Public DNS Subdomain Discovery Scanner avatar

Public DNS Subdomain Discovery Scanner

Pricing

from $0.34 / 1,000 item processeds

Go to Apify Store
Public DNS Subdomain Discovery Scanner

Public DNS Subdomain Discovery Scanner

Discover certificate-observed subdomains of authorized root domains, check public DNS A/AAAA/CNAME records, and export hostnames with issuance provenance for asset inventories.

Pricing

from $0.34 / 1,000 item processeds

Rating

0.0

(0)

Developer

Automation Lab

Automation Lab

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

7 days ago

Last modified

Categories

Share

Find concrete public subdomains of authorized root domains from certificate-transparency issuances, then check their current A, AAAA and CNAME DNS records. This subdomain scanner produces one structured row per hostname, with certificate and lookup provenance for recurring asset inventories.

What does it do?

Supply one to ten root domains. The Actor reads recent public Cert Spotter issuance records, discards wildcard names (a wildcard is not evidence a particular hostname exists), deduplicates concrete child names, resolves DNS, and exports the default dataset. It does not brute-force names, probe websites, detect takeovers, or claim to enumerate every existing host.

Who is it for?

Security and IT teams can periodically snapshot certificate-observed assets they own. Domain administrators can review newly issued names and public resolution state. Analysts can join exported rows with their own authorized inventories.

Why use it?

Certificate evidence and current DNS evidence are separate: a name may occur on a certificate but no longer resolve. Each row retains issuance ID, issuer, validity dates and a provenance URL alongside DNS answers, rather than conflating historical visibility with live service availability. Wildcards and root-only names are excluded.

Getting started

  1. Enter root domains you own or are authorized to inventory, such as python.org for a public demonstration.
  2. Start with maxItems: 5 and maxPagesPerDomain: 1 to inspect a small sample.
  3. Run the Actor and open the Hostnames dataset view.
  4. Export JSON or CSV and compare subsequent scheduled run datasets in your own pipeline. The Actor does not calculate deltas or send alerts.

Input fields

FieldMeaningLimits
domainsPlain DNS root names, not URLs, wildcard names or IPs1–10
maxItemsMaximum distinct concrete child names in the entire run1–1,000; default 100
maxPagesPerDomainRecent issuance pages from Cert Spotter per root1–3; default 1
{"domains":["python.org"],"maxItems":5,"maxPagesPerDomain":1}

Output fields

The default dataset contains rootDomain, hostname, dnsStatus (resolved or no_records), aRecords, aaaaRecords, cnameRecords, certificateId, certificateNotBefore, certificateNotAfter, issuer, provenanceUrl, and checkedAt. DNS record arrays can be empty. Issuance validity and issuer may be null when absent upstream. An observed CNAME alone counts as resolved even if its ultimate destination is currently unavailable; this is a DNS record check, not a website availability test.

Example output

A local Python.org test observed www.python.org, status resolved, A and AAAA addresses, CNAME dualstack.python.map.fastly.net, certificate ID 13425610576, issuer GlobalSign, and the corresponding Cert Spotter issuance URL. Addresses and certificates can change between runs; do not treat the example as a fixed result.

How much does it cost to discover public subdomains?

The Actor uses a one-time start event and an item event only for emitted hostname rows. At the BRONZE spend tier, a run costs $0.01 to start and $0.00056 per emitted hostname. Five results cost an estimated $0.01280; 25 cost $0.02400; 100 cost $0.06600. FREE is $0.000644 per hostname; SILVER is $0.0004368; GOLD, PLATINUM and DIAMOND are $0.000336 each. Spend tiers depend on your monthly Apify Store spend, not the number of results in one run; check the live Apify pricing panel for your effective tier. An empty but successful query has no item charge, but the start event still applies. Platform usage and payout estimates may change with corrections, refunds, fraud, disputes, taxes and clawbacks.

Scope and coverage limits

This is CT-derived discovery, not a complete zone transfer, passive-DNS database, historical archive, DNS brute force or takeover audit. Cert Spotter's free endpoint is rate-limited and may return only recent issuances. maxPagesPerDomain caps history; maxItems caps output, with capacity reserved for each remaining root (a sparse root may leave the run below the cap). A certificate can name a hostname that no longer resolves, and one hostname can have several certificates; the first observed issuance is recorded. No wildcard expansion takes place. DNS checks use the run's public resolver and may differ from private split-horizon DNS.

Failure and retry behavior

A malformed root is rejected. Transient CT 429/5xx and network errors retry twice with bounded delays; persistent failures stop the run rather than silently returning an incomplete inventory. DNS resolver errors other than ordinary no-data/no-domain fail rather than being mislabeled no_records. For large or rate-limited domains, lower page count and schedule less frequently; repeated immediate reruns cannot bypass upstream quotas.

Integrations

Use an Apify schedule to refresh your authorized inventory. Export the default dataset to JSON/CSV, Google Sheets, a SIEM or an asset database. Compare hostname keyed rows across run datasets in your own automation to detect differences; this Actor emits snapshots, not change events. Pair it with Bulk DNS AAAA Record Checker when you already have explicit hostnames and only need IPv6 checks.

Run through the API

Use your own Apify token; do not put it in publicly shared Task inputs.

curl -X POST 'https://api.apify.com/v2/acts/automation-lab~public-dns-subdomain-discovery/runs?token=YOUR_TOKEN' \
-H 'Content-Type: application/json' \
-d '{"domains":["python.org"],"maxItems":5}'

The returned run's defaultDatasetId identifies the JSON/CSV output. For synchronous runs, use the Apify run-sync API only if the expected runtime fits your timeout.

import { ApifyClient } from 'apify-client';
const client = new ApifyClient({ token: process.env.APIFY_TOKEN });
const run = await client.actor('automation-lab/public-dns-subdomain-discovery').call({ domains: ['python.org'], maxItems: 5 });
const { items } = await client.dataset(run.defaultDatasetId).listItems();
console.log(items);
from apify_client import ApifyClient
import os
client = ApifyClient(os.environ['APIFY_TOKEN'])
run = client.actor('automation-lab/public-dns-subdomain-discovery').call(run_input={'domains': ['python.org'], 'maxItems': 5})
rows = client.dataset(run['defaultDatasetId']).list_items().items
print(rows)

MCP integration

Expose this Actor as a tool for an agent with the hosted Apify MCP server:

claude mcp add --transport http apify \
"https://mcp.apify.com?tools=automation-lab/public-dns-subdomain-discovery"

For Claude Desktop, Cursor, or VS Code, configure the hosted HTTP server in the client's MCP settings (use the client's current HTTP transport syntax):

{"mcpServers":{"apify":{"url":"https://mcp.apify.com?tools=automation-lab/public-dns-subdomain-discovery"}}}

Example prompts: “Scan certificate-observed subdomains of python.org, limit to five, and identify those with no public A/AAAA/CNAME records.” “Export the public DNS inventory for github.com with certificate issuance provenance.” Supply your own authorization for any domain you inventory; the Actor does not check ownership.

Data handling and support

No AI provider or model is used. The Actor sends each requested root to Cert Spotter's anonymous public API and each discovered child hostname to the run's DNS resolver. Cert Spotter may log root queries under its own policies; we cannot control that retention. No separate Actor-side cache, cookie store or account is kept. Inputs, output datasets and logs remain in Apify run storage under your account's configured retention; delete them from your Apify storage when no longer needed. For product or run problems, use the Actor's Apify Store issue channel with the run ID and sanitized input; never include tokens or confidential asset names in a public report.

Legality and responsible use

Only inventory domains you own or have explicit permission to assess. Public CT and DNS records can contain sensitive-looking names even when publicly disclosed; control exports, avoid attaching credentials, and respect upstream rate limits. This is observational metadata, not a vulnerability assessment or authorization to probe a host.

FAQ

Does no_records mean a service is offline? No. It only means no public A, AAAA or CNAME answer was returned by the resolver at check time. Other DNS types, private DNS and service health are outside scope.

Why are older hostnames missing? The API lists issuances by pages; increase maxPagesPerDomain up to three, but do not assume complete CT coverage.

Why did the Actor fail on an apparently valid domain? Enter a plain root without scheme/path/wildcard. CT API rate limits or DNS resolver transient errors are visible in the run log; wait for the source quota to recover instead of hammering it.

theHarvester Domain OSINT Collector serves broader authorized domain intelligence, while Bulk Domain Security Posture Checker audits security configuration of supplied domains. Neither is the same as this CT-derived child-hostname snapshot.