Subdomain Finder

Find public subdomains and verify DNS records

Use only on domains you own or are authorized to assess.
Advanced settings

Find public subdomains

Search Certificate Transparency records, then verify discovered hostnames with DNS.

How Subdomain Finder works

Enter a domain or URL. The tool queries crt.sh, Cert Spotter, Wayback Machine, and the latest Common Crawl index in parallel, merges source provenance and historical observations, then verifies up to 500 concrete hostnames through DNS-over-HTTPS.

What is passive subdomain discovery?

Passive discovery uses existing public datasets instead of guessing names or connecting to discovered web services. This tool does not brute-force subdomains, scan ports, crawl hosts, attempt zone transfers, or test vulnerabilities.

Understanding results

Resolved means an A, AAAA, or CNAME record was returned. Unresolved means no relevant record was found. Unknown is kept separate for timeouts, rate limits, and temporary resolver failures. Wildcard certificate patterns describe certificate coverage and are not treated as real hosts.

Privacy and responsible use

Domain queries may be sent to public Certificate Transparency, web archive, web index, and DNS services. CodingTool.dev does not save search history in browser storage; a domain may appear in the page URL for reloadable input. Use this tool only for domains you own or are authorized to assess.

CodingTool is officially live on

Launched on StartupBaseCodingTool.dev - Free, Fast & Easy Developer Tools in One Place | Product HuntCodingTool - Featured on Startup FameFazier badgeListed on Turbo0Featured on Twelve ToolsFeatured on Findly.tools