This tool runs primarily in your web browser. Some sources are fetched through
proxy.php to avoid browser CORS limitations and to apply server-side
allowlist checks. Scan results are not stored by the server.
For full transparency on which services your browser will connect to, please review the Cloud Bill of Materials (CBoM).
No CT attempts yet.
No DNS queries yet.
No IdP probes yet.
No unknown TXT records logged yet.
No unknown SPF records logged yet.
This tool makes direct browser connections where possible and uses proxy.php for selected CORS-restricted sources. Here is a list of all external services used:
Services: Cloudflare DNS, Google DNS
Purpose: Performs DNS lookups for consistent, unfiltered results, bypassing local/ISP resolvers.
Endpoints:
https://cloudflare-dns.com/dns-queryhttps://dns.google/resolvehttps://1.1.1.1/dns-query (Cloudflare via IP)https://1.0.0.1/dns-query (Cloudflare via IP)https://8.8.8.8/resolve (Google via IP)https://8.8.4.4/resolve (Google via IP)Data Sent: The domain name or IP address being queried (e.g., `?name=example.com&type=A`).
Service: crt.sh (via server-side proxy)
Purpose: Discovers subdomains by searching public logs of SSL/TLS certificates.
Endpoint:
https://crt.sh/?q=%.example.com&output=json (fetched server-side via proxy.php)Data Sent: The domain name being scanned. The request is made server-side, so crt.sh sees the server's IP address, not yours.
Service: Archive.org
Purpose: Discovers subdomains and historical URLs matching the domain.
Endpoint: https://web.archive.org/cdx/search/cdx
Data Sent: The domain name being scanned. The request is attempted directly from your browser and falls back to this application's own server-side proxy when the Internet Archive blocks the cross-origin request.
Service: ProjectDiscovery Chaos API
Purpose: Discovers subdomains using the Chaos dataset.
Endpoint: https://dns.projectdiscovery.io/dns/{domain}/subdomains
Data Sent: Domain name and your API key. The request runs through this application's own server-side proxy, which forwards the key to ProjectDiscovery as an Authorization header; a browser cannot send that header to Chaos directly. The Chaos dataset only covers domains from public bug bounty programmes, so most domains return no results.
Service: The identity hosts discovered during the scan.
Purpose: Reads the publicly published discovery document to establish whether a host acts as an OpenID Connect provider and which endpoints it advertises.
Endpoint: https://{host}/.well-known/openid-configuration and /.well-known/oauth-authorization-server
Data Sent: Nothing beyond the request itself. No credentials are sent and no authentication is attempted; the request runs through this application's own server-side proxy, so the target sees the server's IP address, not yours.
Service: AlienVault Open Threat Exchange
Purpose: Passive DNS lookup for subdomain discovery.
Endpoint: https://otx.alienvault.com/api/v1/indicators/domain/{domain}/passive_dns
Data Sent: Domain name and your API Key (X-OTX-API-KEY header). Sent directly or via proxy to AlienVault.
Service: Team Cymru
Purpose: Identifies the network owner (e.g., Google, Amazon) of an IP address via its ASN.
Endpoint: DNS queries are made to `*.asn.cymru.com`.
Data Sent: The reversed IP address being queried (e.g., for `8.8.8.8`, a query is sent for `8.8.8.8.origin.asn.cymru.com`).
Service: RIPEstat
Purpose: To determine the parent IP address range (prefix) for a given public IP.
Endpoint: https://stat.ripe.net/data/network-info/data.json
Data Sent: The IP address being queried (e.g., `?resource=8.8.8.8`).
Purpose: To check for cloud identity services (like Microsoft Entra ID) by querying well-known public configuration endpoints.
Services: Microsoft Online Services (Commercial, US Government, China)
Endpoints: Your browser attempts to connect to endpoints such as:
https://login.microsoftonline.com/{domain}/.well-known/openid-configurationhttps://login.microsoftonline.com/getuserrealm.srf?login=info@{domain}https://login.microsoftonline.us/... (US Gov)https://login.chinacloudapi.cn/... (China)Data Sent: The domain name being scanned.
Service: Generic Identity Provider Discovery
Endpoint: https://{domain}/.well-known/webfinger
Data Sent: The domain name being scanned (e.g., `...webfinger?resource=acct:info@example.com`).
Service: Active Directory Federation Services
Endpoint: If an ADFS server is identified, the tool queries its public metadata endpoint, typically https://{adfs_server}/FederationMetadata/2007-06/FederationMetadata.xml.
Data Sent: A request to the discovered ADFS server hostname.
Service: Cloudflare CDN
Purpose: To load the Punycode.js library, which is required for handling internationalized domain names (IDNs).
Endpoint: https://cdnjs.cloudflare.com/ajax/libs/punycode/2.3.1/punycode.min.js
Data Sent: A standard request to fetch the JavaScript file.
Service: AntiHacker.nl
Purpose: Loads the latest DNS and SPF service signatures.
Endpoint: https://antihacker.nl/infra-mapper/js/definitions.js
Data Sent: A standard request to fetch the JavaScript file.