forcing because it captures certificates issued years ago, even if the subdomain is no longer active.

What is Certificate Transparency and why does it expose subdomains?

Certificate Transparency (CT) is a Google-led standard that requires every SSL/TLS certificate issued by trusted CAs (Let's Encrypt, DigiCert, Sectigo, etc.) to be logged in public, tamper-proof logs. CT was created to detect mis-issued certificates. A side effect: every subdomain that ever obtained a certificate is permanently visible in CT logs. There's no way to opt out, if you want HTTPS, your subdomain shows up. This is why CT is the most reliable subdomain discovery method.

Does this tool find ALL subdomains of a domain?

Almost all that have used HTTPS publicly. CT logs cover every certificate issued by trusted CAs since 2018 (mandatory) and most before that. Subdomains that never obtained a public SSL cert (internal-only, IP-based, self-signed) won't appear. For internal subdomains, you'd need DNS brute-forcing or zone transfers. For 99% of public-facing subdomains, CT log scanning catches them.

Can I find subdomains of competitors' domains?

Yes, this is one of the highest-value use cases. Competitor subdomain audits reveal: hidden product lines (app.competitor.com), staging/dev environments accidentally exposed (staging.competitor.com), regional domains (uk.competitor.com), partner integrations (partners.competitor.com), and internal tools (admin.competitor.com). All public information from CT logs, no hacking, no privacy violations. Just public certificate data.

Why are subdomains important for SEO?

Subdomains are treated as separate sites by Google for ranking purposes, each accumulates its own link equity, page authority, and topical relevance. Multi-subdomain strategies can dilute your domain's overall authority (PageRank gets split). For SEO audits: identify orphan subdomains (no incoming links), redirect dead subdomains to consolidate authority, ensure each active subdomain has its own sitemap.xml and robots.txt. Subdomain hygiene is foundational technical SEO.

What's the difference between subdomains and subdirectories?

A subdomain (blog.example.com) is technically a separate hostname, treated by search engines as a distinct site. A subdirectory (example.com/blog) lives within the main domain and inherits its authority. Generally, subdirectories are better for SEO because all link equity consolidates under one domain. Use subdomains when content is genuinely separate (different language sites, internal apps, distinct products), not for blog/docs that should benefit from main domain authority.

Are subdomains visible to Google by default?

Yes, if Google can find them. Google discovers subdomains via: links from other indexed pages, sitemap submissions in Search Console, public DNS records (less reliable), and Certificate Transparency logs (Google operates several CT logs). To prevent indexing of a subdomain, use robots.txt or noindex meta tags. To verify what Google has indexed for a subdomain, use the site:subdomain.example.com search operator.

How do I find orphan or forgotten subdomains on my own site?

Run this tool against your domain. Compare the result against your active subdomain list. Anything in the CT-discovered list that you don't recognize is a forgotten subdomain, common sources: old marketing campaigns (campaign-2022.example.com), retired internal tools (legacy-admin.example.com), abandoned A/B tests (test1.example.com). Decide whether to: (1) reactivate if useful, (2) 301 redirect to the main site, or (3) take down the DNS record entirely to remove from CT.

Can hackers use subdomain finders for malicious purposes?

Yes, subdomain enumeration is a standard reconnaissance technique in penetration testing and bug bounties. Public subdomain data is available to attackers regardless of whether you use this tool. The defensive answer: assume your subdomains are discoverable, and harden each one. Audit publicly-exposed subdomains for forgotten dev/staging environments, default credentials, and outdated software. The same tool security pros use, defenders should use first.

Why does the tool sometimes show subdomains that don't exist anymore?

Certificate Transparency logs are append-only and historical, once a certificate is issued for a subdomain, it stays in CT logs forever, even after the subdomain is decommissioned. That's why you may see subdomains like old-2019-campaign.example.com that no longer resolve. This is actually useful: it shows the historical infrastructure of a domain, helping audit what was once exposed. To verify if a subdomain is currently active, do a DNS lookup or HTTP check after discovery.

Does this tool store the domains I check?

No. Domain queries are forwarded to the public Certificate Transparency database (crt.sh) and the result is returned to you, nothing is logged or persisted on our servers. The optional history feature uses your browser's localStorage only. Safe to audit competitor domains, client domains, or your own staging infrastructure without any data retention concerns.

Ready to level up your links?

Audit subdomain infrastructure, then track which subdomain CTAs actually convert with Flyn short links, turn discovery into measurable insight.