Subdomain Finder — SSL Certificate Transparency Lookup
Pricing
from $1.00 / 1,000 domain checkeds
Subdomain Finder — SSL Certificate Transparency Lookup
Find the subdomains and SSL/TLS certificates of any domain from public Certificate Transparency logs (crt.sh). Issuer, validity dates, active certificates, and a clean subdomain list. For asset inventory and authorized security reviews.
Pricing
from $1.00 / 1,000 domain checkeds
Rating
0.0
(0)
Developer
KeyMan98
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
3 days ago
Last modified
Categories
Share
Find every subdomain and SSL/TLS certificate publicly logged for a domain, through crt.sh (run by Sectigo) — the standard public search over Certificate Transparency logs. No API key, no HTML scraping, no login.
Every publicly trusted SSL/TLS certificate issued since ~2018 is logged, permanently and publicly, in Certificate Transparency (CT) logs — that's a browser requirement, not something a site can opt out of. crt.sh indexes those logs and makes them searchable by domain. This Actor turns that search into structured rows: every subdomain that ever had a public certificate, and every certificate itself (issuer, validity dates, serial number).
What you get (output fields)
For each domain, one dataset row with:
domain— the domain as given (or the host extracted from a pasted URL), lowercased.subdomains— unique, sorted list of every subdomain found (a wildcard entry like*.example.comis included as-is). Omitted (null) when "Include the subdomains list" is off.subdomainCount— how many, even when the list itself is left out.certificates— up to "Max certificates per domain" certificates, most recent first. Each one:id(crt.sh's own ID),issuerName,commonName,nameValue(every name on the certificate, as a list),notBefore,notAfter,entryTimestamp,serialNumber,crtShUrl(link to crt.sh's own page for that certificate).certificateCount— how many certificates are incertificates(after the cap).0means crt.sh has no certificate on record for this domain.activeCertificateCount— of those, how many are currently within their validity period.source— always"crt.sh"on a successful row.crtShSearchUrl— the public crt.sh search page for this domain, to double-check the answer yourself.error— set only when a row was never checked (invalid domain, duplicate, or crt.sh unreachable); every other field is null on those rows.
Who it's for
- Security teams and pentesters, on domains they're authorized to test — subdomain discovery is a standard first step in an authorized security review.
- Asset inventory — find forgotten subdomains (staging, old marketing sites, internal tools) that still have public certificates.
- Monitoring — run on a schedule with "Only certificates issued since" set to catch new subdomains or unexpected certificates as soon as they're logged.
- Certificate/SSL expiry tracking —
notAfteron every certificate found.
How to use
- Domains — one or more, e.g.
example.com. A pasted URL (https://www.example.com/path) works too — just the host is used, the rest is dropped. - Include expired certificates — off by default (current certificates only, and a much smaller, faster response). Turn on for the full history.
- Include the subdomains list — on by default. Turn off if you only need the count.
- Max certificates per domain — default 200. Raise it for a domain with a long certificate history; lower it to keep rows small.
- Only certificates issued since (optional) —
YYYY-MM-DD, for monitoring: only certificates first valid on or after this date are counted. - Run the Actor. Each domain becomes one row.
Input example (JSON)
{"domains": ["example.com"],"includeExpired": false,"includeSubdomainsList": true,"maxCertificatesPerDomain": 200}
Output example (JSON, shortened)
{"domain": "example.com","subdomains": ["*.example.com", "www.example.com"],"subdomainCount": 2,"certificates": [{"id": 29557945233,"issuerName": "C=GB, O=Sectigo Limited, CN=Sectigo Public Server Authentication CA DV E36","commonName": "example.com","nameValue": ["*.example.com", "example.com"],"notBefore": "2026-09-24T00:00:00","notAfter": "2026-12-21T09:32:54","entryTimestamp": null,"serialNumber": "2caeeaf0743459d7e5f82a75123c58f3","crtShUrl": "https://crt.sh/?id=29557945233"}],"certificateCount": 10,"activeCertificateCount": 10,"source": "crt.sh","crtShSearchUrl": "https://crt.sh/?q=example.com","error": null}
If a domain can't be checked
Every domain gets exactly one row, and the run never fails because of one bad domain:
- Locally invalid (not a valid hostname, or an IP address) — rejected before contacting crt.sh.
errorset, no charge. - Duplicate — the same domain listed twice (case/URL-form-insensitive) is checked and charged only once; later copies are skipped.
