Passive recon · 5 sources · client-side

Subdomain enumeration,
straight from the browser.

Pull subdomains from crt.sh, CertSpotter & HackerTarget in one shot — merged, de-duped, optionally resolved, and exportable.

Press Enter to run · toggle sources in the sidebar · authorized recon only

Subdomains
0
Resolved
0
Sources hit
0
Time
0s
Results
#SubdomainSourcesDNS / IP

Enter a domain and hit Enumerate to start passive recon.

For authorized security research & bug-bounty recon only. All lookups use public passive-DNS & certificate-transparency sources and run entirely in your browser — nothing is logged. Always stay within program scope.