A.R.P. SyndicateARPSyndicate

Subdomain Center

The world's largest Subdomain & Shadow IT Intelligence database.

10B+
Subdomains
1B+
Domains
100k+
TOR Domains
500M+
Brands

Freely accessible — up to 500 results per query, in random order. Add an API key for full, sorted results.

Subdomain Center scours the web, gathering and interpreting data from across the Internet to map the world's shadow IT. Three engines: cuttlefish finds subdomains of a domain, octopus clusters a brand, and ammonites hunts a keyword across every host. Query it from your terminal with the puncia CLI, or build on it via the API documentation.
We do not take responsibility for any malicious use of this data; such use is entirely unintended.

Measured against every other free source

1,594
subdomains returned by Subdomain Center
774
by RapidDNS, the runner-up

In an independent subdomain-enumeration benchmark against delta.com, Subdomain Center returned more than double the next-best free API. The reviewer noted the data contains “strange and complex (but totally valid) subdomains that don't seem to show up anywhere else” — hosts that brute-force and Certificate Transparency alone do not surface. Read the benchmark.

The same dataset powers subdomain discovery inside BBOT, theHarvester and OWASP Amass.

How the data is built

Most subdomain tools resolve a wordlist or replay Certificate Transparency logs. Both methods only find hosts that someone already guessed or that issued a public certificate. Subdomain Center starts from the open web instead.

Web-scale crawlingApache Nutch continuously crawls and extracts hostnames from live page content, headers and linked assets.
Certificate TransparencyCalidog Certstream ingests newly issued certificates in real time, catching hosts the moment they get a cert.
Embedding-based correlationEmbedding models cluster hosts by semantic and structural similarity, surfacing naming patterns a wordlist would never contain.
Proprietary discoveryAdditional in-house tooling fills gaps the three public methods leave behind.

Because discovery does not depend on DNS brute force, results include hosts that never resolve publicly, sit behind a reverse proxy, or were never guessable in the first place.

Common questions

Can it find subdomains behind Cloudflare?

Yes. Subdomain Center does not discover hosts by resolving DNS, so a Cloudflare-proxied record does not hide a hostname from it. Hosts are found through web-scale crawling, Certificate Transparency and embedding-based correlation, all of which observe a hostname's existence independently of what its DNS record currently points at.

What you get back is the hostname. Subdomain Center does not attempt to unmask the origin IP address behind a proxy, and does not perform any active scanning against a target.

Is Subdomain Center free? What are the limits?

The API is free and needs no account, no signup and no API key. A free query returns up to 500 results in random order. An API key removes the 500-result cap and returns the full result set, sorted. Same data either way — the key changes completeness, not quality.

How is this different from Subfinder, Amass or crt.sh?

Those are collectors — they query sources and aggregate answers. Subdomain Center is one of the sources they query; BBOT, theHarvester and Amass all integrate it. Running a collector gives you the union of its configured sources. Querying here gives you the dataset those collectors are pulling from, without configuring anything.

What can I use it for?

Attack surface discovery and shadow IT mapping on infrastructure you own or are authorised to assess; brand monitoring; typosquat and impersonation discovery via the octopus engine; and reconnaissance during authorised security testing.

How current is the data?

Continuously updated. Certificate Transparency ingestion is real time, so hosts that issue a certificate appear quickly. Crawl-derived hosts appear as the crawler reaches them.

Can I query it from the command line?

Yes — the puncia CLI wraps both Subdomain Center and Exploit Observer. The API documentation covers direct HTTP access, and browser extensions are available for Chrome and Firefox.

Premium access

Need full, sorted results, higher limits, or bulk access? Get an API key.

API key

Unlocks full, sorted results (no 500-cap). Sent as an X-API-Key header, stored in your browser only.