subdomain tool
Find the subdomains a domain is using
Look up which subdomains of a domain resolve, using public DNS.
Subdomain Finder asks public DNS which names exist under a domain, so you can see the hosts a site actually uses — mail, docs, an API, staging, and whatever else is published.
That is useful for auditing what your own infrastructure exposes, and for understanding how someone else's site is put together from the outside.
What it does
Public DNS only
Lookups go through ordinary resolvers, so nothing is scanned, probed, or exploited.
Common names first
The usual suspects — www, mail, api, docs, staging — are checked alongside the domain's own records.
Works on any domain
Point it at your own site to audit what you expose, or at a public one to understand its layout.
No sign-up
It runs in the browser against public resolvers, with nothing to install.
How to use Subdomain Finder
- Enter the domain you want to inspect.
- Run the lookup and read which names resolve.
- Use the results to review what your own domain publishes, or to understand another site's structure.
Questions about Subdomain Finder
Is this legal?
Querying public DNS for names under a domain reads information that is already public. Use it on your own infrastructure or for research — not to attack anything.
Why are some subdomains missing?
Only names that resolve publicly will show up. Internal hosts, wildcard-only setups, and names behind a private resolver stay invisible.
Does it find every subdomain?
No. Any enumeration can only guess and check names, so treat what it returns as a partial picture rather than a full inventory.
More tools in the directory
Every tool here is free and needs no account. See the full tools index, or how many people are using them.