Free Subdomain Finderfor Security Professionals
Scan your attack surface, identify exposed services, capture screenshots, and receive e-mail alerts when anything changes.
- Subdomains Found
- 5.2M+
- Domains Scanned
- 41.1k+
- Services Found
- 5.7M+
10 Latest Scans
How it works
Every scan moves through a five-stage pipeline. Results land in a searchable dashboard with screenshots and CSV or JSON export.
- 01Light scanPassive discovery
- 02Deep scanActive enumeration
- 03IP scanResolve & enrich
- 04Port scanDetect services
- 05VerifyVulnerability checks
Why choose SubAnalyzer?
Most tools stop at listing subdomains. SubAnalyzer gives you instant screenshots, searchable results, and a clean interface, so you spend less time on setup and more time on actual recon.
Get startedWhat is a subdomain
A subdomain is a part of a larger domain name and is often used to organize different sections of a website.
example.com
blog.example.comCompany blog
store.example.comOnline shop
dev.example.comDev environment
mail.example.comE-mail
While subdomains are useful for structuring websites, they can also be easy to forget.
If not properly secured, subdomains may expose hidden services or legacy systems, which can become potential entry points for attackers.
That’s why discovering and monitoring subdomains is an important step in protecting your online presence.
CNAME
shops.myshopify.comServices
Hosting
Cloudflare, Inc.
AS13335
Know your subdomains
Each subdomain you create increases the number of entry points into your systems.
Whether it’s used for development, testing, or older applications, a forgotten or poorly configured subdomain can become an easy target for attackers.
By keeping track of your subdomains, you gain better control over your public-facing infrastructure. It helps reduce security risks, improves your visibility, and supports both compliance and incident response efforts.
How we identify subdomains
Two kinds of discovery, one gate in the middle. Nothing reaches your results without passing through it.
Passive · powers the light scan
Reading the public record
Nothing we send touches your infrastructure.
- Certificate transparencyEvery TLS certificate you have been issued, logged in public.
- Public DNS recordsThe names your nameservers already publish.
- Open datasetsArchives that remember what your DNS has dropped.
Active · powers the deep scan
Asking live DNS
Candidates we generate, asked of your nameservers.
- Wordlist brute-forceA curated list of the names teams actually use.
- PermutationsNew candidates built from the names already found.
- Live probingEvery generated name resolved before it is kept.
Every candidate
Verified before it reaches you
- Does it resolve
- Who hosts it
- What is listening
- Can it be taken over
A name that answers nothing is dropped at the gate. What reaches you has an address, a provider, its open ports and a screenshot.