Subdomain Finder
Every certified subdomain of a domain, with certificate history, DNS and a live HTTPS check.
Pay per result on Apify. Runs that return nothing cost nothing; Apify's free plan includes $5 of usage a month, and Apify Bronze, Silver and Gold subscribers get 10%, 20% and 30% off.
Certificate Transparency logs record every certificate ever issued for a domain, which makes them the most complete public list of a company's hostnames. This Actor folds that history into one row per name: how many certificates, when it first and last appeared, every issuing authority, when the newest certificate expires and whether any were revoked.
Then it checks reality: A, AAAA and CNAME records for each name, and optionally an HTTPS request that records the status code, final URL, page title and server header. The source is SSLMate's certspotter — 0.5 seconds per domain against crt.sh's 13 in testing, and 60 hostnames found where crt.sh's usual query returned 25.
What you get
- • Certificate history per hostname
- • DNS resolution and a resolves filter
- • Optional HTTPS check with title and status
- • Wildcards flagged, never counted as hosts
- • Monitored daily
Typical uses
- • Mapping your own public attack surface
- • Finding forgotten staging and admin hosts
- • Certificate expiry and issuer inventory
- • Watching a domain for new subdomains
Output
| domain, hostname, isWildcard | The name and where it came from |
| certCount, firstSeen, lastSeen, lastIssuer, issuers, certExpiresAt, certRevoked | Certificate history |
| resolves, ips, ipCount, cname | What DNS says today |
| httpStatus, httpUrl, httpTitle, httpServer | What answers over HTTPS |