Attack surface

Subdomain discovery

Every subdomain that has ever had a public certificate is listed in public logs. We show you what anyone can find.

Check this on your own domain now. It is free with a DomainGuard account, reads only public records, and gives you a report you can send to whoever runs your website.

What we look at

We search Certificate Transparency logs for certificates issued to names under your domain.

Why it matters to your business

Old staging sites, forgotten portals and test servers keep running long after anyone remembers them, and attackers read these same logs to find them. A subdomain pointing at a service you cancelled can be taken over and used to host a phishing page under your name.

How to fix it

  1. Go through the list and confirm you still own and use each name.
  2. Delete DNS records for anything you have retired, especially CNAMEs pointing at cloud services you no longer pay for.

If you would rather not touch DNS or server settings yourself, forward this page and your report to whoever manages your website, or ask us to do it.

Keep an eye on it

A one-off check tells you how things stand today. On Starter and up, DomainGuard re-checks the domains it watches every day and alerts you in the app when something important changes, so you hear about it before a customer does.