
The fastest and complete solution for domain recognition. Supports screenshoting, port scan, HTTP check, data import from other tools, subdomain monitoring, alerts via Discord, Slack and Telegram, multiple API Keys for sources and much more.

The complete solution for domain recognition. Supports screenshotting, port scanning, importing data from other tools, subdomain monitoring, and more. Be alerted on your findings through services such as Discord, Slack, and Telegram. Multiple API Keys for sources and much more.
The following table demonstrates features that are available in the premium version (but not the free version) of Findomain. It aims to gives you an idea of why you should use Findomain and what it can do for you. The domain used for the test was aol.com. The details of the BlackArch virtual machine used in the test are outlined below:
Host: KVM/QEMU (Standard PC (i440FX + PIIX, 1996) pc-i440fx-3.1)
Kernel: 5.2.6-arch1-1-ARCH
CPU: Intel (Skylake, IBRS) (4) @ 2.904GHz
Memory: 139MiB / 3943MiB
The tool used to calculate the time was Linux's time command.
| Enumeration Tool | Search Time | Total Subdomains Found | CPU Usage | RAM Usage |
|---|---|---|---|---|
| Findomain | real 0m5.515s | 84110 | Very Low | Very Low |
Summary: 84110 subdomains in 5.5 seconds.
--threads option.See Subdomains Enumeration: what is, how to do it, monitoring automation using webhooks and centralizing your findings for a detailed guide, including real-world examples, of how to get the most out of the tool.
Findomain uses Certificate Transparency logs and well-tested APIs to find subdomains. This method makes the tool much faster and more reliable than alternatives. If you want to know more about Certificate Transparency logs, read https://www.certificate-transparency.org/
Findomain queries 54 passive sources. Every one of them parses a documented data format, JSON in almost every case: there is no HTML scraping anywhere, so a redesigned web page can never quietly turn results into noise. Paginated APIs are walked to the last page.
**********************************************************************************Any source can be turned off with --exclude-sources, for example
--exclude-sources wayback,commoncrawl.
Working with other tools
Findomain reads the results of any other enumerator through
--import-subdomains, which accepts as many files as you care to give it: