Certificate Transparency, passive DNS, and active brute-force merged into one list, then live status, takeover risk, ports, security headers, and real screenshots, streamed in as they're checked.
Seven sources merged into one list: crt.sh and CertSpotter read Certificate Transparency logs, the public record every CA publishes per certificate; HackerTarget, Wayback Machine, AlienVault OTX, and RapidDNS pull historical passive DNS; an active brute-force checks common subdomain names directly. Results are deduplicated, then checked live for status, redirects, TLS, and takeover risk.
Certificate Transparency logs are public data, every browser and CA already publishes them, so reading them is unconditionally legal. Checking whether a found host responds is normal, low-impact traffic, similar to visiting the page yourself. Anything further, port scans, header audits, takeover verification, should only run against domains you own or are authorized to assess.
Scanning, live status, and takeover detection are free with no signup. An account additionally unlocks the dashboard, favorites, scheduled monitors with alerts, DNS/TLS detail, port scanning, and real browser screenshots, the parts that cost more to run or reveal more about a target.
Yes, Certificate Transparency data is already public. Only run live checks, port scans, or security tests against domains you own or are authorized to assess.
crt.sh, CertSpotter, HackerTarget, Wayback Machine, AlienVault OTX, RapidDNS, and active DNS brute-force.
Yes, scanning, live checks, and takeover detection are free with no account. An account unlocks the dashboard, monitoring, and deeper recon tools.