Free Subdomain Discovery Scanner & Enumeration Tool
Subdomain enumeration is a critical part of security assessment and attack surface management. Forgotten or misconfigured subdomains can expose development environments, internal tools, and sensitive data. Our free subdomain scanner checks dozens of common subdomain prefixes against your domain, verifying DNS resolution and identifying potentially exposed subdomains that could pose a security risk.
What This Tool Checks
Comprehensive analysis powered by Vysiro's scanning engines
Common subdomain enumeration (50+ prefixes)
DNS resolution verification for each subdomain
A and AAAA record detection per subdomain
CNAME chain resolution and dangling CNAME detection
Web server response code checking
SSL certificate validation per subdomain
Wildcard DNS detection
Exportable subdomain inventory report
How It Works
Get results in seconds with our automated scanning process
Enter your root domain name in the scanner above
We query DNS for 50+ common subdomain prefixes (www, mail, api, etc.)
Each resolving subdomain is checked for A, AAAA, and CNAME records
We detect dangling CNAMEs and potential subdomain takeover risks
Results are categorized by risk level and record type
You receive a full subdomain inventory with security recommendations
Frequently Asked Questions
Everything you need to know about subdomain discovery scanner
What is subdomain enumeration?
Subdomain enumeration is the process of discovering subdomains associated with a root domain (e.g., finding mail.example.com, api.example.com under example.com). It is a standard security assessment technique used to map an organization's attack surface and identify potentially vulnerable assets.
Why should I scan for subdomains?
Forgotten subdomains can expose development environments, staging servers, internal tools, and legacy applications. Attackers routinely scan for subdomains to find unpatched services and misconfigured DNS records (like dangling CNAMEs) that enable subdomain takeover attacks.
What is a dangling CNAME?
A dangling CNAME occurs when a subdomain has a CNAME record pointing to a service (like a cloud provider, CDN, or SaaS platform) that is no longer active. Attackers can claim the abandoned service and serve malicious content on your subdomain. This is known as a subdomain takeover.
What subdomains does this tool check?
We check 50+ common prefixes including www, mail, ftp, api, cdn, dev, staging, test, admin, portal, vpn, remote, webmail, autodiscover, and many more. These cover the most commonly used subdomain patterns across organizations of all sizes.
Is subdomain scanning legal?
Querying public DNS records is legal and is done billions of times daily by DNS resolvers worldwide. Our tool performs standard DNS lookups on common subdomain prefixes. However, you should only scan domains that you own or have explicit authorization to test.
How can I protect against subdomain takeover?
Regularly audit your subdomains and remove DNS records pointing to decommissioned services. Monitor for dangling CNAMEs, use wildcard DNS carefully, and implement a process for cleaning up DNS when deprovisioning cloud resources. Vysiro provides continuous subdomain monitoring on paid plans.
Related Free Tools
Continue your domain security analysis
DNS Health
Full DNS configuration analysis and health scoring.
Use toolDNS Propagation
Check DNS record propagation across multiple global resolvers in real time.
Use toolTrustScore
Get an instant composite trust score (0-1000) across 29 security categories.
Use toolSSL Inspector
Analyze SSL/TLS certificates, expiration, and security configuration.
Use toolGo Beyond Free Checks
Get continuous monitoring, automated fixes, proof packs, and API access. Protect your domains with Vysiro's agentless attack-surface monitor.