subdomain_finder
Find all subdomains of a domain from Certificate Transparency logs, then resolve DNS to separate live hosts from dead records.
Instructions
Subdomain Finder enumerates every subdomain of a domain from Certificate Transparency logs (crt.sh, Cert Spotter) and resolves each one — one row per subdomain, no proxies needed. Billed to your own Apify account: ~$0.0005 per result (Apify free-plan price, lower on paid plans).
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| domains | Yes | Domains — Enter the root domains to enumerate subdomains for, e.g. apify.com. Bare domains and full URLs both work — https://www.apify.com/pricing is reduced to apify.com. One row is returned per subdomain found. Example: ["apify.com"]. | |
| resolveDns | No | Resolve DNS — Turn this on to look up an A record for every subdomain found, so you can tell live hosts from dead certificate records. Costs one extra DNS query per subdomain and fills in resolves, ipv4 and cname. Turn it off for a pure certificate list. | |
| includeWildcards | No | Include wildcard names — Turn this on to also return wildcard certificate names such as *.example.com. They cannot be resolved, so they are excluded by default. | |
| maxSubdomainsPerDomain | No | Max subdomains per domain — Enter the maximum number of subdomains to return per domain, e.g. 500. Big brands have thousands of certificate names; when the cap is hit the subdomains with the most recently issued certificates are kept. |