Skip to main content

Documentation Index

Fetch the complete documentation index at: https://mintlify.com/edoardottt/awesome-hacker-search-engines/llms.txt

Use this file to discover all available pages before exploring further.

Domain enumeration is one of the most critical steps in penetration test reconnaissance. Every subdomain represents a potential entry point — a forgotten staging server, an unsecured admin panel, an old web app running unpatched software, or an orphaned cloud resource. WHOIS and domain intelligence tools reveal ownership history, registrar details, related domains, and infrastructure relationships that can dramatically expand the scope of an assessment. By systematically mapping an organization’s domain footprint, security professionals can identify shadow IT assets, track domain ownership across corporate structures, detect typosquatting attempts, and surface the full breadth of an organization’s attack surface before an adversary does.

PhoneBook

Lists all domains, email addresses, or URLs for the given input domain.

IntelligenceX

Search engine and data archive — indexes domains, IPs, emails, and leaked data.

Omnisint

Subdomain enumeration powered by a large passive DNS dataset.

Riddler

Allows you to search in a high quality dataset of domains and infrastructure.

RobTex

Various kinds of research of IP numbers, Domain names, etc.

CentralOps - DomainDossier

Investigate domains and IP addresses with comprehensive dossier reports.

DomainIQ

Comprehensive Domain Intelligence — ownership, history, and related domains.

whois.domaintools.com

Industry’s fastest domain discovery engine and broadest, most accurate data.

grayhatwarfare.com - domains

How to search URLs exposed by Shortener services.

whoisology.com

Deep Connections Between Domain Names & Their Owners.

who.is

WHOIS Search, Domain Name, Website, and IP Tools.

pentest-tools.com

Discover subdomains and determine the attack surface of an organization.

BuiltWith

Find out what websites are Built With — technology stack fingerprinting.

MoonSearch

Backlinks checker & SEO Report — useful for mapping domain relationships.

sitereport.netcraft.com

Find out the infrastructure and technologies used by any site.

SynapsInt

The unified OSINT research tool — correlates domains, IPs, emails and more.

statscrop.com

Millions of amazing websites across the web are being analyzed with StatsCrop.

securityheaders.com

Scan your site now — analyze HTTP security headers for misconfigurations.

visualsitemapper.com

Create a visual map of your site — discover all pages on a domain.

similarweb.com

The easiest and fastest tool to find out what’s really going on online.

buckets.grayhatwarfare.com

Public buckets — search for exposed cloud storage buckets.

C99.nl

Over 57 quality API’s and growing — includes subdomain and domain tools.

wannabe1337.xyz

Online Tools for reconnaissance and domain research.

subdomainfinder.c99.nl

Scanner that scans an entire domain to find as many subdomains as possible.

AnubisDB

Subdomain enumeration and information gathering tool.

HypeStat

Free statistics and analytics service — find information about every website.

Private Key Project

Information security tools from Private Key Project — subdomain search included.

SiteDossier

Profiles for millions of sites on the web.

SpyOnWeb

Quick and convenient search for the websites that probably belong to the same owner.

HaveIBeenSquatted

Check if a domain has been typosquatted.

expireddomains.net

Gathers all the information you need to find good Expired Domains that are Pending Delete and you can Backorder.

SubDomainRadar.io

Discover hidden subdomains with unparalleled accuracy and speed.

Google Safe Browsing

Google’s Safe Browsing technology examines billions of URLs per day looking for unsafe websites.

WHOISFreaks.com

Unleash the Power of Data with Our Domain and IP Intelligence.

ip.THC.org

Reverse DNS, Subdomains and CNAMEs Lookup.

Tenant Domain Finder

Find All Domains in a Microsoft 365 Tenant.

NetCraft SearchDNS

Search Web by Domain — Netcraft’s comprehensive DNS search.

SpoofChecker

Spoof Checker detects typosquats and spoofed domains to protect your brand from phishing, fraud, and BEC scams.

Why Domain Enumeration Matters

In a typical penetration test, the initial target scope might list just a handful of primary domains. Thorough domain enumeration consistently reveals a much larger attack surface: forgotten subdomains pointing to decommissioned servers, development environments with weak authentication, third-party integrations with broad permissions, and expired domains vulnerable to takeover. Subdomain takeover attacks — where an attacker claims a DNS record pointing to an unclaimed cloud resource — are a persistent, high-impact class of vulnerability that domain intelligence tools help both identify and monitor. Ownership mapping via WHOIS and reverse WHOIS also helps trace corporate relationships. A single registrant email, phone number, or name server can link dozens of seemingly unrelated domains to the same organization, dramatically expanding the known attack surface. Tools like SpyOnWeb and whoisology.com make these hidden connections visible in seconds.

Build docs developers (and LLMs) love