SSL Certificate Lookup
Every certificate publicly logged for a domain, decoded — via Certificate Transparency, not a live handshake.
Checking for an existing session…
Enter a domain to look up.
How it works
Every publicly trusted certificate issued since 2018 must be submitted to a public Certificate Transparency log by policy. This searches those logs for a domain and fully decodes the most recently issued certificate — issuer, subject, SANs, validity window, key details — without ever connecting to the host itself.
Why not a live handshake
A live SSL/TLS checker needs to actually connect to the host and read back its certificate mid-handshake. Cloudflare Workers' support for that is only partially documented, with no confirmed way to read the peer certificate — building on an unresearched capability risks shipping something that silently does not work. Certificate Transparency is the proven alternative: a public, append-only record of what has actually been issued.
An unexpected entry is a signal, not noise
CT logs record every publicly trusted certificate for a domain, including ones issued by mistake, through a compromised account, or for a subdomain that was forgotten about. Seeing a certificate here you did not expect is exactly the situation Certificate Transparency was built to surface — worth investigating, not dismissing.
Example
Look up a domain before an acquisition or vendor review to see its real certificate history, not just its current one. Compare the issuer across several entries — a sudden change from a known CA to an unfamiliar one is worth a second look.
Frequently asked questions
Why is this not a live SSL/TLS checker?
Because that needs an actual TLS handshake against the host, and Cloudflare Workers’ support for that is only partially documented — building it would mean shipping an unresearched feature with a real chance of being infeasible. Certificate Transparency is a proven, standard alternative: every publicly trusted certificate issued since 2018 must be logged to a public CT log by policy, so searching those logs finds real, currently and previously valid certificates without ever touching the target host.
Why does a certificate show up here that I never issued?
Because CT logs record everything, including certificates issued by mistake, by a compromised account, or for a subdomain you forgot existed. That is the actual value of Certificate Transparency — it is a security control, not just a lookup. An unexpected entry here is worth investigating, not dismissing as noise.
Why are older entries less detailed than the newest one?
Decoding a certificate means fetching its full PEM from the CT log and parsing the ASN.1 structure — real work per entry, in a tool already rate-limited to control abuse. The newest certificate is the one you almost always want in detail, so that is the one this tool spends that cost on; older entries still show what the log itself reports for free: common name, issuer, and validity window.
Related tools
X.509 Certificate Decoder
Paste a PEM certificate to read its subject, issuer, validity, key and extensions.
LocalWHOIS Lookup
Registrar, registration and expiry dates, status codes and name servers for any domain.
Sends dataDNS Lookup
Query A, AAAA, MX, TXT, NS, CNAME, SOA and CAA records for any domain.
Sends dataCIDR Calculator
Network, broadcast, mask and usable range for any block — and split it into subnets.
LocalIP Subnet Calculator
Enter an IPv4 address with a prefix or subnet mask, see the whole subnet, and divide it.
LocalCIDR Range Calculator
Convert between a start-end IP range and the CIDR blocks covering it.
LocalFrom the intelligence desk
- Vulnerability curl Vulnerability (CVE-2026-82208)
- Vulnerability curl Certificate Pinning Bypass (CVE-2026-80230)
- Vulnerability curl Vulnerability (CVE-2026-80231)