Subdomain Finder
Find public subdomains and verify DNS records
Find public subdomains
Search Certificate Transparency records, then verify discovered hostnames with DNS.
How Subdomain Finder works
Enter a domain or URL. The tool queries crt.sh, Cert Spotter, Wayback Machine, and the latest Common Crawl index in parallel, merges source provenance and historical observations, then verifies up to 500 concrete hostnames through DNS-over-HTTPS.
What is passive subdomain discovery?
Passive discovery uses existing public datasets instead of guessing names or connecting to discovered web services. This tool does not brute-force subdomains, scan ports, crawl hosts, attempt zone transfers, or test vulnerabilities.
Understanding results
Resolved means an A, AAAA, or CNAME record was returned. Unresolved means no relevant record was found. Unknown is kept separate for timeouts, rate limits, and temporary resolver failures. Wildcard certificate patterns describe certificate coverage and are not treated as real hosts.
Privacy and responsible use
Domain queries may be sent to public Certificate Transparency, web archive, web index, and DNS services. CodingTool.dev does not save search history in browser storage; a domain may appear in the page URL for reloadable input. Use this tool only for domains you own or are authorized to assess.
