← Back to Blog
Updates

Free Subdomain Finder: Spot Competitor Launches via CT Logs

IntelCue Team··8 min read
Free Subdomain Finder: Spot Competitor Launches via CT Logs

A Competitor's New Subdomain Is a Signal. Most Teams Miss It.

Before a product launches publicly, before a press release goes out, before a single ad runs, a certificate gets issued. That certificate is logged publicly, automatically, permanently. If you know where to look, you can spot a competitor's new enterprise., partners., or checkout. subdomain appear in the public record, often before the page it points to is live. Most teams don't know where to look. IntelCue's free subdomain finder makes it trivial: type in a domain, get every meaningful subdomain from Certificate Transparency logs, with the recent ones flagged. No signup.

What Is a Subdomain Finder?

A subdomain finder surfaces the subdomains registered under a given domain. Think app.company.com, api.company.com, checkout.company.com. These aren't hidden, but they're not advertised either.

Subdomains reveal structure. A company running store.company.com is selling direct. One with partners.company.com is building a partner program. enterprise.company.com suggests a new pricing tier is in the works. beta.company.com can mean something is shipping soon. You don't need access to their roadmap. The subdomain hints at it.

Traditional subdomain enumeration tools work by brute-force scanning: they try thousands of common prefixes against a domain and record which ones resolve. That approach is slow, legally ambiguous, and incomplete. It only finds subdomains that are already live and responding.

This tool works differently.

How Certificate Transparency Logs Make This Possible

Publicly trusted SSL/TLS certificates issued for a domain get recorded in a public, append-only ledger called a Certificate Transparency log. The system was documented by the IETF, first as an Experimental RFC (RFC 6962, published in 2013) and later as a Proposed Standard (RFC 9162, published in 2021), to make certificate issuance auditable: anyone can verify that a certificate was properly issued, and CT logs were designed to help detect misissued certificates by putting publicly trusted certificate issuance on the public record.

The practical side effect is that every subdomain backed by a publicly trusted certificate gets logged the moment that certificate is issued, often before the subdomain is wired up to a live server. For certificates from public CAs, that means you can see new infrastructure forming in the public record, rather than only after it goes live.

IntelCue's free subdomain finder draws on these public CT logs. No scanning. No brute-force. No probing anyone's infrastructure. You type in a domain, and the tool returns the meaningful subdomains observed in Certificate Transparency data, newest first.

What Makes This Tool Different from a Raw CT Query

Raw CT log data is noisy. A mature domain like Stripe or Notion accumulates a lot of certificate records over the years, and much of it is not useful: wildcard certificates, deploy-platform hostnames, and random per-tenant IDs. Dumping all of that in a list doesn't help much.

The tool does several things to make the data actually useful:

It Filters Out the Noise

IntelCue continuously ingests CT logs and strips out the clutter, including wildcard certificates, deploy-platform hostnames like *.vercel.app, and random per-tenant identifiers. What's left is the set of subdomains that carry meaning, so you're reading signal instead of scrolling through machine-generated hostnames.

The NEW Tag

Any subdomain first seen in IntelCue's CT data within the last 90 days gets a "NEW" tag. This is the flag that matters most for competitive intelligence: it points you at what has appeared recently rather than at years of accumulated infrastructure. One caveat worth understanding: the tag reflects when the subdomain first showed up in the CT data, not a certified creation date, so read it as "recently observed" rather than "definitely brand new." Even with that caveat, a billing. or enterprise. subdomain surfacing this week is the kind of early read you can act on before an announcement.

AI Explanations for Notable Subdomains

For new and strategically notable subdomains, the tool adds a one-line explanation of what the subdomain likely represents, so you can scan a long list quickly instead of pattern-matching prefixes by hand. These descriptions and the category groupings are automated estimates and can be wrong. Treat them as a starting point, not a verified assessment.

Grouped by Category

Results are organized into categories: product, marketing, infrastructure, integrations, and internal. This structure lets you skip to the subdomains that matter for your purpose. A growth team cares about store., checkout., app., and trial.. A competitive intelligence analyst wants enterprise., partners., and api.. Grouping makes that fast, even on a long list.

Is Looking at CT Logs Legal?

Yes. CT logs are public by design. They were created specifically so that any party can inspect certificate issuance. Reading a public log is categorically different from scanning someone's network or probing their servers.

