About this tool

Because certificate issuance is publicly logged, this is a way to see a domain's certificate history and discover related subdomains named on the same certificates, without ever connecting to the live website.

Example inputs: example.comdigitpol.comlogin.example.net

What the result shows

Issuer
The certificate authority that issued the certificate.
Names
All domain and subdomain names listed on the certificate, which can reveal related hostnames.
Logged at
When the certificate was recorded in the public transparency log.
Validity window
The not-before and not-after dates defining when the certificate is valid.
Serial number
The certificate's unique identifier assigned by its issuer.

Investigation use cases

  • Finding related subdomains such as login or pay portals named on the same certificate
  • Establishing when a domain was first prepared for HTTPS as a timeline signal
  • Comparing certificate issuers between a genuine site and a suspected clone
  • Checking whether a suspicious site is using a newly issued certificate consistent with a recent campaign

Limitations

Results come from a public log and are capped at 100 certificates per query, the search does not make a live TLS connection to the site, and a certificate's existence does not confirm a certificate is still actively deployed or confirm who controls the server today.

Frequently asked questions

Does this connect to the website to check its live certificate?

No, this searches the public certificate transparency log only; no connection is made to the domain's server.

Can this show every certificate ever issued?

It returns up to 100 matching log entries; very high-volume domains may have more certificates than the result includes.

Why do unfamiliar subdomains appear in the results?

Certificates can name multiple hostnames, so related subdomains such as mail or admin portals can surface even if they were not searched for directly.

Is the lookup free?

Yes, within daily limits; a sealed report is a paid or account feature.

Need evidence you can keep?

Every lookup produces a full public-source report sealed with a SHA-256 digest. Accounts keep a saved history and can download the DIGITPOL PDF report.