Skip to content
SubAnalyzer

Frequently asked questions

Scans, takeover risks, monitoring and plans

How do I find all subdomains of a domain?
Enter the domain in the scan box to search for its subdomains. A light scan reads public sources such as certificate transparency logs and passive DNS data. A deep scan then asks live DNS for likely names, looks up SRV records and tries a zone transfer, and keeps the guessed names that resolve. No tool can promise every subdomain, because a name that never appears in public DNS, certificates or datasets can stay hidden.
What is a subdomain finder?
A subdomain finder, also called a subdomain scanner or subdomain checker, is a tool that discovers the subdomains associated with a domain name. It scans public records, DNS data and other sources to reveal subdomains like mail.example.com or dev.example.com that may not be immediately visible.
Does SubAnalyzer check for subdomain takeovers?
Yes. Every scan checks each subdomain's CNAME against cloud and SaaS services where an unclaimed name can be registered by someone else, including Azure services, AWS S3 and Elastic Beanstalk. A free scan flags the subdomains at risk. Paid plans name the service each one is exposed to, which is what tells you how to fix it. Our guide on how dangling CNAME records enable subdomain takeover explains the risk.
Can SubAnalyzer alert me when my subdomains change?
Yes, on a paid plan. SubAnalyzer re-scans up to 5 monitored domains every day and sends one email when something changes: new or removed subdomains, DNS and CNAME changes, owner and cloud changes, open ports, and takeover risks, which are listed first. You choose which changes trigger an alert.
Is SubAnalyzer free?
Yes. Every scan is free, with light and deep discovery, every subdomain it finds, screenshots and change history, up to 2 scans a day. Paid plans start at $12.50 a month, billed yearly, and add unlimited scans, monitoring with email alerts, takeover detection that names the exposed service, and export to CSV/JSON. Visit our pricing page for details.
How many emails will monitoring send?
At most one a day, and only when something changed, with takeover risks at the top. Quiet days send nothing. You choose which kinds of change count for each domain, and you can turn email off for any domain from the email itself.
What does a subdomain scan show?
Each scan lists the subdomains it found with their IP addresses, network owner, open ports and HTTP status codes, plus the cloud provider when it is a major cloud, and checks every CNAME for takeover risk. Web-facing subdomains also get a screenshot and page title. See which ports SubAnalyzer scans for the full list.
Do I need to install anything or give you DNS access?
No. SubAnalyzer works from the outside. Enter a domain and the results appear in your browser. There are no agents to install and no DNS or cloud credentials to share.
Is subdomain scanning legal?
Finding subdomains starts with public data such as DNS records and certificate transparency logs. The deep scan also asks DNS about likely names, and a scan connects to common ports and loads web pages the way any visitor would, from SubAnalyzer's own servers. It never attempts an exploit and installs or changes nothing. The rules differ by country, so scan domains you own or have permission to test.
What is the difference between a light scan and a deep scan?
A light scan uses passive sources like certificate transparency logs to quickly find known subdomains. A deep scan adds active techniques such as DNS brute-forcing, SRV record lookups and zone transfer attempts to uncover subdomains that passive methods miss. Read our light scan vs deep scan comparison for details.

Something else on your mind? Contact us.