Passive subdomain enumeration
Every subdomain on record. Zero packets to the target.
Type a domain and browse every hostname the index has seen under it, oldest first, with the date each name first appeared. A lookup reads the committed index. The domain you look up is never probed and never learns you looked.
Hostnames on file
--
reading the index
Apexes covered
--
distinct registrable domains
CT logs represented
--
counted from ingest evidence
Last source ingest
--
recorded in the catalog
Names on file
Names first logged, by year
Records already on hand
Using it
One call, no key.
One domain in, hostnames out, from a shell or from anything that speaks HTTP. There is no key to request and no account to make. A domain with nothing on file answers 200 with an empty body, so a miss is cheap to handle.
curl -s "$SUBFINDER/v1/search?apex=example.com"
curl -s "$SUBFINDER/v1/search?apex=example.com&format=json&dates=1" \
| jq -r '.[] | "\(.first_seen // "undated")\t\(.sub)"'
What the index is built from
The Chrome and Apple log lists identify CT logs the ingestion pipeline can read through ct/v1/get-entries. The Geomys archive covers retired logs. Zone data from IANA, CISA, and registries that publish openly, plus Common Crawl, add domains that certificates alone can miss. Searches read only data already committed to the index.
Each name keeps three fields. Hostname, apex, and the earliest date any source saw it. No certificate bodies, no serial numbers, no issuer chains.
Reading it without a browser
For setup, API details, and source notes, open the full docs .
Search
GET /v1/search?apex=example.com
One hostname per line. Add &format=json for an array, &dates=1 to attach each first-seen date. Rows come back oldest first, undated names last.
Index size
GET /v1/stats
Counts for the whole index and the timestamp of the last ingest run. It costs nothing against the search allowance, so the counter above can keep itself current.
Allowance
X-RateLimit-Remaining
1000 successful reads per IP per UTC day, shared with the MCP endpoint. Every response carries the limit, what is left, and the reset time. A spent allowance returns 429 with Retry-After.
MCP
POST /mcp
One streamable HTTP tool called search. Pass a domain, get an array of hostnames. Same allowance as the HTTP route, same refusal to probe.