About this tool

This search is a core technique for mapping an organization's internet footprint: a single search can surface subdomains, staging environments and related services that were never advertised, because any of them that obtained a public certificate left a permanent log entry.

Example inputs: example.comdigitpol.coma-target-organization.com

What the result shows

Issuer
The certificate authority or intermediate that issued the logged certificate.
Names (Subject Alternative Names)
Every hostname listed on the certificate, often revealing subdomains beyond the one searched.
Logged at
The timestamp the certificate entry was recorded in the transparency log.
Validity window
Not-before and not-after dates showing the certificate's intended lifetime.
Serial number
The issuer-assigned unique identifier for the certificate.
Total returned versus truncated
How many matching entries crt.sh reported and whether the result was capped at 100.

Investigation use cases

  • Mapping a target domain's subdomains and related hostnames through logged certificate names
  • Investigating a phishing kit that reused a wildcard or multi-domain certificate across several lookalike sites
  • Building a timeline of when a domain and its subdomains were first secured with HTTPS
  • Supporting attack surface review by surfacing forgotten staging or test subdomains

Limitations

Results are capped at 100 entries per query and reflect only publicly logged, browser-trusted certificates, private internal certificate authorities are not logged, and a logged certificate does not confirm the certificate is still in active use.

Frequently asked questions

What is the difference between this and SSL Certificate Lookup?

Both query the same crt.sh data; this tool is framed around exhaustive reconnaissance of all logged names and certificates, while SSL Certificate Lookup frames the same data around one domain's certificate history.

Can this find certificates issued by a private internal CA?

No, only publicly trusted certificate authorities are required to log to certificate transparency, so internal or self-signed certificates will not appear.

Does a logged certificate prove the subdomain is currently live?

No, the log only proves a certificate was issued at some point; the hostname may since have been decommissioned.

Is there a cost to search?

Searching is free within daily limits; a sealed report is a paid or account feature.

Need evidence you can keep?

Every lookup produces a full public-source report sealed with a SHA-256 digest. Accounts keep a saved history and can download the DIGITPOL PDF report.