Enter a domain and see what the public internet already knows about it — subdomains sitting in certificate transparency logs, routes remembered by web archives, paths published in robots.txt and sitemaps.
api.example.com crt.shstaging.example.com certspotter/admin robots.txt/old-pricing wayback
The problem Every certificate you issue is logged publicly, forever. Staging hosts, internal tools and forgotten subdomains end up in those logs and in web archives, and most owners never look — the exposure is public by design, but invisible in practice.
The solution Read the public record instead of attacking the host. Subdomains come from crt.sh and Cert Spotter, then get DNS-verified; routes come from archives, robots.txt and sitemaps, with an optional crawl. Every result carries the source it came from, so nothing is a guess.
Go 1.23 · React · Certificate Transparency · Wayback · No database