fishy

TIL about Certificate Transparency logs, basically every Let's Encrypt certificate you got shows up there as public information, so your subdomains are also public information.

crt.sh/ is a good tool to check that yourself.

crt.shcrt.sh | Certificate SearchFree CT Log Certificate Search Tool from Sectigo (formerly Comodo CA)