Subdomains
Every hostname that received a public certificate, pulled from Certificate Transparency logs (crt.sh) — great for asset and exposure review.
Query
crt.sh is often slow — 10s+ is normal, you can cancel anytime; results are cached server-side for 5 minutes.
Results
Query a root domain to list its subdomains.
How to use
This tool belongs to the “Reachability” category.
- 1For a single target use "IP detection": enter an IPv4 or IPv6 address to get location, ASN and a map pin.
- 2To trace how a site is reached, use site connectivity, egress IP groups, DNS egress and CDN nodes - just enter the domain.
- 3For outside data use WHOIS / RDAP for registration and expiry, subdomain lookup for related hosts, and global ping to compare latency across nodes.
Device and browser checks run on your machine. Domain and IP lookups are fetched by this site from public feeds, and each query string is kept as one public record.
Frequently asked questions
Is subdomain lookup the same as scanning a site?
No. Hosts come from public certificate-transparency logs; this site sends no probes to the target server.
DNS differs from my local nslookup.
The check resolves from the server egress, which rarely matches your local resolver. Compare both when you hunt for DNS pollution.
Global ping looks slower than my own monitoring.
Nodes reach the target over the public internet, unlike a probe inside your network. Use these numbers to compare nodes, not to replace your monitor.