# Subdomain Finder — SSL Certificate Transparency Lookup (`keyman98/cert-transparency-lookup`) Actor

Find the subdomains and SSL/TLS certificates of any domain from public Certificate Transparency logs (crt.sh). Issuer, validity dates, active certificates, and a clean subdomain list. For asset inventory and authorized security reviews.

- **URL**: https://apify.com/keyman98/cert-transparency-lookup.md
- **Developed by:** [KeyMan98](https://apify.com/keyman98) (community)
- **Categories:** Developer tools, SEO tools, Automation
- **Stats:** 2 total users, 1 monthly users, 100.0% runs succeeded, 0 bookmarks
- **User rating**: No ratings yet

## Pricing

from $1.00 / 1,000 domain checkeds

This Actor is paid per event. You are not charged for the Apify platform usage, but only a fixed price for specific events.

Learn more: https://docs.apify.com/actors/running/actors-in-store.md#pay-per-event

## What's an Apify Actor?

An Actor is a serverless cloud program that runs on the Apify platform. It has two run modes.
In Batch mode, an Actor accepts a well-defined JSON input, performs an action which can take anything from a few seconds to a few hours,
and optionally produces a well-defined JSON output, datasets with results, or files in key-value store.
In Standby mode, an Actor provides a web server which can be used as a website, API, or an MCP server.

Apify vocabulary and the platform model are defined once, in the agent quickstart at https://apify.com/agents.md.

## How to integrate an Actor?

If asked about integration, you help developers integrate Actors into their projects.
You adapt to their stack and deliver integrations that are safe, well-documented, and production-ready.

Do not guess an integration path. Every one of them is in the agent quickstart at https://apify.com/agents.md: the Apify MCP server, Agent Skills with the Apify CLI, the JavaScript and Python clients, the REST API, and the account-free path for an agent with no human to sign in. It also carries the rule on stating cost before the first paid run.

For examples already wired to this Actor's own input schema, see the [API](#api) section below.

Each client library has reference documentation the quickstart does not restate: [JavaScript/TypeScript](https://docs.apify.com/api/client/js/docs.md) (`npm install apify-client`) and [Python](https://docs.apify.com/api/client/python/docs.md) (`pip install apify-client`).

# README

## Subdomain Finder — SSL Certificate Transparency Lookup

Find every subdomain and SSL/TLS certificate publicly logged for a domain, through **crt.sh** (run by Sectigo) — the standard public search over Certificate Transparency logs. No API key, no HTML scraping, no login.

Every publicly trusted SSL/TLS certificate issued since ~2018 is logged, permanently and publicly, in Certificate Transparency (CT) logs — that's a browser requirement, not something a site can opt out of. crt.sh indexes those logs and makes them searchable by domain. This Actor turns that search into structured rows: every subdomain that ever had a public certificate, and every certificate itself (issuer, validity dates, serial number).

### What you get (output fields)

For each domain, one dataset row with:

- `domain` — the domain as given (or the host extracted from a pasted URL), lowercased.
- `subdomains` — unique, sorted list of every subdomain found (a wildcard entry like `*.example.com` is included as-is). Omitted (null) when "Include the subdomains list" is off.
- `subdomainCount` — how many, even when the list itself is left out.
- `certificates` — up to "Max certificates per domain" certificates, most recent first. Each one: `id` (crt.sh's own ID), `issuerName`, `commonName`, `nameValue` (every name on the certificate, as a list), `notBefore`, `notAfter`, `entryTimestamp`, `serialNumber`, `crtShUrl` (link to crt.sh's own page for that certificate).
- `certificateCount` — how many certificates are in `certificates` (after the cap). `0` means crt.sh has no certificate on record for this domain.
- `activeCertificateCount` — of those, how many are currently within their validity period.
- `source` — always `"crt.sh"` on a successful row.
- `crtShSearchUrl` — the public crt.sh search page for this domain, to double-check the answer yourself.
- `error` — set only when a row was never checked (invalid domain, duplicate, or crt.sh unreachable); every other field is null on those rows.

### Who it's for

- **Security teams and pentesters, on domains they're authorized to test** — subdomain discovery is a standard first step in an authorized security review.
- **Asset inventory** — find forgotten subdomains (staging, old marketing sites, internal tools) that still have public certificates.
- **Monitoring** — run on a schedule with "Only certificates issued since" set to catch new subdomains or unexpected certificates as soon as they're logged.
- **Certificate/SSL expiry tracking** — `notAfter` on every certificate found.

### How to use

1. **Domains** — one or more, e.g. `example.com`. A pasted URL (`https://www.example.com/path`) works too — just the host is used, the rest is dropped.
2. **Include expired certificates** — off by default (current certificates only, and a much smaller, faster response). Turn on for the full history.
3. **Include the subdomains list** — on by default. Turn off if you only need the count.
4. **Max certificates per domain** — default 200. Raise it for a domain with a long certificate history; lower it to keep rows small.
5. **Only certificates issued since** (optional) — `YYYY-MM-DD`, for monitoring: only certificates first valid on or after this date are counted.
6. **Run the Actor.** Each domain becomes one row.

