← Learn
Beginner · Mar 1, 2026

Subdomain Finder: Learning Enumeration

What subdomain enumeration is, why it matters in authorized recon, and how to study it ethically with labs — not by probing strangers on the internet.

Recon

Interactive lab · practice sample

Subdomain Finder

Practice on the fixed zone demo.lab. For live custom domains and your own API keys, use StreetLab.

Discovery sources

Finder console

Ready

Press “Find subdomains” to simulate discovery on demo.lab.

Subdomains expand the map — with permission.

A subdomain is a DNS name under a parent domain (for example api.example.com under example.com). Organizations often expose many of them: apps, staging, mail, CDNs, partner portals. In authorized security work, finding those names is part of attack-surface mapping: you cannot protect or assess what you have not listed.

This lesson is about concepts and ethics. It is not a live scanner for arbitrary third-party domains.

What "enumeration" means here

Enumeration is systematic discovery of names that resolve (or once resolved) under a scope you are allowed to study. Sources learners commonly discuss at a high level:

  • Certificate Transparency (CT) — public logs of issued TLS certificates often list hostnames.
  • DNS records & zone history — public datasets and historical DNS can surface old or alternate names.
  • Public documentation — job posts, changelogs, status pages, and developer docs sometimes leak hostnames.
  • Wordlists in a lab — guessing common labels (www, api, staging) against your own lab domain or a provider that explicitly allows testing.

Treat every name as a hypothesis until you verify it in scope. Finding a name is not the same as "owning" a host.

Ethics and authorization (non-negotiable)

  • Work only on systems you own, written permission, or explicit public programs (bug bounty / VDP) with clear rules.
  • Passive public data (CT, search indexes) is still bound by program rules and applicable law — do not harass, scrape abusively, or pivot into unauthorized active probing.
  • Do not point mass DNS or HTTP scanners at random internet domains "for practice." That is unauthorized recon.
  • Prefer disposable labs: local VMs, intentionally vulnerable apps, or commercial practice platforms that invite this work.

If a technique only works when consent is missing, it does not belong in your public notes as a how-to.

A learning loop that sticks

  1. Pick a lab domain you control (or a practice target that invites testing).
  2. Build a hostname list from allowed sources; write it down.
  3. Cross-check which names resolve and which serve HTTP (see the HTTP Status lesson).
  4. Document findings like a report: host, evidence source, date, next question.

Practice without crossing the line

Use the sample inventory demo on this page (demo.lab hosts only). Filter names, read the notes, and practice triage language — without sending packets to the public internet.

When you are ready for tooling on authorized scopes, study vendor docs for DNS lookup utilities and CT search interfaces in a controlled lab. Curiosity stays sharp; scope stays the brake.

Secure notes · XSS blocked

Lesson notes

Sign in through the Student Lab app to save plain-text notes. Markup and scripts are blocked in the browser and again on the server.

Checking session…

Subdomain Finder: Learning Enumeration · HackerOnStreet