All posts
Subdomain Explorer — Certificate Transparency OSINT
August 24, 2026 · DevTools
subdomains
ct
osint
security
The Subdomain Explorer searches Certificate Transparency logs through crt.sh. It lists hostnames that appeared on publicly logged certificates — passive recon, not port scanning.
How to use
- Enter a root domain you are authorized to assess
- Review the deduplicated hostname list
- Validate live names with DNS Lookup
Limits
- Internal hostnames never certificated will not appear
- Historical certs may list retired hosts
- When crt.sh is down (HTTP 502), retry later — this is an upstream outage, not your domain
Ethics
Use only for domains you own or have written permission to investigate.