### Input example (JSON)

```json
{
  "domains": ["example.com"],
  "includeExpired": false,
  "includeSubdomainsList": true,
  "maxCertificatesPerDomain": 200
}
```

### Output example (JSON, shortened)

```json
{
  "domain": "example.com",
  "subdomains": ["*.example.com", "www.example.com"],
  "subdomainCount": 2,
  "certificates": [
    {
      "id": 29557945233,
      "issuerName": "C=GB, O=Sectigo Limited, CN=Sectigo Public Server Authentication CA DV E36",
      "commonName": "example.com",
      "nameValue": ["*.example.com", "example.com"],
      "notBefore": "2026-09-24T00:00:00",
      "notAfter": "2026-12-21T09:32:54",
      "entryTimestamp": null,
      "serialNumber": "2caeeaf0743459d7e5f82a75123c58f3",
      "crtShUrl": "https://crt.sh/?id=29557945233"
    }
  ],
  "certificateCount": 10,
  "activeCertificateCount": 10,
  "source": "crt.sh",
  "crtShSearchUrl": "https://crt.sh/?q=example.com",
  "error": null
}
```

### If a domain can't be checked

Every domain gets exactly one row, and the run never fails because of one bad domain:

- **Locally invalid** (not a valid hostname, or an IP address) — rejected before contacting crt.sh. `error` set, no charge.
- **Duplicate** — the same domain listed twice (case/URL-form-insensitive) is checked and charged only once; later copies are skipped.
- **No certificates on record** — a valid domain crt.sh has simply never logged a public certificate for (never had HTTPS, or a typo). A normal row, `certificateCount: 0`, no charge.
- **crt.sh unreachable** after retries — `error` set to a clear message, no charge, the rest of your domains keep processing.

### Pricing

Pay only for domains crt.sh actually found something for. Pricing model: **pay-per-event**.

| Event | When it's charged | Price |
| --- | --- | --- |
| `domain-checked` | crt.sh returned **at least one certificate** for this domain | 0.001 USD |

Not charged: locally invalid domains, duplicates, crt.sh errors, and valid domains with zero certificates on record.

### Reliability

crt.sh is the standard, widely-used public search over Certificate Transparency logs — but it's a free service with no SLA, and no published Terms of Use were found for it. Measured directly against the live API: a "cold" (not recently queried) domain can take 20-40 seconds to answer, and it occasionally returns a server error (HTTP 502) under load. This Actor uses a long timeout (75s) and several retries with backoff before giving up on a domain — a slow or briefly-erroring crt.sh almost always still succeeds within a run; it never fails the whole run.

No fallback data source is used when crt.sh is down. **SSLMate's CertSpotter API** was evaluated as one: it needs no API key, but SSLMate's own documentation states its no-account tier is "for personal or evaluation purposes" only, not for a paid, production service — using it silently here would contradict that. When crt.sh can't be reached after retries, the affected domain gets a clear, non-charged error row (`"crt.sh temporarily unavailable, retry later"`) instead of a fallback result from a source that doesn't actually permit this use.

One request is sent per domain (`https://crt.sh/?q=<domain>&output=json`), not two. crt.sh's plain search already matches the domain itself and every subdomain by substring, verified directly against the live API; a second "wildcard" request would only double the load on a free, often-overloaded service for the same data. `exclude=expired` is also sent server-side whenever "Include expired certificates" is off, which cuts the response size substantially for a domain with a long certificate history, instead of downloading everything and discarding most of it locally.

### Limitations

- Only certificates that were **logged in Certificate Transparency** are found — this is every publicly trusted certificate issued since ~2018, but a subdomain that never had a public HTTPS certificate (internal-only, or HTTP-only) won't show up. This is not DNS brute-forcing.
- `entryTimestamp` is always `null`: crt.sh's own JSON search API doesn't expose the CT log entry time (only its HTML page shows one) — kept in the schema rather than dropped, so it's clear it was considered.
- `maxCertificatesPerDomain` caps the certificates *and* the subdomains list together for a domain with more certificates than the cap: only the most recent ones are considered.
- Duplicate log entries for the same certificate (the same certificate logged to more than one CT log) are collapsed into one; a certificate that only mentions your domain in an unrelated field (e.g. a CA's own test-certificate Subject line) is filtered out entirely, not counted or listed.

### FAQ

#### Am I charged if a domain has no certificates?

No. Only a domain crt.sh returns at least one certificate for is charged. A valid domain with zero certificates on record is a free, informational row.

#### Where does the data come from?

crt.sh, a free public search over Certificate Transparency logs, run by Sectigo. Every publicly trusted SSL/TLS certificate is required to be logged there — it isn't something a website can turn off.

