DNSniffer

DNSniffer

A free searchable database of 364+ million domains built from Certificate Transparency logs and ICANN zone files, with brand-monitoring alerts and a public JSON API.

🔗 Visit DNSniffer
📁 Security & Privacy🗣️ English📅 August 29, 2026

Description

Every time a website gets an SSL certificate or a domain name gets registered, that fact becomes public record somewhere on the internet — buried across certificate logs and registry files nobody has time to read. DNSniffer is like a search engine for that hidden paper trail: type in a company name, a keyword, or a wildcard pattern, and it tells you every matching domain it has found, when it first appeared, and what certificate authority issued its SSL certificate. It's aimed at people who need to know what's out there on the web, whether that's a security researcher hunting for phishing lookalikes of their company's domain, or a developer curious which domains are using a particular certificate issuer.

Under the hood, DNSniffer continuously ingests Certificate Transparency logs (the public audit trail every CA must publish) and ICANN's Centralized Zone Data Service feeds, building a searchable index that currently covers over 364 million domains across hundreds of TLDs. Results can be queried through a web UI, a free read-only JSON API with cursor-based pagination, a live WebSocket feed of newly-indexed domains, or daily bulk CSV exports per TLD or certificate authority. It also ships an MCP server so AI agents (like Claude) can query domain data directly, and a brand-monitoring feature that emails daily alerts when new lookalike domains targeting a given brand are detected.

💬 Our review

The short version: if you need to search public domain and SSL certificate data without paying for a SecurityTrails or Censys subscription, DNSniffer is a genuinely useful free alternative, though it's younger and less proven than the established players.

DNSniffer's core pitch — treating CT logs and zone files as a commodity rather than a premium product — is a real point of differentiation against tools like SecurityTrails, Censys, or crt.sh's raw interface, all of which either gate bulk access behind paid tiers or require technical comfort with raw certificate data. DNSniffer wraps that same underlying public data in a friendlier search UI, a documented JSON API, and ready-made bulk CSV exports, all free with no rate limits stated. The trade-off is that it's built at single-maintainer scale (a DataChaser.com project) rather than by an enterprise security vendor, so there's no SLA, no support contract, and coverage/uptime claims aren't independently verified. For casual domain research, brand-monitoring on a budget, or scripting against a free API, it's a solid pick; for mission-critical threat intelligence at a company, it's worth pairing with — not necessarily replacing — established paid platforms.

💰 Pricing

FreeEntirely free — web UI, JSON API, live feed, and bulk CSV exports all free with no credit card or account required.

📊 Global score

53Average
🌐Availability15/100Faible

1 language · 0 platform

📄Profile90/100Excellent

Profile completeness

🤖 AI-enriched data

💰 Pricing model
🆓 free

Free for everyone — web search, JSON API, and CSV exports all free with no credit card or account required.

👥 Target audienceSecurity researchers, pen-testers, brand-protection teams, students, and developers needing domain/DNS/SSL data.
🗣️ LanguagesEnglish
🌍 Target countriesGlobal
👍

Pros

Completely free, no account needed

364M+ domains indexed from CT logs and zone files

Free JSON API with no stated rate limits

MCP server for AI agent integration

👎

Cons

Single-maintainer side project, no SLA

No stated data-freshness or uptime guarantees

Less mature/polished than established paid platforms

No mention of historical data retention limits

❓ Frequently asked questions

What is DNSniffer?
Who is DNSniffer for?
How much does DNSniffer cost?
What are DNSniffer's key features?
Is it worth the money compared to alternatives?
Which tool should you pick for your case?