# Findomain: certificate transparency logs instead of brute force

> A Rust subdomain enumerator built on CT logs and 54 passive APIs, with a version 11 rewrite that handed scanning to external tools.

**Findomain/Findomain** — The fastest and complete solution for domain recognition. Supports screenshoting, port scan, HTTP check, data import from other tools, subdomain monitoring, alerts via Discord, Slack and Telegram, multiple API Keys for sources and much more.

- Repository: https://github.com/Findomain/Findomain
- Website: https://findomain.app
- Stars: 3,797 · Forks: 398
- Language: Rust
- License: GPL-3.0
- Published: 2026-10-06 · Updated: 2026-10-06 · Language: en
- Canonical page: https://hysenlabs.com/projects/findomain-findomain

## Subdomain discovery without a wordlist

Findomain describes itself as a complete solution for domain recognition and subdomain enumeration, written in Rust and licensed GPL-3.0. The method it names in its own heading is Certificate Transparency: every certificate a certificate authority issues is recorded in a public append-only log, so a subdomain shows up there the moment someone requests a certificate for it, whether or not the name resolves in DNS.

The README puts the claimed speed next to the method. A benchmark table in the README reports 84110 subdomains for aol.com in 5.5 seconds, measured with Linux's `time` command on a BlackArch KVM guest, with the host, kernel, CPU and memory configuration printed above the table so the conditions are checkable. The authors also note that resolution is parallelised, claiming roughly 3.5k subdomains per minute under good network conditions, and that the ceiling on any target is about 15 seconds when an API times out.

Those are the project's numbers rather than independent verification, and the measurement conditions are a modest virtual machine rather than dedicated hardware. Still, the mechanism is sound: reading a log someone else already wrote is a different class of operation from generating and testing candidate names.

## Fifty-four sources, all of them documented formats

The source list is long and worth reading as a design statement. Findomain states it queries 54 passive sources, that each one parses a documented data format, JSON in almost every case, and that there is no HTML scraping anywhere. The reasoning given is practical: a redesigned web page can never quietly turn results into noise. Paginated APIs are walked to the last page.

The list spans certificate transparency sources such as `Crt.sh`, Facebook CT and DigiCert CertCentral, commercial intelligence APIs like Ahrefs, SecurityTrails, Censys and Shodan, free passive DNS services like BufferOver and HackerTarget, and archives such as CommonCrawl, Arquivo.pt and the UK Web Archive. Markers in the list indicate which sources need an account or a paid key.

DNS over TLS support and specific IPv4 or IPv6 queries sit alongside this, as does the ability to report the IP address behind each subdomain for later analysis. Wildcard detection is listed too, which matters more than it sounds: without it, a DNS provider that resolves any name hands you thousands of false positives that look exactly like real findings.

## What version 11 removed and why

The 11.0.0 beta releases are the most informative thing in the repository, and the breaking changes are about subtraction. The codebase was rewritten around an immutable configuration and a per-target session, the passive source set grew from 14 to 54, and the scanning stages that used to be built in are now delegated to the tools that specialise in them.

Concretely, `--external-subdomains` is gone. Findomain no longer runs amass or subfinder on your behalf. The stated reasoning is that you run them yourself and import the result, which also lets you keep their own flags, which is a fair argument for anyone who has ever fought a wrapper's opinion about scan scope. SQLite also became the default monitoring database, with Postgres still available.

The current manifest reflects that shape. It is not published to crates.io, because the resolver and HTTP checker come straight from git:

```
rusolver = { git = "https://github.com/Edu4rdSHL/rusolver", tag = "0.11.0" }
fhc = { git = "https://github.com/Edu4rdSHL/fhc", tag = "0.10.0" }
```

The crate declares `rust-version` of 1.88, edition 2021, and the version field reads 11.0.0-beta.2. So building from a tag or using a release binary is the path, rather than installing from crates.io.

