Using Certificate Transparency Logs to check sub domains
Most domains use TLS certificates for security. Did you know they are published, logged and can be queried? Fun!
You might use it to discover sub domains:
curl -sS --retry 5 --retry-all-errors "https://ctlogs.dev/search?q=*.openai.com&output=json" | jq -r '.rows | map(.match) | unique[]'