Resolve the zone
A, AAAA, MX, NS and TXT records establish where the domain lives, who handles its mail and which providers it trusts.
domain module
Point Command One at a domain and it reads DNS and mail records, pulls hostnames out of certificate-transparency logs, then dispatches Sublist3r and theHarvester for passive subdomain, host and contact discovery — everything normalised into one filterable, exportable case file.
public sources only · free registration
how the recon runs
A, AAAA, MX, NS and TXT records establish where the domain lives, who handles its mail and which providers it trusts.
Certificate-transparency logs reveal subdomains the moment a certificate is issued, including staging, admin and internal-sounding hosts.
Sublist3r and theHarvester add hostnames, email addresses and related infrastructure from public search and archive indexes.
Hosts, addresses and identities merge into unified entities, render on the intel map, and export as CSV or a branded PDF.
engines behind it
Each engine contributes a different slice of the surface, and all of them write into the same normalised schema so duplicate hostnames merge instead of stacking up.
DNS and mail records plus certificate-transparency subdomain extraction, returned in seconds for a single credit.
Passive subdomain enumeration across public search engines and indexes — broad coverage without touching the target.
Emails, hostnames and employee surfaces per domain, the classic first step of an organisational footprint.
200+ modules with built-in correlation, for when you need the deep infrastructure and reputation picture in one run.
The footprint renders as a relationship graph: the domain at the centre, hosts and contacts as confidence-coloured nodes you can drag and inspect.
WHOIS, Wayback, company-register and search-dork links generated for the domain so you can confirm ownership by hand.
questions
It enumerates hostnames belonging to a domain from passive sources — certificate-transparency logs, DNS records and public search indexes — so you see the external surface without sending traffic at the target's infrastructure.
Yes. Passive enumeration reads records that third parties already publish, such as issued TLS certificates and DNS zones. Command One does not port-scan, brute-force or attempt access, which keeps the workup lawful and quiet.
Native DNS and certificate-transparency recon runs instantly, and the worker fleet adds Sublist3r for passive subdomain discovery, theHarvester for emails and hosts, and SpiderFoot for 200+ correlated data modules.
Often the domain workup surfaces contact addresses, registrant artefacts and reused handles that pivot straight into the email and username modules, which is where a domain becomes an identity lead rather than infrastructure.
Registration is free with a daily credit allowance. Native domain recon costs one credit; Sublist3r and theHarvester are one credit each on the fleet, and SpiderFoot's full correlation run costs eight.
Create a free account, enter a domain and watch hostnames, mail infrastructure and contact surfaces fill the grid. Lawful research and due-diligence use only.