CLI reference
subenum [flags] <domain>
subenum [flags] -dL domains.txt
Flags may appear before or after the domain. A URL, a port or an internationalized name is normalized to the apex domain before scanning.
Flags
| Flag | Default | Description |
|---|---|---|
-attempts <int> |
- | Total DNS resolution attempts per subdomain, 1 = no retry (default 1) |
-ct |
- | Add names from Certificate Transparency logs (crt.sh, one HTTPS request per target, no API key) as candidates and -permute seeds |
-dL <string> |
- | File of apex domains to scan, one per line (- for stdin); replaces the <domain> argument |
-depth <int> |
1 | Max recursion depth when -recursive is set (1 = no recursion) |
-diff <string> |
- | Previous results file (any -format); report only names added or removed since then, and exit 4 when there are changes |
-dns-server <string> |
8.8.8.8:53 | DNS server: ip:port (UDP, TCP fallback), tls://host[:853] (DNS over TLS) or https://host/path (DNS over HTTPS) |
-exclude <string> |
- | Comma-separated out-of-scope names and *.parent patterns; never queried or expanded |
-exclude-file <string> |
- | File of out-of-scope names and *.parent patterns, one per line (# comments allowed) |
-force |
- | Continue scanning even if wildcard DNS is detected |
-format <string> |
text | Output format: text, json, jsonl, or csv |
-hit-rate <int> |
15 | In simulation mode, percentage of names that resolve (1-100) |
-max-queries <int> |
- | Max candidate names to test (0 = unlimited); each name sends one query per record type, per attempt |
-no-abort |
- | Do not abort when the resolver failure rate exceeds 20% (warning is still emitted) |
-o <string> |
- | Write results to file (in addition to stdout) |
-permute |
- | After each scan, scan permutations of the names found (api -> api-dev, dev-api, dev.api, api2, …) |
-print-config |
- | Print every setting’s effective value and its source (flag, env, config or default), then exit |
-progress |
true | Show progress during scanning |
-r <string> |
- | File of resolvers (ip or ip:port, one per line) to spread queries over; every hit is re-validated against -dns-server |
-rate <int> |
- | Max DNS queries per second on the wire, all workers combined; counts every record type, retry and wildcard probe (0 = unlimited) |
-recursive |
- | Recursively enumerate subdomains of discovered subdomains |
-resume <string> |
- | Resume an interrupted run from its state file (no other arguments) |
-retries <int> |
- | Deprecated: use -attempts instead |
-sarif <string> |
- | Write takeover candidates to this file as SARIF 2.1.0, for GitHub code scanning (needs CNAME in -type) |
-seed <uint> |
- | In simulation mode, seed for reproducible results (0 = random; the seed used is printed) |
-seeds <string> |
- | Results file (any -format) whose names also seed -permute; implies -permute |
-show-records |
- | In text format, append each result’s records (TYPE=value) |
-silent |
- | Pipeline mode: bare result names on stdout, and only errors (and a simulation warning) on stderr |
-simulate |
- | Run in simulation mode without actual DNS queries (for testing) |
-simulate-zone <string> |
- | Lab mode: answer every query from this scenario file via a local DNS server, so no traffic leaves the machine (see the Labs page) |
-state <string> |
subenum-resume.json | Where an interrupted run saves its state for -resume |
-stats <string> |
- | Write a JSON run-quality report (outcomes, queries sent, verdict) to this file |
-t <int> |
100 | Number of concurrent workers |
-timeout <int> |
1000 | DNS lookup timeout in milliseconds |
-tui |
- | Launch the interactive terminal UI (all other flags are ignored) |
-type <string> |
A,AAAA | Comma-separated DNS record types to look up: A, AAAA, CNAME |
-v |
- | Enable verbose output |
-version |
- | Show version information |
-w <string> |
- | Path to the wordlist file (- for stdin); omitted: the bundled top-5000 list |
Exit codes
| Code | Meaning |
|---|---|
0 |
Success |
1 |
Failure |
2 |
Invalid arguments or configuration |
3 |
Some -dL targets failed |
4 |
-diff found added or removed names |
130 |
Interrupted (Ctrl+C) |
143 |
Terminated (SIGTERM) |
Defaults from the environment or a file
Settings you repeat on every run can live in the environment or a config file. Precedence, highest first: command-line flag, then SUBENUM_* environment variable, then config file, then built-in default.
- Each flag reads
SUBENUM_<FLAG>, upper-cased with dashes as underscores:SUBENUM_DNS_SERVER,SUBENUM_RATE,SUBENUM_T. - The config file is
config.jsonin your user config directory (~/.config/subenum/on Linux,~/Library/Application Support/subenum/on macOS,%AppData%\subenum\on Windows), or the path inSUBENUM_CONFIG. Keys are flag names; values are strings, numbers or booleans, andexcludeandtypealso take a list of strings. Mode flags (tui,version,print-config,resume) are command-line only. - The TUI (
-tui) starts its form from these values too, over the values it remembers from its last session. subenum -print-configprints every effective setting and where it came from:flag,env,configordefault. With a bad value,-h,-versionand-print-configstill run and warn; a scan refuses to start and names every bad value.- When
-attemptsand the deprecated-retriesboth have a value, the one from the higher-precedence source wins; both on the command line (or both from the same file) is an error.
{
"dns-server": "tls://1.1.1.1",
"rate": 200,
"type": "A,AAAA,CNAME"
}
Output streams
Resolved names go to stdout and nothing else does, so subenum example.com | httpx works as expected. Progress, warnings and the per-outcome breakdown go to stderr. -o writes the same results to a file in the chosen -format; results files are replaced atomically.