Blog

Subdomain enumeration, DNS security, and recon, explained

Written by the people building the tool. Every guide links back to something you can actually run, not just read about.

Subdomain takeover guide thumbnail
What Is a Subdomain Takeover? How to Check and Fix It
A dangling DNS record is one of the easiest, most overlooked ways into a company's infrastructure. Here's exactly how the attack works and how to check your own domains for it, free, in under a minute.
Why crt.sh times out thumbnail
Why crt.sh Times Out (and the 7 Sources That Do Not)
crt.sh is slow, overloaded, or down more often than people admit. Here's why, and how merging 7 sources instead of relying on one fixes it.
Is subdomain enumeration legal thumbnail
Is Subdomain Enumeration Legal? A Straight Answer
A plain-language look at when subdomain enumeration is legal, the difference between passive and active recon, and how scope and authorization change the picture.
How to find every subdomain thumbnail
How to Find Every Subdomain of a Domain (5 Methods Compared)
Five real methods for finding a domain's subdomains, compared on speed, coverage, and setup: Certificate Transparency, passive DNS, brute-force, dorking, and all-in-one tools.
Certificate Transparency logs explained thumbnail
Certificate Transparency Logs Explained for Beginners
What Certificate Transparency logs are, why they exist after the 2011 DigiNotar breach, how anyone can query them, and why they matter for subdomain discovery.
Passive DNS versus active reconnaissance thumbnail
Passive DNS vs. Active Reconnaissance: What's the Difference
Passive DNS and active reconnaissance find subdomains in very different ways, with different stealth, speed, and legal tradeoffs. Here is when to use each.
SPF DKIM DMARC DNSSEC checklist thumbnail
SPF, DKIM, DMARC, and DNSSEC: A Practical Checklist
What SPF, DKIM, DMARC, and DNSSEC actually protect against, a practical checklist for verifying each, and why forgotten mail-sending subdomains slip through.
Bug bounty recon 101 thumbnail
Bug Bounty Recon 101: Subdomain Enumeration Methodology
A practical subdomain enumeration methodology for bug bounty hunters: scope review, passive collection, active validation, live-host filtering, and prioritization.
Best free subdomain finders 2026 thumbnail
Best Free Subdomain Finders in 2026 (Tested, No Signup)
A tested comparison of free subdomain enumeration tools in 2026: signup requirements, speed, takeover detection, live-status checks, and export options.
Attack surface management for small teams thumbnail
Attack Surface Management for Small Teams (No Enterprise Budget)
What attack surface management means, why small teams need it, and a lightweight, free-tool routine for tracking subdomains, takeovers, and exposed panels.
Detect a dangling CNAME thumbnail
How to Detect a Dangling CNAME Before an Attacker Does
What a dangling CNAME is, how subdomain takeover works, common vulnerable services, and a step-by-step manual and automated detection process.
Cloudflare protected status thumbnail
Cloudflare Is Blocking My Scanner: What "Protected" Status Means
Why a subdomain returning a Cloudflare challenge page is not the same as a dead subdomain, and how to correctly interpret a protected status.