Skip to main content
QUIETLYTIC
Networking

SSL Certificate Lookup

Every certificate publicly logged for a domain, decoded — via Certificate Transparency, not a live handshake.

Checking for an existing session…

Backend · queries a Certificate Transparency log on your behalf Awaiting a domain
Esc Clear
Certificates

Enter a domain to look up.

How it works

Every publicly trusted certificate issued since 2018 must be submitted to a public Certificate Transparency log by policy. This searches those logs for a domain and fully decodes the most recently issued certificate — issuer, subject, SANs, validity window, key details — without ever connecting to the host itself.

Why not a live handshake

A live SSL/TLS checker needs to actually connect to the host and read back its certificate mid-handshake. Cloudflare Workers' support for that is only partially documented, with no confirmed way to read the peer certificate — building on an unresearched capability risks shipping something that silently does not work. Certificate Transparency is the proven alternative: a public, append-only record of what has actually been issued.

An unexpected entry is a signal, not noise

CT logs record every publicly trusted certificate for a domain, including ones issued by mistake, through a compromised account, or for a subdomain that was forgotten about. Seeing a certificate here you did not expect is exactly the situation Certificate Transparency was built to surface — worth investigating, not dismissing.

Example

Look up a domain before an acquisition or vendor review to see its real certificate history, not just its current one. Compare the issuer across several entries — a sudden change from a known CA to an unfamiliar one is worth a second look.

Frequently asked questions

Why is this not a live SSL/TLS checker?

Because that needs an actual TLS handshake against the host, and Cloudflare Workers’ support for that is only partially documented — building it would mean shipping an unresearched feature with a real chance of being infeasible. Certificate Transparency is a proven, standard alternative: every publicly trusted certificate issued since 2018 must be logged to a public CT log by policy, so searching those logs finds real, currently and previously valid certificates without ever touching the target host.

Why does a certificate show up here that I never issued?

Because CT logs record everything, including certificates issued by mistake, by a compromised account, or for a subdomain you forgot existed. That is the actual value of Certificate Transparency — it is a security control, not just a lookup. An unexpected entry here is worth investigating, not dismissing as noise.

Why are older entries less detailed than the newest one?

Decoding a certificate means fetching its full PEM from the CT log and parsing the ASN.1 structure — real work per entry, in a tool already rate-limited to control abuse. The newest certificate is the one you almost always want in detail, so that is the one this tool spends that cost on; older entries still show what the log itself reports for free: common name, issuer, and validity window.

Related tools

From the intelligence desk