Certificate Discovery
Cert Spotter is used as the primary certificate source, with crt.sh available as a fallback while the root domain remains part of every inventory.
Public Attack Surface Inventory
A responsive public-domain inventory workspace that brings certificate discovery, DNS resolution and HTTPS reachability into one focused interface for reviewing exposed hosts.
Independent security tooling project • Open-source development
Overview
Rootline starts from a root domain and builds a compact inventory of public hosts using certificate records, DNS resolution and HTTPS availability checks. The interface keeps discovery, filtering, host inspection, export and scan history together without turning the workflow into a dense security dashboard.
Features
Cert Spotter is used as the primary certificate source, with crt.sh available as a fallback while the root domain remains part of every inventory.
Discovered hosts are resolved into IPv4, IPv6 and CNAME records so certificate findings become a more useful infrastructure inventory.
Public hosts can be checked for HTTPS availability while private, local and reserved IP ranges are deliberately excluded from network probing.
Results can be exported as CSV or JSON, copied as a plain-text report and revisited from scan history stored in the current browser.
Architecture
A responsive client manages domain input, inventory filters, result views, exports, history and explicit light or dark theme preferences.
Same-origin serverless endpoints receive authorized public-domain scan requests while keeping the discovery workflow outside the public frontend.
Shared scan logic combines certificate discovery, root-domain validation, DNS lookups and HTTPS reachability into normalized host records.
Public-host limits, reserved-address filtering, local history and exportable records keep the serverless workflow practical and predictable.
Interface
Technology
FAQ
Rootline builds a focused inventory of publicly visible hosts associated with a root domain. It combines certificate records, DNS information and HTTPS reachability so the user can review public-facing infrastructure from one workspace.
Cert Spotter is the primary certificate discovery source and crt.sh is available as a fallback. The root domain itself is also checked so a useful inventory can still be produced when certificate services are unavailable.
Rootline resolves IPv4, IPv6 and CNAME records for discovered public hosts. This turns hostname discovery into a more structured view of how each public name resolves.
HTTPS checks are skipped for private, local and reserved IP addresses. The public deployment is intended only for domains the user owns or is authorized to assess.
A scan is capped at 48 public hosts so certificate discovery, DNS resolution and HTTPS checks remain predictable inside serverless execution limits instead of turning a lightweight inventory tool into an unbounded crawler.
Scan history and workspace results remain in the current browser. Explicit light or dark theme selection is also stored locally and restored before the stylesheet renders to avoid a visible theme flash.
Rootline demonstrates frontend product design, Node.js serverless APIs, external data integration, DNS and HTTPS processing, browser persistence, security headers, restrictive CSP configuration and automated verification with the Node.js test runner.
Independent Development
Rootline is an independently developed project focused on turning several public-domain signals into a practical inventory workflow with clear boundaries, exportable data and a production-ready deployment structure.
Designed the product around a clear host inventory instead of presenting raw certificate, DNS and network responses as disconnected technical output.
Structured the deployment so the public frontend stays static while Node.js functions handle scanning and shared discovery logic on the server.
Scan history, filters and theme choices stay in the browser, keeping the application lightweight without requiring an account system for everyday use.
Added security headers, a restrictive Content Security Policy, service-worker cache behavior and automated verification for a safer public deployment.