4

I just signed up Cloudfare and they showed me a list of my subdomains by scanning my domain.

How do they do this? What technology is used to scan all subdomains related to a root domain?

  • Can you explain that a little bit further? It is possible that they just did a zone transfer (depending on your DNS settings) – MichelZ Apr 16 '14 at 17:34
  • Have a look [here](http://stackoverflow.com/questions/131989/how-do-i-get-a-list-of-all-subdomains-of-a-domain) – MichelZ Apr 16 '14 at 17:36
  • My setup does not allow axfr zone transfer – Isabella Wilcox Apr 16 '14 at 17:39
  • 1
    To pick a nit: You do not have a root domain. There is only one root domain and it is at the root (of all places). What you have is most likely a second or third level domain name. –  Apr 16 '14 at 17:40

2 Answers2

4

They flood your DNS server with requests for "common" entries. It definitely does not get them all, just tried on one of my domains with "weird" subdomains and it only caught about half of them.

MichelZ
  • 11,068
  • 4
  • 32
  • 59
Chris S
  • 77,945
  • 11
  • 124
  • 216
1

One possibility is to just google for the domain name and see what subdomains come up.

E.g.: https://www.google.ch/?q=site:test.com#q=site:test.com

MichelZ
  • 11,068
  • 4
  • 32
  • 59