Skip to content

Subfinder

Passive subdomain discovery through public sources

VerifiedOSINT· Email & DomainBeginnerMITOpen sourceEntry revised 30 Dec 2025
  • Linux
  • macOS
  • Windows
  • Kali
  • Docker
  • Source
This entry is thinner than the rest of the directory — missing sections are shown as such rather than filled with filler.Improve this pageContribute

Overview

4 commands documented

Subfinder assembles a domain's subname list from certificate transparency logs, search engines and data-source APIs — passively, meaning it does not poke your target. The list it produces is the input to every later step of an authorized review.

Supported platforms

6

Documented install or usage guidance

Learning curve

beginner

Difficulty of becoming productive, not of the underlying theory

Tags

subdomains, passive, cert transparency, attack surface

Dataset entry

subfinder.ts

Reviewed 2025-12-30

Installation

Grouped by platform. Elevation requirements are marked per method.

Homebrew

RecommendedHomebrew
brew install subfinder

Package availability follows your distribution and enabled repositories. Entry revised 30 Dec 2025 — confirm the current release on the project's own download page.

Commands

4 entries

Every command carries its purpose, an example where useful, and the limitations that change how you should read the output.

01Passive subname enumeration

bash

Queries all enabled sources and writes a deduplicated list.

subfinder -d example.org -o subs.txt -silent

02Force every source, including rate-limited ones

bash

`-all` is slower and more likely to be throttled, but finds names the fast sources miss.

subfinder -d example.org -all -timeout 8 -retries 2

03Keep only names that resolve

bash

Resolution filters historic log entries that no longer point anywhere.

subfinder -d example.org -recursive -resolve -o live.txt

Notes

  • `-resolve` touches DNS only — it does not open TCP connections to the hosts.

04Configure API keys for better coverage

bash

Sources like SecurityTrails, VirusTotal and Censys need credentials in the provider config.

$EDITOR ~/.config/subfinder/provider-config.yaml

Notes

  • Without keys, subfinder silently skips those sources, which is why two people's lists differ.

Common errors

Symptoms you will actually hit, with the cause and the legitimate fix.

Short list compared with a colleague's runCause 1/2

Possible causes

  • Missing provider keys and no `-all`.

Usual fix

Add keys, run with `-all -silent -o`, and keep both outputs to compare; log which sources were enabled.

Too many requests / source errorsCause 2/2

Possible causes

  • Repeat runs against rate-limited sources.

Usual fix

Cache and space out runs; `--provider` lets you query one source at a time.

Tips

  • Diff today's list against last month's. Newly appearing names are where surprises live.
  • Feed the output into httpx (with authorization) to learn which names actually serve HTTP.

Alternatives & comparisons

Not documented yet: amass. Request an entry and it will link up automatically.Request a tool

Side-by-side

References

Where to verify anything on this page. External links open in a new tab.

Found something wrong?Suggest an editMore in OSINT

Looking for alternatives?

theHarvester cover adjacent parts of the same job.

Compare side by side