crt.name

Search the subdomain index.

Give it an apex domain. You get every subdomain on file, plus the date each name first showed up.

Free · no token · 1000 requests per IP per day

How the index is built

Live CT. The index reads every usable CT log in Chrome's and Apple's programs as entries land: Static CT (Let's Encrypt Sunlight, Geomys, Cloudflare Raio) and legacy RFC 6962 (Google Argon, Sectigo, DigiCert). It parses each certificate in memory, pulls out the SAN hostnames, then throws the rest away.

Backfill. The live feed only sees forward, so most of the depth is history: retired CT logs replayed from the Internet Archive, plus Common Crawl, ICANN CZDS zone files, ProjectDiscovery Chaos, and HaGeZi DNS blocklists.

Active probing. A prober works through common hostnames against known apexes on a loop, and anything it turns up joins the same index.

Every name is normalized by apex. The index keeps three fields, (apex, subdomain, first-seen). It holds no certificate metadata and never deletes a name.

API

No token. 1000 requests per IP per day. Returns one subdomain per line by default. apex must be an eTLD+1; use ?format=json for JSON or &dates=1 to include first-seen dates.

GET /v1/find?q=loginclosed betaSearch all indexed names when you know part of a subdomain.
GET /v1/top?n=100closed betaApexes ranked by how many subdomains the index holds.
GET /v1/streamclosed betaServer-sent events for newly indexed names.

MCP

POST /mcp free · no token

Streamable HTTP endpoint for agent clients. Shares the free /v1/search budget (same counter). One tool, search: pass an apex, get every indexed subdomain. No token; free tier does not probe.

CLI

github.com/melvinsh/subfaster crt source · on by default

A subdomain enumerator that queries this index directly. Its crt source runs by default and takes no key, so subfaster -d namecheap.com reaches the free API on a fresh install.

Search a domain →