What it is
Finds subdomains through public Certificate Transparency logs, via crt.sh. Every certificate a CA issues is logged publicly, so any hostname anyone has ever requested a certificate for ends up on record. The check resolves the registrable domain, then collects and deduplicates the names from every certificate issued beneath it.
Why it matters
Subdomains are where the forgotten things live: staging servers, admin panels, old campaign sites, a dashboard somebody stood up for a demo and never took down. They tend to be maintained to a lower standard than the main site. CT logs are historical, though, so expect a good share of what turns up no longer to resolve.