Subdomain Finder & Recon Tool
Pricing
$1.00 / 1,000 domain scans
Subdomain Finder & Recon Tool
Discover subdomains for any target via passive OSINT sources. Ideal for security bug bounties and attack surface mapping.
Subdomain Finder & Recon Tool
Pricing
$1.00 / 1,000 domain scans
Discover subdomains for any target via passive OSINT sources. Ideal for security bug bounties and attack surface mapping.
Root domains to scan for subdomains (e.g. example.com). Each domain is checked against certificate transparency logs and optionally brute-forced via DNS.
[ "example.com"]Single domain to scan. Use the 'Domains' field above for bulk scanning — this field exists for backwards compatibility.
Query crt.sh certificate transparency logs to discover subdomains that appear in publicly issued TLS certificates.
Check a wordlist of common subdomain names (www, api, mail, staging, etc.) by resolving DNS. Enable alongside CT for broader coverage.
Custom wordlist for DNS brute-force discovery. Only used when DNS bruteforce is enabled. The default list covers common names like www, api, mail, staging, and admin.
[ "www", "mail", "api", "dev", "staging", "test", "blog", "app", "portal", "admin", "cdn", "static", "m", "beta"]Maximum time in seconds to wait for each DNS or crt.sh request to respond.