Subfinder
Subfinder by ProjectDiscovery is a fast, passive subdomain discovery tool. It asks many online sources which names exist under a domain and combines their answers. ActiveDNS is one of those sources: it adds names that have actually been seen resolving, newest first.
Coming soon: ActiveDNS support has been written for Subfinder and is being submitted to the project.
Get a token
Request a free token on the Subfinder token page. Tokens are free and come with an hourly and daily budget.
Add it to Subfinder
Subfinder reads API keys from ~/.config/subfinder/provider-config.yaml (the file is created the first time Subfinder runs). Add your token under activedns:
activedns:
- adnsj_your_token_here
Then run Subfinder as usual; ActiveDNS is used for every domain you enumerate. To query ActiveDNS alone, for example to check the token works:
subfinder -d example.com -s activedns
subfinder -ls lists the sources Subfinder knows about: activedns appears there once your Subfinder version includes it.
Limits
Each token has its own hourly and daily budget. If you are experiencing that the currnet limits are too tight, Contact me, and I'll look into it.
