See how it works
By DefenceCore Team·August 1, 2026·8 min read
company domain footprintfind all websites owned by a companysubdomain enumerationcertificate transparency subdomainsdomain osintwebsite footprint mapping

How to Map a Company's Domain and Website Footprint

The homepage is the smallest part of a company's web presence. Behind it sit product domains, documentation sites, help centers, status pages, regional variants, marketing microsites, developer portals, staging environments, and acquired brands that were never fully absorbed.

Mapping that footprint is one of the highest-yield moves in any investigation involving an organization. It reveals structure the marketing site deliberately simplifies: which products actually exist, which markets are served, which brands belong together, and which parts of the estate stopped being maintained.

This guide covers how to expand from one domain to the full picture — and, just as importantly, how to avoid attributing properties to a company that do not belong to it.


Start from one confirmed domain

Everything depends on the seed being right. Begin with a domain you have confirmed belongs to the company — one taken from an official channel, not from a search result or an inbound email.

Then read the site for the links it gives you for free:

  • Footer and header navigation, which usually expose the widest set of properties
  • Legal pages — terms, privacy, and cookie notices frequently enumerate every domain the policy covers
  • Support, documentation, and status links
  • App store, marketplace, and integration directory links
  • Careers and press pages
  • Cookie and subprocessor disclosures, which sometimes list infrastructure and regional domains

A surprising share of the footprint is simply published. Exhaust the free evidence before reaching for tooling.

Expand through DNS

DNS records describe how a domain is actually wired, and each record type answers a different question:

  • A / AAAA — where the site resolves
  • CNAME — which third-party services the company has delegated subdomains to
  • MX — the mail provider, and whether the company runs mail on its own domain
  • TXT / SPF / DKIM / DMARC — which services are authorized to send mail as the company, which is one of the most revealing records in the set
  • NS — the DNS provider

SPF records in particular tend to name a company's email, marketing, ticketing, and transactional providers in one line. That is a map of operational tooling, published deliberately.

Enumerate subdomains through certificate transparency

Every publicly trusted TLS certificate is logged to public certificate transparency logs. Because nearly everything a company serves over HTTPS needs a certificate, those logs are the single most productive source for enumerating subdomains.

Certificate transparency reliably surfaces:

  • Product and app subdomains that are not linked from anywhere public
  • Documentation, status, and support hosts
  • Regional and language-specific variants
  • Internal-sounding hosts — staging, dev, admin, vpn — that were issued public certificates
  • Historical hosts that no longer resolve, with issuance dates that date the estate

Two disciplines matter here. First, a certificate is evidence of issuance, not of a live service — many logged hosts no longer exist, and you should confirm resolution before treating one as active. Second, a logged host is not an invitation: enumerating names from public logs is passive research, while probing, authenticating to, or otherwise interacting with hosts that were plainly not meant to be public is a different activity with a different legal posture. Stay on the passive side of that line.

Follow the registration and hosting layer

Domain registration records (WHOIS/RDAP) still carry useful signal even though most personal details are redacted by default:

  • Creation date — the strongest single fact for testing claims about operating history
  • Registrar and nameservers — consistency across a company's domains
  • Organization field — occasionally unredacted for corporate registrations, and decisive when it is
  • Expiry — a domain allowed to run close to expiry says something about how the property is valued

Hosting and infrastructure are much weaker attribution evidence than they appear. A shared IP on a CDN or a large cloud provider connects a company to thousands of unrelated sites. Treat shared infrastructure as a lead to verify, never as proof of a relationship.

Corroborate the relationship before you claim it

This is the step that separates a defensible footprint map from a pile of loosely associated domains. For each property you discovered, record why you believe it belongs to the company, and how strong that reason is.

EvidenceStrengthNotes
Official cross-link from the company's own siteStrongThe company asserts the relationship
Domain named in the company's legal or subprocessor pagesStrongDocumented and deliberate
Same organization in unredacted registration or certificate detailsStrongDirect attribution
Consistent branding plus a shared support or login hostMediumCorroborates, does not prove
Same analytics or tag identifier across sitesMediumStrong in practice, but IDs get reused and copied
Shared nameservers or mail providerWeakCommon across unrelated customers of the same vendor
Shared IP, CDN, or cloud providerVery weakAlmost meaningless alone

The failure mode is a map that looks impressive and quietly contains three properties that belong to someone else. One wrong attribution discredits the whole document — which is the same reason entity resolution insists that every link carry its own confidence rather than inheriting the confidence of the cluster.

Read the footprint, don't just list it

A list of domains is inventory. The value is in what the shape tells you.

  • Product structure. Separate documentation and status hosts per product usually indicate genuinely separate products with separate teams — not one product with several marketing pages.
  • Geography. Country domains and language subdirectories show where the company actually invested in localization, which is a stronger market signal than a flags dropdown.
  • Maturity. A dedicated developer portal, a public status page, and versioned API documentation indicate a company with technical customers and uptime obligations.
  • Consolidation. Legacy brand domains redirecting into a primary domain usually mean an acquisition or rebrand — with dates, if you check when the redirect appeared.
  • Decay. Documentation frozen years ago, a status page with no incidents, certificates that stopped being renewed — parts of the estate that were abandoned rather than retired.

Record dates alongside findings. A footprint without dates cannot distinguish a growing company from one that grew three years ago.


Where this fits

Domain footprint mapping is a component of a larger process, not an end in itself:

Frequently asked questions

How do I find all the websites a company owns? Start from one confirmed domain, harvest what the company publishes itself (navigation, legal pages, subprocessor and cookie disclosures, marketplace listings), then expand through DNS records and certificate transparency logs. Ownership specifically — as opposed to association — usually has to come from an official cross-link, a legal page, or unredacted registration details.

What is certificate transparency and why does it help? Publicly trusted TLS certificates are recorded in open, append-only logs. Because almost any host served over HTTPS needs a certificate, those logs enumerate subdomains that are not linked from anywhere public, and their issuance dates help date the estate.

Is subdomain enumeration legal? Reading public DNS records and public certificate transparency logs is passive research on published data. The legal picture changes when you move from reading public records to interacting with the hosts you found — probing, brute-forcing, or attempting access. Keep to passive sources unless you have explicit authorization.

Does shared hosting prove two websites are related? No. Shared IPs, CDNs, cloud providers, nameservers, and mail providers are shared by enormous numbers of unrelated organizations. Treat infrastructure overlap as a lead requiring corroboration, and rely on official cross-links, legal-page disclosures, or registration details for attribution.

How much of a company’s footprint can be mapped from public sources? Enough to understand product structure, markets, technical maturity, and recent direction — but not everything. Private infrastructure, internal tooling, and unlinked properties without public certificates stay invisible, and a thin footprint is often just a small or offline-oriented business rather than a hidden one.


Investigate a domain

DefenceCore takes a domain or URL and follows its connected public signals automatically, returning a sourced evidence map with confidence on every link rather than a list of raw records.

Run an investigation · See a sample report

← All posts

SEE IT IN THE PRODUCT

See the identity graph, risk signals, and recommended action one investigation returns.

See a sample report →