You're not touching any company's infrastructure. You're reading a public ledger of domain names that certificate authorities have already published. The analogy is searching a public property registry: the information is published, it's meant to be auditable, and reading it is legitimate.

This is distinct from subdomain brute-forcing or DNS zone transfers, which involve actively probing infrastructure. The CT log approach is both more complete and cleaner from a legal and ethical standpoint than traditional scanning methods.

What Subdomains Actually Tell You About Competitor Strategy

The intelligence value depends on what you're tracking. Here are a few patterns worth watching.

New enterprise. or business. subdomains often precede a move upmarket. A competitor that has run self-serve for years and suddenly registers enterprise.competitor.com may be signaling a strategic shift, ideally one you learn about before their sales team starts calling your accounts.

New partners. or integrations. subdomains suggest ecosystem investment. A company building a partner program often stands up a subdomain before announcing anything, because it needs a destination to link to during onboarding. That can surface ahead of a formal announcement.

New checkout. or store. subdomains in a SaaS context can signal a move toward product-led growth or a new billing flow. That's relevant if you're competing on distribution model.

For a deeper look at how monitoring competitor website changes fits into a broader tracking system, the principles apply directly here: the subdomain layer sits one floor below the page layer, and it often fires first.

You can try this on real domains right now. Looking up the subdomains that a mature, infrastructure-heavy domain like Stripe runs is itself informative, because the scope of what a company operates across its infrastructure reveals a lot about how it's structured.

From Snapshot to Continuous Monitoring

The free tool gives you a point-in-time view. You look up a domain, you see what has been observed in CT data. That's useful. But competitive intelligence has a timing problem: what you find today is stale by next week.

IntelCue's Certificate Transparency monitoring turns this into a live feed. Connect a domain, and IntelCue watches the CT log stream for new certificates matching it. When a new subdomain appears, you get an alert ranked by severity, alongside monitoring for the same competitor's newsletters, blogs, news, and Google Ads. You can ask about any of it in natural language right inside Claude or ChatGPT.

This is the difference between a one-time lookup and an early warning system. Tracking competitor subdomains continuously is the kind of signal that surfaces in competitive intelligence software for SaaS startups precisely because it fires before most other sources do.

Start with the free subdomain finder to see what's already out there. Then connect IntelCue to watch what comes next.


Frequently Asked Questions

What is a subdomain finder and how does it work?

A subdomain finder surfaces the subdomains registered under a domain, such as app.company.com or api.company.com. IntelCue's free subdomain finder sources its data from public Certificate Transparency (CT) logs, which record publicly trusted SSL/TLS certificates the moment they're issued. Because a certificate is often issued before a site is live, results can include subdomains that don't yet appear in search engines, giving you earlier visibility than tools that rely on DNS scanning.

How do I find a company's subdomains without scanning their infrastructure?

Use a Certificate Transparency log reader instead of a scanner. CT logs are public ledgers that record certificates issued by public CAs for any domain. Reading them returns associated subdomains without touching the company's servers. IntelCue's free subdomain finder does exactly this: enter a domain and get the meaningful subdomains observed in CT data, with no signup required.

What does the "NEW" tag mean on a subdomain result?

The NEW tag marks subdomains first seen in IntelCue's Certificate Transparency data within the last 90 days. It reflects when the subdomain first appeared in the CT data rather than a certified creation date, so it's best read as "recently observed." Even so, a new enterprise. or partners. subdomain tagged NEW is a useful early signal worth a closer look.

Is finding subdomains from Certificate Transparency legal?

Yes. CT logs are public by design, documented by the IETF specifically to make certificate issuance auditable by anyone. Reading a public log is not the same as scanning or probing infrastructure. This approach is legally and ethically distinct from brute-force subdomain enumeration, which actively probes a target's servers. You're reading a public record, not accessing any system.

How do subdomains reveal competitor product launches early?

Subdomains are often created before content goes live, because a certificate must be issued before a site can serve HTTPS, and that certificate is logged publicly at issuance. A competitor building a new pricing tier, partner program, or checkout flow will typically register the subdomain first. IntelCue monitors these CT log entries continuously and alerts you when new subdomains appear, so the signal reaches you around the time it enters the public record rather than at announcement.

Put this into practice with IntelCue

New to the terminology? See the competitive intelligence glossary.

Related Articles