Skip to content
Aback Tools Logo

Certificate Transparency Log Checker

Search Certificate Transparency logs to find all TLS certificates issued for any domain. Query the crt.sh public database to view certificate details including issuer (Certificate Authority), SHA-256 fingerprint, Subject Alternative Names (SANs), validity periods, and the specific CT logs that recorded each certificate - all in your browser with no signup required.

Certificate Transparency Log Checker

Check if certificates for any domain appear in Certificate Transparency logs via crt.sh. View log names, entry timestamps, issuer details, and certificate validity periods.

Enter a domain name to search in Certificate Transparency logs

Quick test:

Why Use Our Certificate Transparency Log Checker?

Certificate Transparency Log Search

Query crt.sh, the industry-standard Certificate Transparency log database, to find all TLS certificates issued for any domain. View every certificate logged by public CT logs with full metadata and fingerprint details.

Detailed Certificate Metadata

For each certificate, see the SHA-256 fingerprint, serial number, issuer (Certificate Authority), Subject Alternative Names (SANs), and the exact CT log that recorded the certificate with its entry timestamp.

Validity & Expiry Tracking

Each certificate card shows its validity period (not before / not after) with a color-coded status badge - Active (green), Expired (red), or Not Yet Valid (amber). Quickly identify expired certificates that may need renewal.

Issuer & Log Aggregation

View a summary of all Certificate Authorities that issued certificates for the domain, and the CT logs used to record them. Understand your certificate landscape at a glance with issuer and log count breakdowns.

Common Use Cases for CT Log Checker

TLS Certificate Inventory

Maintain a complete inventory of all TLS certificates issued for your domains. CT logs provide the only authoritative record of every certificate, including those issued by mistake or without your knowledge.

Unauthorized Certificate Detection

Detect certificates issued for your domain by unauthorized or unknown Certificate Authorities. Certificate Transparency makes it possible to catch rogue certificates that could be used for man-in-the-middle attacks.

Expired Certificate Audit

Identify expired certificates in CT logs that may still be in use or cached by clients. An expired certificate can cause service disruptions and security warnings for your users.

Domain Security Monitoring

Regularly monitor CT logs for new certificates issued for your domain as part of your security monitoring pipeline. Detect certificate mis-issuance, test certificates, or unauthorized provisioning.

Certificate Authority Assessment

Review which Certificate Authorities have issued certificates for your domain or your competitors. Understand the CA landscape and make informed decisions about which CAs to trust for your certificate procurement.

Pre-Change Due Diligence

Before changing Certificate Authorities or certificate types, check CT logs to understand your current certificate profile - including all active certificates, their issuers, and subject alternative names.

Understanding Certificate Transparency Logs

What is Certificate Transparency?

Certificate Transparency (CT) is an open auditing and monitoring system designed to protect the TLS/SSL certificate ecosystem. When a Certificate Authority (CA) issues a certificate for a domain, they must submit it to one or more public CT logs. These logs are append-only and cryptographically verifiable, creating a permanent, public record of every TLS certificate issued. CT has been mandatory for all publicly trusted TLS certificates since April 2018 (enforced by Chrome and other major browsers).

How Our CT Log Checker Works

  1. Enter a Domain: Type any domain name (e.g., google.com) and click "Check CT Logs". Your browser queries the crt.sh API - a free, public database that aggregates certificates from all major CT logs worldwide.
  2. Certificate Discovery: crt.sh returns all certificates where the domain appears in the Common Name (CN) or Subject Alternative Names (SANs). Results are de-duplicated by SHA-256 fingerprint and sorted by entry timestamp.
  3. Metadata & Analysis: Each certificate is displayed with its issuer (CA), validity period, fingerprint, serial number, SANs, and the specific CT log that recorded it. Summary sections show issuer distribution and log usage statistics for the domain.

Certificate Transparency Log Fields Explained

  • SHA-256 Fingerprint: A cryptographic hash of the certificate. Each certificate has a unique fingerprint - used to identify and de-duplicate entries.
  • Issuer (CA):The Certificate Authority that issued the certificate (e.g., Let's Encrypt, Google Trust Services, DigiCert).
  • Subject Alternative Names (SANs): All domain names the certificate is valid for. Modern certificates can cover multiple domains (e.g., example.com and www.example.com).
  • Entry Timestamp: When the certificate was added to the CT log - usually shortly after issuance.
  • CT Log Name:The specific CT log that recorded this certificate (e.g., Google Xenon, Let's Encrypt Oak). Browsers require certificates to appear in at least two approved logs.

Privacy, Security & Availability

Our Certificate Transparency Log Checker queries the public crt.sh API directly from your browser. We do not store, log, or process any domain lookups on our servers. crt.sh is a free, publicly available service maintained by the community. The tool is 100% free with no signup, no account, and no usage limits - all processing happens client-side in your browser.

Frequently Asked Questions About CT Log Checker

Certificate Transparency is a public audit system for TLS certificates. When a Certificate Authority issues a certificate for a domain, they must submit it to one or more public CT logs. These logs are append-only and cryptographically verifiable, creating a public record of every TLS certificate issued. CT helps detect mis-issued or fraudulent certificates and has been mandatory for publicly trusted certificates since April 2018.

crt.sh is a free, public Certificate Transparency log search engine maintained by the Certificate Search community. It aggregates data from all public CT logs and provides a searchable database of certificates. Our tool queries crt.sh directly from your browser to find certificates for any domain.

Enter your domain name in the input above and click "Check CT Logs". We query crt.sh and return all certificates found in CT logs for that domain and its subdomains. Results include issuer details, validity dates, fingerprints, and the CT log information.

If you find a certificate for your domain that you did not request, it could indicate a misconfiguration by your hosting provider, a test certificate, or potentially a fraudulent certificate. CT logs make it possible to detect unauthorized certificates. If you suspect a fraudulent certificate, contact the Certificate Authority immediately.

CT logs are append-only and entries are permanent - once a certificate is logged, it cannot be removed. This is by design to ensure a complete historical record. Certificates remain searchable indefinitely through services like crt.sh.

No. Your queries are sent directly from your browser to the crt.sh API. We do not store, log, or process your queries on any server. All processing happens client-side, and crt.sh is a free public service.

Active certificates have a validity period that includes today's date. Expired certificates have a notAfter date in the past. Not Yet Valid certificates have a notBefore date in the future - these are often pre-issued certificates that haven't been deployed yet.

Yes! 100% free with no signup, no account, and no usage limits. Check Certificate Transparency logs for any domain as many times as you need. The tool queries the free public crt.sh API.