#### Is this legal to run on any domain?

Certificate Transparency logs are public — looking up what's in them isn't a security bypass. But treat the *results* responsibly: only use this for domains you own or are authorized to assess (a pentest, a bug bounty, your own infrastructure). Finding a subdomain here doesn't mean it's fair game to attack.

#### Can I use this for ongoing monitoring?

Yes — schedule the Actor to run periodically with "Only certificates issued since" set to yesterday's date (or your last run date): each run then only counts certificates first valid since then, useful for catching a new subdomain or an unexpected certificate quickly.

#### Does this brute-force DNS to find subdomains?

No. Every subdomain returned had a real, publicly logged SSL/TLS certificate at some point — this finds what's *provable* from CT logs, not every subdomain that might exist.

#### Can I use this through the Apify API or an MCP server?

Yes, like any Apify Actor — the standard Apify API, or the Apify MCP server with Claude, Cursor, or another MCP client.

### Export

Results can be downloaded from the Apify dataset as JSON, CSV, or Excel, or accessed via the Apify API. Underlying data is crt.sh's own public Certificate Transparency search; `crtShUrl` on every certificate and `crtShSearchUrl` on every row link to crt.sh's own page so you can double-check any result yourself.

# Actor input Schema

## `domains` (type: `array`):

One or more domains, e.g. "example.com". A pasted URL (e.g. "https://www.example.com/path") is also accepted - just the host is used.

## `includeExpired` (type: `boolean`):

Off (default): only certificates that are still within their validity period. On: also include certificates that have already expired - a much longer, slower list for domains with a long history.

## `includeSubdomainsList` (type: `boolean`):

On (default): each row includes the full "subdomains" list. Off: only "subdomainCount" is included (smaller rows, e.g. for a dashboard that only needs the count).

## `maxCertificatesPerDomain` (type: `integer`):

Cap on how many certificates (most recent first) are returned per domain. Protects memory and output size for domains with thousands of logged certificates.

## `onlyNewSince` (type: `string`):

"YYYY-MM-DD". For monitoring: only count/return certificates first valid on or after this date. Leave empty for the full history.

## Actor input object example

```json
{
  "domains": [
    "example.com"
  ],
  "includeExpired": false,
  "includeSubdomainsList": true,
  "maxCertificatesPerDomain": 200
}
```

# Actor output Schema

## `results` (type: `string`):

All checked domains in the default dataset (JSON, CSV, Excel).

# API

You can run this Actor programmatically using our API. Below are code examples in JavaScript, Python, and CLI, as well as the OpenAPI specification and MCP server setup.

## JavaScript example

```javascript
import { ApifyClient } from 'apify-client';

// Initialize the ApifyClient with your Apify API token
// Replace the '<YOUR_API_TOKEN>' with your token
const client = new ApifyClient({
    token: '<YOUR_API_TOKEN>',
});

// Prepare Actor input
const input = {
    "domains": [
        "example.com"
    ]
};

// Run the Actor and wait for it to finish
const run = await client.actor("keyman98/cert-transparency-lookup").call(input);

// Fetch and print Actor results from the run's dataset (if any)
console.log('Results from dataset');
console.log(`💾 Check your data here: https://console.apify.com/storage/datasets/${run.defaultDatasetId}`);
const { items } = await client.dataset(run.defaultDatasetId).listItems();
items.forEach((item) => {
    console.dir(item);
});

// 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/js/docs

```

## Python example

```python
from apify_client import ApifyClient

# Initialize the ApifyClient with your Apify API token
# Replace '<YOUR_API_TOKEN>' with your token.
client = ApifyClient("<YOUR_API_TOKEN>")

# Prepare the Actor input
run_input = { "domains": ["example.com"] }

# Run the Actor and wait for it to finish
run = client.actor("keyman98/cert-transparency-lookup").call(run_input=run_input)

# Fetch and print Actor results from the run's dataset (if there are any)
print(f"💾 Check your data here: https://console.apify.com/storage/datasets/{run.default_dataset_id}")
for item in client.dataset(run.default_dataset_id).iterate_items():
    print(item)

# 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/python/docs/quick-start

```

## CLI example

```bash
echo '{
  "domains": [
    "example.com"
  ]
}' |
apify call keyman98/cert-transparency-lookup --silent --output-dataset

```

## MCP server setup

```json
{
    "mcpServers": {
        "apify": {
            "type": "http",
            "url": "https://mcp.apify.com/?tools=fetch-actor-details,keyman98/cert-transparency-lookup"
        }
    }
}
```

The hosted server signs you in with OAuth on first connect, so no API token belongs in this config. Clients without OAuth support can send an `Authorization: Bearer <APIFY_API_TOKEN>` header instead, using a token from API & Integrations in Apify Console (https://console.apify.com/settings/integrations).

## OpenAPI specification

Download the OpenAPI definition: https://api.apify.com/v2/actors/lbNhsZdvekba0UFrP/builds/7aHzmGchz6SpGE4fX/openapi.json
