Skip to content
SubAnalyzer

Subdomain finderfor security professionals

Scan your attack surface, identify exposed services, capture screenshots, and receive e-mail alerts when anything changes

Subdomains found
5.2M+
Domains scanned
41.1k+
Services found
5.7M+

How it works

Every scan moves through a five-stage pipeline. Results land in a searchable dashboard with screenshots and CSV or JSON export.

  1. 01Light scanPassive discovery
  2. 02Deep scanActive enumeration
  3. 03IP scanResolve & enrich
  4. 04Port scanDetect services
  5. 05VerifyVulnerability checks

Why choose SubAnalyzer?

Most tools stop at listing subdomains. SubAnalyzer gives you instant screenshots, searchable results, and a clean interface, so you spend less time on setup and more time on actual recon.

Get started

What is a subdomain?

A subdomain is a part of a larger domain name and is often used to organize different sections of a website.

example.com

blog.example.comCompany blog

store.example.comOnline shop

dev.example.comDev environment

mail.example.comE-mail

While subdomains are useful for structuring websites, they can also be easy to forget.

If not properly secured, subdomains may expose hidden services or legacy systems, which can become potential entry points for attackers.

That’s why discovering and monitoring subdomains is an important step in protecting your online presence.

Know your subdomains

Each subdomain you create increases the number of entry points into your systems.

Whether it’s used for development, testing, or older applications, a forgotten or poorly configured subdomain can become an easy target for attackers.

Subdomains often host different services, have separate access controls, or link to third-party tools. If one is not properly secured or monitored, it can expose data, open the door to attackers, or even be taken over.

By keeping track of your subdomains, you gain better control over your public-facing infrastructure. It helps reduce security risks, improves your visibility, and supports both compliance and incident response efforts.

How we identify subdomains

Two kinds of discovery, one gate in the middle. Nothing reaches your results without passing through it.

Passive · powers the light scan

Reading the public record

Nothing we send touches your infrastructure.

  • Certificate transparencyEvery TLS certificate you have been issued, logged in public
  • Public DNS recordsThe names your nameservers already publish
  • Open datasetsArchives that remember what your DNS has dropped

Active · powers the deep scan

Asking live DNS

Candidates we generate, asked of your nameservers.

  • Wordlist brute-forceA curated list of the names teams actually use
  • PermutationsNew candidates built from the names already found
  • Live probingEvery generated name resolved before it is kept

Every candidate

Verified before it reaches you

  • Does it resolve
  • Who hosts it
  • What is listening
  • Can it be taken over

A name that answers nothing is dropped at the gate. What reaches you has an IP address, a provider, open ports, and a screenshot.

FAQ

What is a subdomain finder?
A subdomain finder is a tool that discovers all the subdomains associated with a domain name. It scans public records, DNS data, and other sources to reveal subdomains like mail.example.com or dev.example.com that may not be immediately visible.
How does subdomain enumeration work?
Subdomain enumeration combines passive techniques (like querying certificate transparency logs and DNS records) with active techniques (like DNS brute-forcing) to build a complete list of subdomains. SubAnalyzer uses both approaches to maximize coverage.
What is the difference between a light scan and a deep scan?
A light scan uses passive sources like certificate transparency logs to quickly find known subdomains. A deep scan adds active techniques such as DNS brute-forcing and permutation scanning to uncover subdomains that passive methods miss. Read our light scan vs deep scan comparison for details.
What information will I receive from a scan?
Each scan returns a list of discovered subdomains along with their IP addresses, open ports, running services, and HTTP status codes. For web-facing subdomains, you also get automatic screenshots and page titles, giving you a visual overview of your entire attack surface. See which ports SubAnalyzer scans for the full list.
What can I do with the screenshots SubAnalyzer captures?
Screenshots let you visually identify what each subdomain hosts without visiting it manually. This makes it easy to spot login pages, default server pages, staging environments, or forgotten applications across hundreds of subdomains at a glance.
What can I do after finding subdomains?
Once you have your list of subdomains, you can review screenshots to quickly identify what each one hosts, check for forgotten services or staging environments, look for misconfigurations, and export everything to CSV or JSON for further analysis in your preferred security tools.
Can I automate subdomain scans?
Yes. With monitoring enabled for a domain, SubAnalyzer re-scans it automatically on a fixed schedule and sends you an e-mail alert whenever its subdomains change. Monitoring is available on paid plans.
Can I export my scan results?
Yes. All scan results can be exported to CSV or JSON format. This makes it easy to import findings into other security tools, share reports with your team, or keep records for compliance purposes.
Who can benefit from using SubAnalyzer?
SubAnalyzer is built for security professionals, penetration testers, bug bounty hunters, and IT teams who need to map and monitor their external attack surface. It's also useful for compliance teams tracking organizational assets and developers who want visibility into their infrastructure.
Why is subdomain discovery important for security?
Every subdomain is a potential entry point for attackers. Forgotten or misconfigured subdomains can expose internal services, staging environments, or outdated software. Regular subdomain discovery helps security teams maintain visibility over their full attack surface.
Is subdomain scanning legal?
Yes. Subdomain information is publicly available through DNS records, certificate transparency logs, and other open sources. Discovering subdomains is a standard practice in security operations and does not require special authorization.
Is SubAnalyzer free to use?
SubAnalyzer offers a free light scan for every domain so you can try the tool instantly. For deeper scans, screenshot capture, and unlimited access, paid plans start at $15/month. Visit our pricing page for details.