Subfinder Docs

Passive subdomain enumeration

Every subdomain on record. Zero packets to the target.

Type a domain and browse every hostname the index has seen under it, oldest first, with the date each name first appeared. A lookup reads the committed index. The domain you look up is never probed and never learns you looked.

Hostnames on file

--

reading the index

Apexes covered

--

distinct registrable domains

CT logs represented

--

counted from ingest evidence

Last source ingest

--

recorded in the catalog

Using it

One call, no key.

One domain in, hostnames out, from a shell or from anything that speaks HTTP. There is no key to request and no account to make. A domain with nothing on file answers 200 with an empty body, so a miss is cheap to handle.

curl -s "$SUBFINDER/v1/search?apex=example.com"

curl -s "$SUBFINDER/v1/search?apex=example.com&format=json&dates=1" \
  | jq -r '.[] | "\(.first_seen // "undated")\t\(.sub)"'

What the index is built from

The Chrome and Apple log lists identify CT logs the ingestion pipeline can read through ct/v1/get-entries. The Geomys archive covers retired logs. Zone data from IANA, CISA, and registries that publish openly, plus Common Crawl, add domains that certificates alone can miss. Searches read only data already committed to the index.

Each name keeps three fields. Hostname, apex, and the earliest date any source saw it. No certificate bodies, no serial numbers, no issuer chains.

Reading it without a browser

For setup, API details, and source notes, open the full docs .

Search

GET /v1/search?apex=example.com

One hostname per line. Add &format=json for an array, &dates=1 to attach each first-seen date. Rows come back oldest first, undated names last.

Index size

GET /v1/stats

Counts for the whole index and the timestamp of the last ingest run. It costs nothing against the search allowance, so the counter above can keep itself current.

Allowance

X-RateLimit-Remaining

1000 successful reads per IP per UTC day, shared with the MCP endpoint. Every response carries the limit, what is left, and the reset time. A spent allowance returns 429 with Retry-After.

MCP

POST /mcp

One streamable HTTP tool called search. Pass a domain, get an array of hostnames. Same allowance as the HTTP route, same refusal to probe.

The record

Copy page Download page