SSL Certificate Search (CT Logs)

Look up every publicly trusted certificate issued for a domain and its subdomains — issuer, expiry and revocation status.

Loading Tool...

Help shape SSL Certificate Search (CT Logs)

The bug you just noticed will fade in 3 minutes. The feature idea will vanish after your next tab switch. Crazy peps don't suffer silently.

0/1000

Frequently Asked Questions

Public CAs must log every certificate they issue in public, append-only logs. Anyone can search them to spot certificates issued for their domain.

To catch certificates you didn't request, find forgotten subdomains, and see when certificates expire across your infrastructure.

The free Cert Spotter API limits lookups per IP address per hour. If you hit it, wait a while and try again.

Browsers can't open raw TLS connections, but the newest unexpired entry is almost always the live one. The commands tab also has the openssl s_client one-liner.

No. Everything is decoded and generated with JavaScript in your tab. Private keys are never uploaded or saved; only CT searches query Cert Spotter.