Decide whether you need active, known or indexed hostnames
DNS can contain names that have never been indexed. Search engines can retain old hostnames no longer in DNS. Hosting can serve names created outside the current DNS zone. A useful audit records the source and status of each result.
Authoritative inventory
Start with systems you control
- Export or review the active DNS zone, including A, AAAA and CNAME records.
- List domains, subdomains and aliases in Plesk or the current hosting platform.
- Check CDN, load balancer, email, analytics and SaaS dashboards for connected hostnames.
- Review deployment configuration, source repositories and certificate automation.
- Mark each hostname as current, redirecting, retired, internal-only or unknown.
Google search data
Use a Search Console Domain property
A verified Domain property covers the registered domain, its subdomains and supported protocols. Use Performance and indexing reports, then filter page URLs by hostname to find subdomains Google has data for.
A URL-prefix property covers only its exact protocol and hostname, so it cannot provide the same domain-wide view.
Search Console property guideSupplementary public checks
Use several sources, then verify every result
- site: searches
- May surface indexed URLs on subdomains, but Google states that site: results are not guaranteed to list every indexed URL.
- Certificate Transparency logs
- Can reveal hostnames included in public TLS certificates, including retired or wildcard entries.
- Passive DNS services
- May show historical observations but can be stale, incomplete or subject to access limits.
- Backlink and analytics tools
- Can expose visited or linked hostnames, not a complete DNS inventory.
- Search Console links and pages
- Useful for owned properties, but data is sampled and governed by its reporting scope.
- Server logs
- Show requested hostnames reaching the server, including bots and invalid Host headers that need verification.
Validate findings
Check each hostname before acting
- Does it resolve now, and to which provider?
- Does HTTP or HTTPS serve intentional content or a default page?
- Is the certificate valid and expected?
- Is it linked internally or present in a sitemap?
- Should it remain indexed, redirect, return 404/410 or be protected?
- Who owns the service and approves its retirement?
Inventory only domains you own or are authorised to assess
Do not use discovery as permission to probe services, enumerate applications or attempt access. Publicly visible hostnames can still belong to sensitive systems.
Need help auditing a UKC-hosted domain?
Send the registered domain, assigned UKC service, DNS provider and reason for the inventory. Include a list of uncertain hostnames and their current DNS results; never include passwords or private keys.
Ask the Hosting team