Browser-Native Subdomain Scanner
Zero-Trust Utilities
Tracking this target over time?
This page gives you subdomain enumeration right now. The Recon Workspace saves each scan and shows you what changed since the last one — a new subdomain, a weakened DMARC policy — with the same browser-only guarantee.
What is Browser-Native Subdomain Scanner?
How it works
Features & Benefits
- 100% Private: Scan targets never touch any utility servers; queries go direct to public DoH providers
- Concurrent Scanning: Fast, throttled client-side resolution avoids browser rate limits and hangs
- CSV/JSON Export: Save discovered subdomains along with their IP resolutions instantly
- Offline Ready: The scanner code and default wordlist load once and run entirely on your local machine
Frequently Asked Questions
Is this scanner as fast as command line tools?
Because it is subject to browser fetch connection limits and CORS, it is designed for targeted discovery (using 50-200 common names) rather than brute-forcing millions of combinations.
Why does it use DNS-over-HTTPS instead of native socket connection?
Web browsers cannot make raw UDP/TCP DNS queries. DoH allows us to query DNS records via standard secure HTTP fetch requests.
Can I use custom wordlists?
Yes, you can edit the list of subdomains in the options section before launching the scan.
Related Tools
Analyze DNS records (MX, SPF, DMARC, TXT) to identify email spoofing risks and domain security configurations privately in your browser.
Test if your browser autofill is leaking hidden data to websites. Interactive simulation of the 'hidden field' attack.
Popular Utilities
Format, validate, and minify JSON instantly in your browser. Your data never leaves your device.
Decode JWT tokens and inspect header and payload instantly in your browser. Your tokens never leave your device.
Count words, characters, sentences, and estimate reading time instantly in your browser. No sign-up required.
Learn More & Guides
Real DNS From a Browser Tab: DoH, CORS, and What You Genuinely Cannot Scan
A browser can resolve real DNS records, brute-force subdomains, and audit mail security without a server. It cannot scan a port. Here is exactly where the line sits, and why.
5 min readSPF, DMARC, and the Grades Nobody Checks
A domain with an SPF record can be completely unprotected against spoofing. Two records is worse than one. And p=none, the most common DMARC policy in the wild, blocks nothing at all.
5 min readWhat Changed Since Tuesday: Recon as a Longitudinal Job
A one-shot scan answers the wrong question. The finding that matters is not which subdomains exist, it is which one appeared last week. That requires storing scans, and getting one field exactly right.
5 min readUsername Sweeps and the Rate-Limit Trap
Checking one handle across eight platforms is easy. The bug worth avoiding is treating every failed request as proof the account does not exist, which is how OSINT tools quietly lie to you.
5 min read