Skip to content

Domain certificates and subdomains

Back to tools

Public certificate transparency search for issued certificates and names they cover.

Search certificates

Search certificates

Find issued certificates and the domain names they reveal on crt.sh. Expired certificates are excluded by default; results are limited to the newest matching certificates.

Your information

Domain to search, for example example.com.

Maximum number of certificates to return, for example 100.

Include expired certificates, for example true.

1 credit per completed run

The same inputs also work from your code or an AI assistant. See For developers.

Example results

Certificates and domains

Certificates

Domain names

  • *.example.com

  • dev.example.com

  • example.com

  • m.example.com

  • products.example.com

  • support.example.com

  • www.example.com

Choose an action

About the crt.sh tool

crt.sh’s Search certificates method returns matching certificates and DNS names for a required domain.

Search certificates returns newest certificates first; optionally include expired certificates or set a maximum result count.

Built from crt.sh. Last checked Sep 29, 2026.

Actions

Search certificates

1 credit

Find issued certificates and the domain names they reveal on crt.sh. Expired certificates are excluded by default; results are limited to the newest matching certificates.

What you provide

FieldTypeRequiredDescription
DomaindomainTextRequiredDomain to search, for example example.com.Example: example.com
Max Resultsmax_resultsNumberOptionalMaximum number of certificates to return, for example 100.Example: 100
Include Expiredinclude_expiredYes or noOptionalInclude expired certificates, for example true.Example: Yes

What you get

FieldTypeDescription
SubdomainssubdomainsListUnique matching DNS names, sorted A-Z, including wildcards and the root domain when present.
CertificatescertificatesListMatching unique certificates, newest first.
Linkcertificates[].linkTextCertificate page on crt.sh.Example: https://crt.sh/?id=29557945233
Crt Sh IDcertificates[].crt_sh_idNumberExample: 29557945233
Valid Fromcertificates[].valid_fromDateExample: 2026-09-24
Valid Untilcertificates[].valid_untilDateExample: 2026-12-21
Names Coveredcertificates[].names_coveredListDNS names listed on the certificate.
Serial Numbercertificates[].serial_numberTextExample: 2caeeaf0743459d7e5f82a75123c58f3
Issuer Organizationcertificates[].issuer_organizationTextOrganization that issued the certificate.Example: Sectigo Limited

Example result

For Domain: example.com, Max Results: 100, Include Expired: Yes

JSON
{
  "subdomains": [
    "*.example.com",
    "dev.example.com",
    "example.com"
  ],
  "certificates": [
    {
      "link": "https://crt.sh/?id=29557945233",
      "crt_sh_id": 29557945233,
      "valid_from": "2026-09-24",
      "valid_until": "2026-12-21",
      "names_covered": [
        "*.example.com",
        "example.com"
      ],
      "serial_number": "2caeeaf0743459d7e5f82a75123c58f3",
      "issuer_organization": "Sectigo Limited"
    },
    {
      "link": "https://crt.sh/?id=28361996564",
      "crt_sh_id": 28361996564,
      "valid_from": "2026-07-29",
      "valid_until": "2026-10-27",
      "names_covered": [
        "*.example.com",
        "example.com"
      ],
      "serial_number": "0624d0ab311558780b7d5213b9631831",
      "issuer_organization": "SSL Corporation"
    },
    {
      "link": "https://crt.sh/?id=28361996505",
      "crt_sh_id": 28361996505,
      "valid_from": "2026-07-29",
      "valid_until": "2026-10-27",
      "names_covered": [
        "*.example.com",
        "example.com"
      ],
      "serial_number": "62546d11b12882adbce18f65f9372286",
      "issuer_organization": "SSL Corporation"
    }
  ]
}

For developers

Call it from your code with one request. Change the values in input to run it on new data. To get an API key, open Developers at the bottom of Studio, turn on Developer mode and go to API keys.

cURL
curl 'https://api.fous.com/v1/query' \
  --fail-with-body --silent --show-error --max-time 180 \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H 'Content-Type: application/json' \
  --data-raw '{
  "api": "@crt-sh",
  "visibility": "public",
  "operation": "search_certificates",
  "version": 1,
  "input": {
    "domain": "example.com",
    "max_results": 100,
    "include_expired": true
  },
  "response": {
    "format": "json"
  }
}'

What you can do with it

  • Review certificates issued for a domain
  • Identify subdomains revealed by certificates
  • Check certificate validity dates
  • Compare certificate issuer organizations
  • Review names covered by certificates

Questions about crt.sh

Can I run it with my own inputs?

Yes. Change the inputs in Studio and press Run, or send new inputs from your code, or ask a connected AI assistant.

Can I call this crt.sh tool as an API?

Yes. Send a POST request to /v1/query with your Fous API key and the inputs, and get JSON back.

How much does it cost?

Each completed run costs 1 credit. Failed runs without a completed receipt are free; completed work can remain charged if delivery is interrupted. With pay as you go, a credit costs 1¢. Monthly plans cost less per credit.

Do I need a crt.sh account?

No. You only need a Fous account.

How current is the data?

Fous gets the data from crt.sh when you run it. Some results are reused for up to 24 hours, and results that use your account or key are never reused. It was last verified on Sep 29, 2026.

What certificates were issued for a domain?

Search certificates returns matching certificates for the required domain, newest first.

Which subdomains do certificates reveal?

Search certificates returns unique matching DNS names, including wildcards and the root domain when present.

All Security toolsBrowse all tools