Subdomain Finder
The subdomain you forgot to shut down is the one that gets you. Because every SSL certificate is logged publicly in Certificate Transparency logs, those logs double as an inventory of hostnames that exist. We read them for your domains and surface the ones you aren't monitoring — a leftover staging. box, a demo host, a client's legacy subdomain — then grade each one so you can see which are actually exposed.
Attack-surface tools list subdomains. We list them and tell you which have a failing SSL grade, an expiring certificate, or no HTTPS redirect — the part that says whether it's a problem.
Check any hostname's SSL and security setup free — no signup.
Find it, then know if it matters
Discover from CT logs
No brute-force wordlists or DNS guessing. We use the certificates actually issued for your domains, so the list is real hostnames that exist — not maybes.
Scan each one
One click grades a discovered host: SSL grade, certificate expiry, HTTP→HTTPS redirect, security headers. The forgotten staging box with an expiring cert and grade F is exactly what this finds.
Bring it under monitoring
Add a discovered host to monitoring in one click and it's checked on the same schedule as the rest — with an alert if its grade drops or its certificate nears expiry.
Built for agencies and anyone with more than one host
Taking over a new client's infrastructure? Subdomain discovery is the first report you can hand them: here's everything you have exposed that nobody was watching. It runs off the Certificate Transparency data we already collect for monitoring, so there's nothing to configure — add the parent domain and the shadow inventory appears in your dashboard.
Related: