SubAnalyzer combines public records with direct DNS queries to find your domain's subdomains. It then checks each candidate, confirms open services and looks for takeover risks. The result is a list of names with their addresses, hosting providers, services and web pages.
The scan runs through five steps: Light scan, Deep scan, IP scan, Service scan and Verify. Some run side by side, and names discovered later go back through the same checks. Most scans finish in under two minutes, and a large domain takes a few minutes more.
Light scan: what public sources already know
Public sources reveal the subdomains an attacker can find first. The light scan collects names from certificate records, passive DNS datasets and your website. It also includes names from earlier scans.
Certificate transparency logs
Certificate transparency (CT) logs make certificate hostnames public. A certificate for staging-admin.example.com can reveal that name even if no page ever links to it.
SubAnalyzer reads CT logs itself and keeps its own index of hostnames in newly logged certificates. Public certificate search services fill in older certificates, including expired ones.
A wildcard certificate such as *.example.com leaves a gap: it does not list each host it covers. Those names need to be found another way.
Passive DNS, website links and earlier scans
Passive DNS datasets contribute names observed in DNS lookups around the internet, including hosts that never had a certificate.
SubAnalyzer also reads your homepage, robots.txt and the sitemaps they reference, looking for links to hosts under your domain. These are a handful of ordinary requests identified as SubAnalyzer.
On a re-scan, it checks every previously discovered subdomain again, even if the name has disappeared from public sources.
These sources only know names that have been published or observed. The deep scan looks for names they missed by asking DNS directly.
Deep scan: asking DNS directly
The deep scan starts alongside the light scan. It uses several subdomain discovery methods, from requesting the full DNS zone to testing likely names.
Zone transfers and zone walking
A zone transfer (AXFR) asks each nameserver for a full copy of the zone. Most nameservers refuse. When one allows it, SubAnalyzer can collect the zone's names directly.
DNSSEC can offer another route. An NSEC record used to prove that a name does not exist also identifies the next name in the zone. Following that chain is called zone walking. SubAnalyzer first checks whether the zone uses NSEC or NSEC3. Because NSEC3 hashes the names, the scanner does not attempt an NSEC walk on those zones.
Records that point to other hosts
SubAnalyzer queries 169 common SRV records, including _autodiscover._tcp and _sip._tcp, and reads your NS, MX and SPF records. These can reveal service, nameserver and mail hosts.
Only names under your domain are included. A mail server belonging to your email provider is left out.
Wordlist discovery
The scan also tests 20,659 common labels, from www and mail to vpn, staging and grafana. This can find names that never appeared in public sources.
The wordlist is skipped if a zone transfer or walk has already listed the zone. It is also skipped when a wildcard makes every possible name resolve, because a successful lookup would reveal nothing about whether the guessed name has its own record.
Checking which names are real
Discovery produces candidates, not a finished list. Before a candidate appears in your results, SubAnalyzer checks the evidence behind it. On the scan page, these checks are part of Deep scan.
Candidates are resolved through a pool of 12 public resolvers at about 3,000 names a second. The scanner requests IPv4 addresses first, then IPv6 addresses for every name that exists. A timeout is treated differently from an answer saying the name does not exist.
A name qualifies if it has an address, is a CNAME alias or has TXT records of its own. A CNAME still counts when its target has disappeared, because that dangling record may indicate takeover risk.
Names supported by certificates or your own DNS records can remain in the results even when they do not resolve today. They appear without an address and are hidden in the Live view. Names found only by guessing must resolve to count.
Wildcard DNS
A wildcard such as *.example.com can make any name resolve. Without checking for it, a scanner can report thousands of invented subdomains.
SubAnalyzer tests for wildcards at every level of your domain. For each resolving candidate, it queries a random 16-character name at the same level. If that random name also resolves, the scanner moves up one level at a time to find where the wildcard begins.
A candidate beneath a wildcard needs closer inspection. A zone listing, a DNSSEC signature, a record that differs from the wildcard's or a nonresolving random name one level below the candidate can establish that it has its own DNS record.
If DNS cannot settle the question, SubAnalyzer compares the candidate's web page with pages served for two random names at the same address. Matching pages indicate a wildcard response, so the candidate is dropped. A different page or a valid certificate of its own allows the name to stay, marked Via wildcard.
For example, shop.example.com might serve a distinct storefront and be kept, while test.example.com serves the same default page as the random names and is dropped.
Names beneath a wildcard that point to private addresses cannot undergo that page comparison. They are kept only when a certificate or your website names them.
Confirming removals
A failed lookup should not erase a real subdomain. When a previously discovered name appears to be gone, SubAnalyzer asks your own nameservers directly. It reports the name as removed only when all of them agree that it no longer exists.
If the answers are inconclusive, the name keeps its last known result. After several inconclusive scans, it is marked Unverified.
The scanner also checks for broader resolver failures. If a large share of hosts with previously open ports stops resolving at once, the scan fails and your previous results are preserved.
IP scan: addresses and hosting
The IP scan records IPv4 and IPv6 addresses and identifies the networks behind them. The Reachable count includes subdomains with at least one public address. Other names have no current address or point only to private networks.
Using each host's first resolved address, SubAnalyzer looks up the network operator in MaxMind's GeoLite2 ASN database. It also recognizes 11 major clouds and CDNs, including AWS, Azure, Google Cloud, Cloudflare and Akamai, and names the provider in the Hosting column.
Service scan: confirming open services
An initial port response does not always mean a service is available. SubAnalyzer checks 58 TCP ports on public IPv4 addresses, covering web servers, mail, remote access, databases and infrastructure. The full port reference explains which ports are included and why.
It checks up to 8 addresses per host and limits each address to about 25 probes a second. IPv6 addresses are recorded but are not scanned for services.
A real connection before a result
The fast pass sends the first packet of a connection. Firewalls and SYN proxies can answer that packet even when no service is listening, making a host appear open on many ports.
Before showing a port, SubAnalyzer requires a completed TLS handshake, an HTTP response or a connection that stays open. It also probes port 2 to identify addresses that appear to answer indiscriminately. For those addresses, only real handshakes count.
Ports 443 and 80 are always checked under each hostname, even if the fast pass missed them. Ports seen in recent scans are checked again too. Service labels, such as HTTPS for port 443, come from the port number. The scan does not check software versions.
Finding more names along the way
Service checks can reveal hosts that earlier sources missed. Each TLS handshake reads the server's certificate, which may list additional hostnames. In parallel, a reverse DNS sweep looks up every address in the surrounding block of 256 addresses, potentially finding neighbors such as backup servers.
New names under your domain go back through verification. Those that pass receive their own service scan. Wildcard certificate entries are skipped. If the entire domain uses wildcard DNS, names discovered from these certificates are set aside because resolving them would not establish that they exist independently.
Verify: takeover checks and screenshots
The final step checks for takeover risk and captures web pages, adding context to the names and services the scan has found.
Subdomain takeover checks
A takeover can happen when a CNAME points to a cloud or SaaS resource that no longer exists. If someone else can register that resource's name, they may gain control of what your subdomain serves. Read more about how subdomain takeover happens and how to prevent it.
SubAnalyzer checks each discovered CNAME against 36 supported services: 15 Azure services, AWS S3 and Elastic Beanstalk, and 19 other platforms, including WordPress.com and Ghost.
The evidence depends on the service. For supported Azure services, a target missing from DNS indicates risk. For S3, the scanner looks for a response such as NoSuchBucket. A wildcard that returns a CNAME is checked the same way, and a finding applies to every name beneath it.
Every detected risk receives a red Takeover risk marker, including on free scans. Paid plans also name the service each affected subdomain points to.
Screenshots and web responses
While takeover checks run, a headless browser visits each host with an open web port and captures a screenshot at 1280 by 720. It also records the HTTP status and page title for the Web column.
Hosts that lead to the same page share a screenshot. An existing screenshot for a host and port is kept, and new screenshots may continue arriving briefly after the scan finishes.
After the first scan: changes and monitoring
The first scan establishes a baseline. Each re-scan checks the previous results and compares them with the new findings. The Changes tab shows new and removed subdomains, changes to addresses, CNAME records, hosting and services, and new takeover risks. Previous rows stay dimmed until they have been checked again.
Monitoring runs these re-scans daily, weekly or monthly. When something changes, SubAnalyzer sends one email with takeover risks first. You can monitor 1 domain for free, and paid plans support up to 10.
What a scan never does
SubAnalyzer examines your domain from the internet using DNS queries, connections to common ports and web page requests. It never logs in, attempts an exploit or changes anything.
Scan your domain
Start a free scan to see the subdomains, services, hosting providers and takeover risks SubAnalyzer finds.