Subdomain Center
The world's largest Subdomain & Shadow IT Intelligence database.
Freely accessible — up to 500 results per query, in random order. Add an API key for full, sorted results.
Measured against every other free source
In an independent subdomain-enumeration benchmark against delta.com,
Subdomain Center returned more than double the next-best free API. The reviewer noted the
data contains “strange and complex (but totally valid) subdomains that don't seem to
show up anywhere else” — hosts that brute-force and Certificate Transparency alone
do not surface.
Read the benchmark.
The same dataset powers subdomain discovery inside BBOT, theHarvester and OWASP Amass.
How the data is built
Most subdomain tools resolve a wordlist or replay Certificate Transparency logs. Both methods only find hosts that someone already guessed or that issued a public certificate. Subdomain Center starts from the open web instead.
Because discovery does not depend on DNS brute force, results include hosts that never resolve publicly, sit behind a reverse proxy, or were never guessable in the first place.
Common questions
Can it find subdomains behind Cloudflare?
Yes. Subdomain Center does not discover hosts by resolving DNS, so a Cloudflare-proxied record does not hide a hostname from it. Hosts are found through web-scale crawling, Certificate Transparency and embedding-based correlation, all of which observe a hostname's existence independently of what its DNS record currently points at.
What you get back is the hostname. Subdomain Center does not attempt to unmask the origin IP address behind a proxy, and does not perform any active scanning against a target.
Is Subdomain Center free? What are the limits?
The API is free and needs no account, no signup and no API key. A free query returns up to 500 results in random order. An API key removes the 500-result cap and returns the full result set, sorted. Same data either way — the key changes completeness, not quality.
How is this different from Subfinder, Amass or crt.sh?
Those are collectors — they query sources and aggregate answers. Subdomain Center is one of the sources they query; BBOT, theHarvester and Amass all integrate it. Running a collector gives you the union of its configured sources. Querying here gives you the dataset those collectors are pulling from, without configuring anything.
What can I use it for?
Attack surface discovery and shadow IT mapping on infrastructure you own or are authorised to assess; brand monitoring; typosquat and impersonation discovery via the octopus engine; and reconnaissance during authorised security testing.
How current is the data?
Continuously updated. Certificate Transparency ingestion is real time, so hosts that issue a certificate appear quickly. Crawl-derived hosts appear as the crawler reaches them.
Can I query it from the command line?
Yes — the puncia CLI wraps both Subdomain Center and Exploit Observer. The API documentation covers direct HTTP access, and browser extensions are available for Chrome and Firefox.
Premium access
Need full, sorted results, higher limits, or bulk access? Get an API key.