## Monitoring, imports and configuration formats

Passive enumeration is a snapshot; monitoring is how you find out that something changed. Findomain supports subdomain monitoring with findings pushed to Discord, Slack or Telegram webhooks, and stores what it has seen so previous discoveries can be queried directly. The manifest shows both storage engines present, `rusqlite` with the bundled feature and `postgres`, plus `lettre` for building and sending the emailed report.

Imports matter because the version 11 changes make them load-bearing rather than optional. The feature list includes the ability to import and work with data discovered by other tools, and a separate section of the README is devoted to it. If you are running amass and subfinder yourself, feeding their output back in is now the normal path rather than an alternative.

Configuration is unusually accommodating: the tool reads TOML, JSON, INI or YAML through the `config` crate, and the repository ships a `config_examples/` directory for them. Targets come from an argument or a file, output can go to a single file or automatically named TXT files, and there is a quiet mode for scripted runs. Build instructions, including cross-compiling for other architectures, live under `docs/INSTALLATION.md` rather than in the README.

## The repository as a package manifest

Reading `Cargo.toml` tells you more about the tool's design than the feature list does. HTTP work goes through `reqwest` with blocking, json and gzip enabled. DNS resolution is `hickory-resolver`, with the `rusolver` git dependency layered on top for bulk work. `rayon` handles parallelism, and `tokio` and `futures` cover the async side.

The rest is worth noting for what it implies. `headless_chrome` is a dependency, which is how the screenshotting feature works: a real browser, not an HTTP probe, so you get a rendered image of the page. `postgres-native-tls` and `native-tls` cover encrypted database and webhook connections. `quick-xml` handles XML, and `libc` is pulled in on unix targets for one specific reason, restoring the default SIGPIPE disposition because the crate was already in the tree.

The tree is compact and conventional: `src/`, `tests/`, `docs/`, `docker/`, `Utilities/`, `config_examples/`, a `findomain.1` man page, `SECURITY.md` and a rustfmt config. There is a `docker/` directory, though the beta release notes say the beta is not pushed to Docker Hub. The repository is not archived, the last push was 2026-09-17, and with 3794 stars and only 6 open issues it is one of the quieter bug bounty tools in terms of tracker noise.

## Conclusion

Findomain's real argument is about what you do not have to do. Certificate transparency is a public, append-only log of every certificate a CA issued, so subdomains appear there whether or not anyone pointed DNS records at them, and no wordlist guessing is involved. Version 11 then made the opposite trade on scanning: amass, subfinder and nuclei are no longer bundled, which makes the tool smaller and its output easier to reason about but pushes orchestration onto you. What is left is a fast, well-documented passive enumerator with TOML, JSON, INI and YAML config, SQLite or Postgres storage for monitoring, and webhook delivery to Discord, Slack and Telegram. Start with the free build and the passive source list before deciding whether monitoring is worth the API keys.

## FAQ

### What is the best subdomain finder?

There is no single answer, but Findomain's approach is distinctive: it reads certificate transparency logs plus 54 passive APIs rather than brute-forcing a wordlist, which is why its own benchmark reports tens of thousands of subdomains in seconds. It also supports bruteforce as an option, imports results from other tools, and since version 11 it expects you to run amass, subfinder and nuclei yourself rather than bundling them.

### What is the best tool for searching for domain names?

For subdomain discovery against domains you are authorised to test, Findomain covers passive sources, Certificate Transparency logs and bruteforce in one binary, with monitoring and webhook alerts on top. If you only need to look up who owns a single domain, that is a WHOIS or registrar question rather than something this tool answers.

### How do I install Findomain 11?

Findomain 11 is a pre-release, so it is not marked as latest and does not reach Docker Hub or the distribution packages, which track stable tags. Take the binary from the release assets or clone the repository at the tag and build it with cargo, which needs a Rust toolchain at version 1.88 or newer.

## Sources

- [Findomain/Findomain on GitHub](https://github.com/Findomain/Findomain)
- [License: GPL-3.0](https://github.com/Findomain/Findomain/blob/master/LICENSE)
- [Project website](https://findomain.app)
- [README](https://github.com/Findomain/Findomain/blob/master/README.md)
- [Releases](https://github.com/Findomain/Findomain/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/findomain-findomain
