Free tool
Certificates issued for your domain
Every SSL certificate is recorded in public logs, for everyone to see. Reading them reveals your subdomains, who issues your certificates, and forgotten addresses that someone could take over.
Why certificates are public
Since 2018, browsers only trust a certificate if it has been recorded in public Certificate Transparency logs. The goal: that no authority can issue a certificate for your domain in secret. The side effect: the name of every subdomain that ever had a certificate is visible to everyone, forever.
01
Spot forgotten services
An old test site, a retired shop, a subdomain from a former provider: the list shows what you may have forgotten.
02
Close takeover doors
A subdomain pointing to a deleted service (Heroku, GitHub Pages, Azure…) can be claimed by anyone. Remove the record.
03
Watch the issuers
An unknown authority issuing for your domain deserves a question. A CAA record limits who may issue.
Questions
Can I remove a name from the logs?
No: the logs can only be added to. That is why internal or confidential names (“new-product-launch.example.com”) should never go into a public certificate. A wildcard certificate (*.example.com) avoids publishing each name.
Why so many certificates?
Let's Encrypt and Google certificates last 90 days or less and renew automatically; a CDN like Cloudflare also issues its own. Dozens of certificates a year are normal.
What is a subdomain takeover?
You create shop.example.com, pointing to a service (Shopify, Heroku…). Later, you close the service account but leave the DNS record. Someone opens an account at the same service and claims that name: they now publish content on your subdomain, with your reputation.