# Subdomain Finder Examples

Worked Subdomain Finder examples: every known subdomain of a small and of a very large domain, with paging and ordering.

Source: https://docs.deepinfo.com/reference/discovery/subdomain-finder/examples/

Last updated: 2026-09-24

---
`GET https://api.deepinfo.com/v1/discovery/subdomain-finder` · endpoint: [Subdomain Finder](/reference/discovery/subdomain-finder/)

Worked examples for the Subdomain Finder: every subdomain Deepinfo knows of a domain. Two domains (`deepinfo.com` and `google.com`), then paging and ordering.

Every example is a real request with the response the API returned on September 24, 2026 (Deepinfo DEMO account); totals such as `result_count` change as the dataset is updated.

Responses are trimmed for display: `results` shows the first 3 records, long lists inside a record the first 10 items and very long texts the first 4,000 characters, while `result_count` stays the full total; each page says what was shortened. Personal data (WHOIS contact names, addresses, phone numbers and personal e-mail addresses) is redacted, and cookie values are masked (`<value>`).

These examples use the API’s default page size, 100, unless they show paging. `page` is 1 to 400 and `page_size` 25 to 100.

Each result is a full domain record, the same shape as a Domain Detail response: WHOIS, DNS, SSL certificate and web data.
The domain itself is part of the result (`type: 1`), next to its subdomains (`type: 2`).

## Ordering Values

`ordering` sorts the results by one field, ascending; a leading `-` sorts descending (`-domain.whois.create_date` puts the newest registration first). Each value below was tried on the live API on September 24, 2026, on one of the Discovery endpoints, and sorted the results as described. Without `ordering`, the order is not fixed: the same request can return its records in a different order.

| Value | Sorts By |
|---|---|
| `punycode` | The domain name, in its ASCII (punycode) form |
| `domain.extension.punycode` | The extension (TLD) |
| `dns_last_change_date` | The last change seen in the DNS records |
| `ssl_last_change_date` | The last change seen in the SSL certificate |
| `domain.whois_last_change_date` | The last change seen in the WHOIS record |
| `domain.whois.create_date` | The registration date |
| `domain.whois.expiry_date` | The expiry date |
| `domain.whois.update_date` | The date the registry last updated the WHOIS record |

## Parameters Without an Example

As of September 24, 2026, these parameters have no worked example.

| Parameter | Why |
|---|---|
| `export` | `export=true` returns the whole result set as a file download (JSON or CSV) instead of a page of results; these examples show paged JSON only. |
| `export_format` | Used only with `export=true`: `json` (the default) or `csv`. |
| `export_scope` | Used only with `export=true`: `basic`, `default` or `extended` (how many fields each exported record carries). |

Each example links to its own page with the request and the response.

## Lookups

| Example | Param | Value |
|---|---|---|
| [Every Subdomain of a Domain](/reference/discovery/subdomain-finder/examples/default/) | `domain` | `deepinfo.com` |
| [A Domain With Many Subdomains](/reference/discovery/subdomain-finder/examples/many-subdomains/) | `ordering`<br>`domain` | `punycode`<br>`google.com` |

## Paging

| Example | Param | Value |
|---|---|---|
| [Second Page of Results](/reference/discovery/subdomain-finder/examples/second-page/) | `page`<br>`domain` | `2`<br>`google.com` |
| [Smaller Pages (25 Results)](/reference/discovery/subdomain-finder/examples/page-size-25/) | `page_size`<br>`domain` | `25`<br>`google.com` |

## Ordering

| Example | Param | Value |
|---|---|---|
| [Alphabetical Order](/reference/discovery/subdomain-finder/examples/ordering-punycode/) | `ordering`<br>`domain` | `punycode`<br>`deepinfo.com` |
| [Most Recent Certificate Change First](/reference/discovery/subdomain-finder/examples/ordering-ssl-last-change-date-desc/) | `ordering`<br>`domain` | `-ssl_last_change_date`<br>`deepinfo.com` |
