About SubDoms

We are building the most comprehensive subdomain intelligence platform on the internet. Our mission is to give security teams complete visibility into their organization's external attack surface, one subdomain at a time.

2.4B+
Subdomains Indexed
18M+
Domains Scanned
12K+
Active Users
47
Data Sources

Our Story

SubDoms was born from a simple frustration: existing subdomain discovery tools were either too slow, too inaccurate, or too expensive for the average security professional to use effectively. Our founding team of penetration testers and security engineers had spent years relying on a patchwork of open-source scripts, manual DNS queries, and expensive commercial platforms that still left blind spots in their reconnaissance workflows.

In early 2024, we decided to build something better. We started by aggregating data from Certificate Transparency logs, which provide a public record of every SSL/TLS certificate ever issued. This gave us a foundational dataset of hundreds of millions of subdomains. From there, we layered on passive DNS data from global sensor networks, results from intelligent dictionary-based brute-forcing, web scraping of search engine caches, and real-time zone transfer detection.

The result is a platform that combines the breadth of passive reconnaissance with the depth of active scanning. SubDoms does not just find subdomains; it enriches each result with IP resolution data, HTTP response codes, technology fingerprints, WHOIS information, and vulnerability indicators. When our engine detects a subdomain pointing to an unclaimed cloud resource or an expired third-party service, it flags it immediately as a potential takeover target.

Today, SubDoms serves security teams at startups, enterprises, government agencies, and bug bounty hunters around the world. Our platform processes over 500 million DNS queries daily across our distributed infrastructure, and our index grows by approximately 4 million new subdomains every week. We are committed to keeping a generous free tier available so that independent researchers and small teams can benefit from the same intelligence that large organizations rely on.

We believe that visibility is the foundation of security. You cannot protect what you cannot see. Every forgotten staging server, every abandoned development environment, and every misconfigured third-party integration represents a potential entry point for attackers. SubDoms exists to eliminate those blind spots and give defenders the complete picture they need to secure their perimeter.

Our Values

Transparency

We believe security tools should be transparent about their methods and data sources. We document our enumeration techniques openly and explain exactly how our scoring algorithms work.

Responsible Disclosure

We follow responsible disclosure practices. When our scanners identify critical vulnerabilities, we work with affected organizations privately before publishing any data. Ethical conduct is non-negotiable.

Community First

The security community built the tools and techniques we rely on. We give back by maintaining open-source projects, publishing research, and offering free access to independent researchers.

Continuous Innovation

Attack surfaces evolve constantly. We invest heavily in research and development to stay ahead of new infrastructure patterns, cloud services, and evasion techniques used by adversaries.

Our Journey

Q1 2024

Founded

SubDoms founded by a team of penetration testers frustrated with existing tools.

Q3 2024

CT Log Integration

Integrated Certificate Transparency log monitoring covering 100+ log servers.

Q1 2025

API Launch

Released public REST API with support for bulk queries and webhook alerts.

Q3 2025

1 Billion Records

Crossed 1 billion indexed subdomains with 99.7% accuracy rate.

Q1 2026

Takeover Detection

Launched automated subdomain takeover detection across 80+ cloud providers.

Meet the Team

AK

Alex Khoury

Co-Founder & CEO

Former penetration tester with 12 years of experience in offensive security and red team operations.

SR

Sarah Richter

Co-Founder & CTO

DNS infrastructure specialist and former engineer at a major cloud provider. Architect of our scanning engine.

MZ

Marcus Zhang

Lead Engineer

Full-stack engineer specializing in distributed systems and high-throughput data processing pipelines.

LP

Lina Petrova

Security Researcher

Published researcher in subdomain takeover techniques. Top 100 bug bounty hunter on major platforms.

Ready to See Your Attack Surface?

Start scanning domains for free and discover subdomains you never knew existed.

Launch Scanner