Free subdomain finder: discover subdomains of any domain

Enter a domain name such as example.com to list every subdomain that appeared in a publicly trusted TLS certificate, for example www.example.com, api.example.com or mail.example.com. Each name shows when it was first seen, when its latest certificate expires and whether a certificate for it is still valid today.

Certificate authorities must publish every certificate they issue in public certificate transparency logs. This makes the names in those certificates public. The tool searches the logs through crt.sh, so the discovery is passive: the domain and its servers are never contacted.

The tool is free, needs no account and does not store the domains you search. AI assistants such as Claude can use the same search through an open MCP server at https://felix-pfeiffer.com/mcp, together with a whois and a DNS record lookup.

What you get

How to use it

  1. Open the tool and type a domain name or paste a link.
  2. Press Search. Large domains can take up to a minute.
  3. Filter the list, show only names with a valid certificate or copy all names.

Frequently asked questions

How can I find all subdomains of a domain?

Search the domain in certificate transparency logs. Every subdomain that ever had a publicly trusted TLS certificate is listed there. This tool does that search for you and merges the results into one list.

What is certificate transparency?

Certificate transparency is a system of public, append only logs. Certificate authorities must record every TLS certificate they issue there, so anyone can check which certificates exist for a domain.

Does this find every subdomain?

No. It finds names that appeared in a public certificate. Names that only exist in DNS, are internal or are covered by a wildcard certificate such as *.example.com do not show up by name.

Is subdomain discovery from certificate logs legal?

Yes. The logs are public by design and the search is passive: the domain and its servers are not contacted. Only test systems further if you are allowed to.

Can an AI assistant use this subdomain finder?

Yes. The tool is available as an MCP server at https://felix-pfeiffer.com/mcp. Add it as a custom connector in Claude or with the command claude mcp add --transport http security https://felix-pfeiffer.com/mcp in Claude Code.

Are my searches stored?

No. The domain you enter is sent through this server to crt.sh, the result is cached for 30 minutes and never saved.

More free tools

How to use this tool from an AI assistant (MCP)

Part of the portfolio of Felix Pfeiffer.