Subdomain Finder for Security Professionals

Map your external attack surface in one quick scan. Enumerate subdomains, detect subdomain takeover vulnerabilities, identify services, cloud providers, and ownership, with screenshots of every live web service.

41.8k+
Domains Scanned
5.7M+
Subdomains Found
11.1M+
Services Found

How it works

Every scan moves through a five-stage pipeline. Results land in a searchable dashboard with screenshots and CSV or JSON export.

01

Light scan

Passive discovery

02

Deep scan

Active enumeration

03

IP scan

Resolve & enrich

04

Port scan

Detect services

05

Verify

Vulnerability checks

Why choose SubAnalyzer?

Most tools stop at listing subdomains. SubAnalyzer gives you instant screenshots, searchable results, and a clean interface, so you spend less time on setup and more time on actual recon.

What is a subdomain

A subdomain is a part of a larger domain name and is often used to organize different sections of a website.

example.com
blog.example.com
Company blog
store.example.com
Online shop
dev.example.com
Dev environment

While subdomains are useful for structuring websites, they can also be easy to forget.

If not properly secured, subdomains may expose hidden services or legacy systems, which can become potential entry points for attackers.

That's why discovering and monitoring subdomains is an important step in protecting your online presence.

PayPal subdomain example showing various subdomains
Discovered subdomains
6 found
  • www.example.com
    Live
  • blog.example.com
    Live
  • cdn.example.com
    Takeover risk
  • mail.example.com
    Live
  • shop.example.com
    Live
    Services
    Web80HTTP443HTTPS
    IP Owner
    Cloudflare, Inc. (ASN: 13335)
    cloudflare.com
  • legacy.example.com
    Takeover risk
2 takeover risks foundscan complete

Know your subdomains

Each subdomain you create increases the number of entry points into your systems.

Whether it's used for development, testing, or older applications, a forgotten or poorly configured subdomain can become an easy target for attackers.

Subdomains often host different services, have separate access controls, or link to third-party tools. If one is not properly secured or monitored, it can expose data, open the door to attackers, or even be taken over.

By keeping track of your subdomains, you gain better control over your public-facing infrastructure. It helps reduce security risks, improves your visibility, and supports both compliance and incident response efforts.

How we identify subdomains

Our subdomain discovery process is designed to be thorough, structured, and privacy-respecting.

We start by gathering publicly available information from reliable sources to find known subdomains associated with your domain. After the initial discovery, we expand our search using intelligent techniques that help identify hidden or lesser-known subdomains that might not be easily visible through conventional methods.

Each potential subdomain is then carefully validated through real-time resolution checks to confirm its existence and activity. Once validated, we conduct further analysis to discover additional details, such as active services, providing a deeper understanding of your external attack surface.

By combining these layers of discovery and validation, we deliver a comprehensive and accurate map of your domain's presence online.

Our 3-step process

1

Initial discovery

Gathering publicly available information from reliable sources

2

Expanded exploration

Intelligent techniques to uncover hidden subdomains

3

Validation and analysis

Resolution checks and focused network analysis

FAQ

What is a subdomain finder?+
A subdomain finder is a tool that discovers all the subdomains associated with a domain name. It scans public records, DNS data, and other sources to reveal subdomains like mail.example.com or dev.example.com that may not be immediately visible.
How does subdomain enumeration work?+
Subdomain enumeration combines passive techniques (like querying certificate transparency logs and DNS records) with active techniques (like DNS brute-forcing) to build a complete list of subdomains. SubAnalyzer uses both approaches to maximize coverage.
What is the difference between a light scan and a deep scan?+
A light scan uses passive sources like certificate transparency logs to quickly find known subdomains. A deep scan adds active techniques such as DNS brute-forcing and permutation scanning to uncover subdomains that passive methods miss.
Subdomain Finder | SubAnalyzer