Certificate Transparency Lookup

This tool requires network access: only public information such as the domain is sent to our server. No private key or CSR is ever uploaded.

Data sourced from public Certificate Transparency logs (crt.sh).

About Certificate Transparency Lookup

The CSR.plus Certificate Transparency Lookup searches public CT logs for every certificate ever issued for a domain. Enter a hostname to list matching certificates with their serial numbers, issuers, validity periods, and SAN coverage, sourced from public transparency logs such as crt.sh.

Certificate transparency makes unauthorised issuance detectable: every publicly trusted CA must log the certificates it issues. This lookup helps you discover shadow certificates issued for your domain without your knowledge, detect phishing and impersonation, and understand your real-world attack surface.

Why use

  • Find every certificate publicly logged for a domain, including shadow certificates
  • Detect unauthorised issuance that indicates phishing or compromise
  • Inspect serial numbers, issuers, validity, and SAN coverage per certificate
  • Audit your external attack surface without any account or setup

How to use

  1. Enter the domain you want to investigate (for example example.com).
  2. The tool queries public Certificate Transparency logs for matching certificates.
  3. Review the result list: issuer, validity window, and SAN coverage for each certificate.
  4. Spot unexpected entries — certificates you did not order may signal abuse.

Frequently asked questions

▸What are Certificate Transparency logs?

Public, append-only ledgers that record every certificate a CA issues, making unauthorised issuance detectable.

▸Why would I search CT logs?

To find certificates issued for your domain that you did not authorise — a key step in detecting phishing and impersonation.

▸Is the data always complete?

It reflects publicly logged certificates; some internal or mis-issued certs may not appear, but coverage is very broad.

▸How do I stop unauthorised certificates?

Publish a CAA record restricting issuance to the CAs you use, and monitor CT logs regularly. CAA alone does not cover mis-issuance, which is why CT monitoring matters.

Namecheap

Need a new SSL certificate?

DV, OV, EV and wildcard certificates from just $5.98/yr — issued in minutes.

Get SSL on Namecheap

Affiliate link — we may earn a commission at no extra cost to you.

More free tools

Certificate Viewer

Paste or upload an X.509 certificate to inspect its subject, issuer, validity, key, fingerprints, SAN and extensions — all locally.

Certificate / Key Matcher

Check whether a private key and a certificate belong to the same key pair — computed locally, the key never leaves your browser.

PEM Viewer

Paste a PEM bundle (certificates, keys, CSRs) and see a structured breakdown of every block — locally.

SSL Format Converter

Convert between PEM, PFX/PKCS#12 and P7B/PKCS#7 — all locally in your browser.

SSL Checker (A-F Grade)

Grade any domain from A to F: TLS versions, certificate health, chain trust and HSTS.

SSL Bulk Checker

Check multiple SSL certificates at once

ACME Challenge Preflight

Test HTTP-01 and DNS-01 validation before Let's Encrypt does: DNS, port 443, well-known reachability and TXT records with fix suggestions.

Let's Encrypt Checker

Detect Let's Encrypt certificates (R3/R10/E5/E6), see the 90-day renewal countdown, chain health and renewal advice.

DNS Propagation Checker

Check TXT, A, AAAA, NS and MX records across Cloudflare, Google and AdGuard resolvers and confirm propagation.

LE Chain Compatibility

See whether your site serves the new ISRG E5/E6 chain or the legacy cross-signed chain and whether old devices trust it.

ACME Command Generator

Generate copy-paste issuance commands for Certbot, acme.sh, lego and win-acme with HTTP-01 or DNS-01.

Certificate Inspector

Enter a domain to inspect certificate validity, expiry, TLS protocol and full chain integrity.

SSL Expiry Checker

Quickly check a domain's SSL certificate expiry date and remaining days.

CAA Record Checker

Query a domain's DNS CAA records to see which Certificate Authorities are allowed to issue certificates for it.

Certificate Revocation Checker

Verify whether a certificate has been revoked via its CRL distribution points, and view embedded OCSP endpoints.

SSL Handshake Tracer

Perform a real TLS handshake and record every step: DNS, TCP, negotiated TLS version and cipher, and each certificate returned.