Skip to main content
Network and domains tools

Network and domains / FREE TOOL

Subdomain finder

Find domain names recorded in public certificate transparency data, with source attribution and a dated lookup.

Passive public-data lookup

Start with a public domain

This lookup sends your domain to BreachLine and public certificate sources. It reads certificate records only. It does not probe hosts, check DNS, or confirm that names are active. Free requests share a limited allowance.

Certificate names

Follow the certificate trail.

Enter a domain to find names observed in public certificates. Results can include historical or inactive names and are not a complete asset inventory.

 

A QUICK WALKTHROUGH

How to use it

  1. 01Enter a public domain name without a URL path.
  2. 02Run the lookup to query public certificate records.
  3. 03Review the source, collection time and coverage limits before exporting names.

What this check can tell you

Queries public certificate records through BreachLine. Records can be historical, incomplete or unavailable; a listed name is not proof of a live host, current ownership or a vulnerability. No target scanning, DNS brute forcing or service probing is performed. Free shared usage limits apply.

The domain you submit is sent to BreachLine and a public certificate-data provider. No request is sent to the target host.

Certificate Transparency overview