Loading...

Subdomain Finder

Discover hostnames exposed in public TLS Certificate Transparency logs.

Enter a domain only. A pasted HTTP or HTTPS URL will be reduced to its hostname.
Passive certificate search

This search reads public certificate records and does not connect to each discovered hostname.

Searching certificate logs...

Discovered subdomains

Unique subdomains
0
Certificates reported
0
Result source
CertKit could not be reached, so these older cached results are shown. Verify them before use.
The provider or safety limit truncated this result set. The list may be incomplete.
No concrete subdomains were found in the returned certificate records.
# Subdomain Latest issuer Certificate valid until Action
How to interpret the results

Certificate logs are historical evidence, not a live availability check. Wildcards and the root domain are excluded, and you should confirm DNS and authorization before further testing.

About the Subdomain Finder

The Subdomain Finder searches public Certificate Transparency data through CertKit and extracts concrete hostnames found in certificate common names and DNS names.

Results are deduplicated and cached in the VuiZ database for 24 hours. A listed hostname appeared in a public certificate, but it may no longer resolve, accept connections, or belong to the same service.

Key features

  • Certificate Transparency discovery Find hostnames disclosed when public certificate authorities issued TLS certificates for a domain.
  • Scoped and deduplicated results Keep only concrete names below the requested domain, remove duplicates, and exclude apex and wildcard-only entries.
  • Certificate context Review the issuer and latest certificate expiry associated with each extracted hostname.
  • Database cache Reuse a stored search for 24 hours to reduce upstream requests; stale data is labeled when used during a CertKit outage.

How to find subdomains in certificate logs

Use a registrable domain or a delegated subdomain and interpret the results as historical certificate evidence.

  1. Enter a domain Enter a hostname such as example.com without a path, query string, wildcard, or IP address.
  2. Search Certificate Transparency data Select Find subdomains. VuiZ checks its database cache first and queries CertKit when the cached entry has expired.
  3. Filter and review the hostnames Filter the deduplicated list and review issuer and certificate expiry information for useful leads.
  4. Export and verify Copy or download the list, then verify DNS resolution and service ownership before using a hostname in an inventory or assessment.

Usage tips

  • Search both the root domain and important delegated zones when you need a broader inventory.
  • Treat expired certificate names as historical leads and confirm them with current DNS data.
  • Only assess systems you own or are explicitly authorized to test; this tool does not perform active probing.

Frequently asked questions

VuiZ queries the CertKit search API, then extracts in-scope common names and DNS names from public Certificate Transparency records.
No. It proves that the hostname appeared in a logged certificate. DNS records, hosting, and ownership may have changed or disappeared.
A certificate for *.example.com covers many possible labels but does not prove that any specific subdomain exists, so wildcard-only names are not presented as discovered hosts.
Internal certificates, certificates outside public logs, services without TLS, provider limits, and names never included in a certificate can all be absent.
Each normalized domain stores its extracted results and certificate summary for 24 hours. If CertKit is temporarily unavailable, an older record may be returned with a stale-cache warning.