- No certificates on record — a valid domain crt.sh has simply never logged a public certificate for (never had HTTPS, or a typo). A normal row,
certificateCount: 0, no charge. - crt.sh unreachable after retries —
errorset to a clear message, no charge, the rest of your domains keep processing.
Pricing
Pay only for domains crt.sh actually found something for. Pricing model: pay-per-event.
| Event | When it's charged | Price |
|---|---|---|
domain-checked | crt.sh returned at least one certificate for this domain | 0.001 USD |
Not charged: locally invalid domains, duplicates, crt.sh errors, and valid domains with zero certificates on record.
Reliability
crt.sh is the standard, widely-used public search over Certificate Transparency logs — but it's a free service with no SLA, and no published Terms of Use were found for it. Measured directly against the live API: a "cold" (not recently queried) domain can take 20-40 seconds to answer, and it occasionally returns a server error (HTTP 502) under load. This Actor uses a long timeout (75s) and several retries with backoff before giving up on a domain — a slow or briefly-erroring crt.sh almost always still succeeds within a run; it never fails the whole run.
No fallback data source is used when crt.sh is down. SSLMate's CertSpotter API was evaluated as one: it needs no API key, but SSLMate's own documentation states its no-account tier is "for personal or evaluation purposes" only, not for a paid, production service — using it silently here would contradict that. When crt.sh can't be reached after retries, the affected domain gets a clear, non-charged error row ("crt.sh temporarily unavailable, retry later") instead of a fallback result from a source that doesn't actually permit this use.
One request is sent per domain (https://crt.sh/?q=<domain>&output=json), not two. crt.sh's plain search already matches the domain itself and every subdomain by substring, verified directly against the live API; a second "wildcard" request would only double the load on a free, often-overloaded service for the same data. exclude=expired is also sent server-side whenever "Include expired certificates" is off, which cuts the response size substantially for a domain with a long certificate history, instead of downloading everything and discarding most of it locally.
Limitations
- Only certificates that were logged in Certificate Transparency are found — this is every publicly trusted certificate issued since ~2018, but a subdomain that never had a public HTTPS certificate (internal-only, or HTTP-only) won't show up. This is not DNS brute-forcing.
entryTimestampis alwaysnull: crt.sh's own JSON search API doesn't expose the CT log entry time (only its HTML page shows one) — kept in the schema rather than dropped, so it's clear it was considered.maxCertificatesPerDomaincaps the certificates and the subdomains list together for a domain with more certificates than the cap: only the most recent ones are considered.- Duplicate log entries for the same certificate (the same certificate logged to more than one CT log) are collapsed into one; a certificate that only mentions your domain in an unrelated field (e.g. a CA's own test-certificate Subject line) is filtered out entirely, not counted or listed.
FAQ
Am I charged if a domain has no certificates?
No. Only a domain crt.sh returns at least one certificate for is charged. A valid domain with zero certificates on record is a free, informational row.
Where does the data come from?
crt.sh, a free public search over Certificate Transparency logs, run by Sectigo. Every publicly trusted SSL/TLS certificate is required to be logged there — it isn't something a website can turn off.
Is this legal to run on any domain?
Certificate Transparency logs are public — looking up what's in them isn't a security bypass. But treat the results responsibly: only use this for domains you own or are authorized to assess (a pentest, a bug bounty, your own infrastructure). Finding a subdomain here doesn't mean it's fair game to attack.
Can I use this for ongoing monitoring?
Yes — schedule the Actor to run periodically with "Only certificates issued since" set to yesterday's date (or your last run date): each run then only counts certificates first valid since then, useful for catching a new subdomain or an unexpected certificate quickly.
Does this brute-force DNS to find subdomains?
No. Every subdomain returned had a real, publicly logged SSL/TLS certificate at some point — this finds what's provable from CT logs, not every subdomain that might exist.
Can I use this through the Apify API or an MCP server?
Yes, like any Apify Actor — the standard Apify API, or the Apify MCP server with Claude, Cursor, or another MCP client.
Export
Results can be downloaded from the Apify dataset as JSON, CSV, or Excel, or accessed via the Apify API. Underlying data is crt.sh's own public Certificate Transparency search; crtShUrl on every certificate and crtShSearchUrl on every row link to crt.sh's own page so you can double-check any result yourself.