Subdomains of ledher.org.
Every subdomain that public records give away, from certificate logs to the web archive, with where each one points today.
Looking up…
Where the names come from.
- Certificate logs. Every certificate a public authority issues is logged with the names it covers. Hivex reads them through crt.sh and keeps each name with the end date of its latest certificate.
- The domain's own records. Mail servers, name servers, hosts named in the SPF record and common service records (
_autodiscover,_sip,_imaps…) often sit under the domain. - The site's certificate and the web archive. The names on the certificate the website serves, and the hosts the Internet Archive has crawled under the domain.
- Common names. About 180 names such as
www,mail,apiandstaging, skipped when a wildcard record makes every name answer.
Reading the list.
- A subdomain that answers resolves now: to addresses, or to an alias (CNAME) whose platform is named when Hivex knows it.
- Points nowhere means an alias to a name that no longer exists. If that service lets anyone register the name, a stranger could take the subdomain over: delete the record, or claim the name back.
- Names in certificates that no longer resolve were real once; old ones are usually harmless, but check that nothing still links to them.
Questions people ask.
How does the subdomain finder work?
It reads certificate transparency logs through crt.sh, the domain's own mail, name server, SPF and service records, the certificate its website serves, and the Internet Archive's list of crawled hosts, then tries about 180 common names. Every name is then looked up in DNS, live.
Why are subdomains public in certificate logs?
Browsers only trust certificates that were logged in public Certificate Transparency logs (RFC 6962), so every name on a certificate can be read by anyone. A wildcard certificate (*.example.com) covers names without listing them.
Can it find every subdomain?
No tool can without the zone itself. A name that never had its own certificate, was never crawled and is not a common word stays hidden. Hivex does not try zone transfers or guess beyond its short list.
What is a dangling CNAME?
A subdomain that is an alias for a name at a service (a cloud bucket, a hosting platform) that no longer exists. If the service lets anyone create that name, a stranger can, and then serves pages on your subdomain. Remove the record when you stop using the service.
Does the search touch the subdomains themselves?
No. It reads public sources and asks DNS, so nothing reaches the subdomains' servers or their logs. The one exception is a short TLS handshake with the main website to read the names on its certificate.
What does a wildcard record change?
A record for *.example.com makes every name answer, so a guessed name proves nothing. The finder then skips guessing and marks hosts that only the web archive has seen as not confirmed.
Hivex index
Short names, still free to register.
Starting something new? Hivex keeps a live index of short, brandable .si names nobody has claimed yet, each checked with the registry.
From code, or an AI assistant.
Hivex's free JSON API and MCP server check domains, DNS and registration records from your own code or from AI assistants that speak MCP. No key needed.
More DNS tools
- DNS lookupAll records at once: A, AAAA, CNAME, MX, NS, TXT, CAA, SOA.
- MX lookupMail servers in priority order, the provider, SPF and DMARC at a glance.
- NS lookupName servers, the DNS host, SOA settings, and marketplace parking.
- TXT lookupSPF, DMARC, DKIM and verification tokens, joined and labelled.
- CNAME lookupThe full alias chain, the final addresses, and the platform behind it.
- CAA lookupAllowed certificate authorities, wildcard rules and report addresses.
- DNS propagation checker13 public resolvers side by side, with how long each keeps its copy.
- Reverse DNSThe PTR hostname of an IPv4 or IPv6 address, checked both ways.
- DNS health checkEvery name server asked directly: one report, every check.
- DNSSEC checkerDS, keys and validation: where the chain of trust holds or breaks.
- DNS historyPast IP addresses and hosts, from passive DNS.
- DNS setup helperThe records each platform asks for, checked live.
- Domain checkerIs a name free to register? Checked live on any extension.
Sources
- RFC 6962: Certificate Transparency
- RFC 4592: The role of wildcards in DNS
- crt.sh: certificate search by Sectigo
- Internet Archive: the Wayback CDX server API
- OWASP Web Security Testing Guide: test for subdomain takeover
By Hivex. Updated 11 October 2026. Names come from crt.sh, DNS and the Internet Archive and are checked live through Cloudflare's resolver; results are kept up to a day and the names you search are not stored.