Subdomains Lookup
Domain Intelligence and AnalysisSubdomains Lookup API — discovers subdomains observed for a domain, each with first_seen and last_seen dates so you can tell live infrastructure from historical records. Results are paginated: read total_pages and total_records from the first response, then pass page to walk the rest. Pass status to return only active or only inactive hosts. Built for attack-surface mapping, asset inventory and shadow-IT discovery. Each page is one billable call.
🌍 Global — Available worldwide
What Subdomains Lookup Is Used For
Attack surface mapping
Discover subdomains exposed for a domain, with first_seen and last_seen dates to separate live from historical.
Shadow IT discovery
Find hosts standing up under your domain that never went through IT.
Asset inventory
Build and refresh a list of everything published under a domain you own.
Acquisition due diligence
Survey the infrastructure footprint of a company before you buy it.
Quick Start
1. Copy your API key from Dashboard → API Keys
2. Send a POST request to /api/v1/domain/subdomains
3. Pass the key as Authorization: Bearer <key>
4. Read the result from the data object in the JSON response
cURL
curl -X POST https://app.way2api.com/api/v1/domain/subdomains \
-H "Authorization: Bearer YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{"domain_name":"way2api.com"}'