Dome Subdomain Enumeration Tool
Dome Subdomain Enumeration Tool

Dome: Subdomain Enumeration Tool

Dome is a fast and reliable python script that makes active and/or passive scan to obtain subdomains and search for open ports. This tool is recommended for bug bounty hunters and pentester in their reconnaissance phase.

If you want to use more OSINT engines, fill the config.api file with the needed API tokens

Passive Mode:

Use OSINT techniques to obtain subdomains from the target. This mode will not make any connection to the target so it is undetectable. The basic use of this mode is:

python -m passive -d domain

Active Mode:

Perform bruteforce attacks to obtain alive subdomains. There are 2 types of bruteforce:

  • Pure Bruteforce: Check subdomains from to (26 + 26^2 + 26^3 = 18278 subdomains) this bruteforce can be disabled with -nb, --no-bruteforce
  • Wordlist based: Use a custom wordlist provided by the user using the flag -w, --wordlist. If no wordlists is specified, this mode won’t be executed

This mode will also make passive mode attack but in this case, the connection is tested to ensure the subdomain is still alive. To disable passive scan in active scan mode, use --no-passive flag

The basic use of this mode is:

python -m active -d domain -w wordlist.txt

Add -p option or a built-it port option (see usage menu) to perform port scanning

python -m active -d domain -w wordlist.txt -p 80,443,8080


You can run Dome with Python 2 or 3. Python3 is recommended

Install the dependencies and run the program

git clone
cd Dome
pip install -r requirements.txt
python --help

Top Features

  • Easy to use. Just install the requirements.txt and run
  • Active and Passive scan (read above)
  • Faster than other subdomain enumeration tools
  • 7 different resolvers/nameservers including google, cloudfare (fastest), Quad9 and cisco DNS (use –resolvers filename.txt to use a custom list of resolvers, one per line)
  • Up to 21 different OSINT sources
  • Subdomains obtained via OSINT are tested to know if they are alive (only in active mode)
  • Support for webs that requires API token
  • Detects when api key is no longer working (Other tools just throw an error and stops working)
  • Wildcard detection and bypass
  • Custom Port scaning and built-in params for Top100,Top1000 and Top Web ports
  • Colored and uncolored output for easy read
  • Windows and Python 2/3 support (Python 3 is recommended)
  • Highly customizable through arguments
  • Scan more than one domain simultaneously
  • Possibility to use threads for faster bruteforce scans
  • Export output in different formats such as txt, json, html


Dome user interface
Dome user interface

Passive mode:

Passive mode in Dome
Passive mode in Dome

Active mode + port scan:

Active mode in Dome
Active mode in Dome

OSINT Search Engines

Dome uses these web pages to obtain subdomains

Without API:

  • AlienVault
  • HackerTarget
  • RapidDNS
  • ThreatMiner
  • CertSpotter
  • Anubis-DB
  • Sonar
  • SiteDossier
  • DNSrepo

With API:

  • VirusTotal
  • Shodan
  • Spyse
  • SecurityTrails
  • PassiveTotal
  • BinaryEdge


ArgumentsDescriptionArg example
-m, –modeScan mode. Valid options: active or passiveactive
-d, –domainDomains name to enumerate subdomains (Separated by commas),
-w, –wordlistWordlist containing subdomain prefix to bruteforcesubdomains-5000.txt
-i, –ipWhen a subdomain is found, show its ip
–no-passiveDo not use OSINT techniques to obtain valid subdomains
-nb, –no-bruteforceDont make pure bruteforce up to 3 letters
-p, –portsScan the subdomains found against specific tcp ports80,443,8080
–top-100-portsScan the top 100 ports of the subdomain (Not compatible with -p option)
–top-1000-portsScan the top 1000 ports of the subdomain (Not compatible with -p option)
–top-web-portsScan the top web ports of the subdomain (Not compatible with -p option)
-s, –silentSilent mode. No output in terminal
–no-colorDont print colored output
-t, –threadsNumber of threads to use (Default: 25)20
-o, –outputSave the results to txt, json and html files
–max-response-sizeMaximun length for HTTP response (Default:5000000 (5MB))1000000
–r, –resolversTextfile with DNS resolvers to use. One per lineresolvers.txt
-h, –helpHelp command
–versionShow dome version and exit
-v, –verboseShow more information during execution


Perform active and passive scan, show the ip address of each subdomain and make a port scan using top-web-ports. Data will also be written in /results folder:

python -m active -d domain -w wordlist.txt -i --top-web-ports -o

Perform passive scan in silent mode and write output to files.

python -m passive -d domain --silent --output

Perform active scan without passive and port scan

python -m active -d domain -w wordlist.txt --no-passive

Only bruteforce with wordlist

python -m active -d domain -w wordlist.txt --no-bruteforce

Scan active and passive and perform port scan ONLY in ports 22,80,3306

python -m active -d domain -w wordlist.txt -p 22,80,3306
Dark Mode

Dome (this link opens in a new window) by v4d1 (this link opens in a new window)

Dome – Subdomain Enumeration Tool. Fast and reliable python script that makes active and/or passive scan to obtain subdomains and search for open ports.