Show HN: CertRadar – Find every certificate ever issued for your domain

https://certradar.net/

Comments

ops_mechanicJan 25, 2026, 5:52 PM
Hey HN, I built this after years of dealing with SSL certificate surprises – expired certs on subdomains nobody knew existed, shadow IT spinning up certs, the usual 3am outages.

CertRadar has four free tools (no signup, no premium tier):

- CT Log Search – find every certificate ever issued for a domain via Certificate Transparency logs. Great for discovering forgotten subdomains.

- SSL Analyzer – cert chain, TLS versions, HSTS, expiration. Faster than SSL Labs.

- DNS + SSL Check – DNS records and SSL health in one view.

- Security Headers – HSTS, CSP, X-Frame-Options analysis with recommendations.

Built with Rust on GCP Cloud Run. Happy to talk about the architecture or any feedback on what would make these more useful.

eric_trackjsJan 25, 2026, 11:56 PM
crt.sh is a wonderful tool. I applaud anyone who makes CT log searching more available!

That said, crt.sh can be woefully unreliable. It often returns errors during a query or is just hard down. Large result sets may never return. Queries often take a very long time.

I wanted a more reliable CT log search tool for something I'm working on, so I built a purpose built CT log search tool. I ingest all the data from the logs directly and store in Clickhouse.

https://www.certkit.io/tools/ct-logs/

yanosh_kunshJan 25, 2026, 7:09 PM
This is really cool. I've gone down the rabbit hole of Certificate Transparency to find out how crt.sh gets its information - first time I've even heard that it exists. Also, much better UI than crt.sh. I've tried to go over the information there, but it looks really cumbersome.
ops_mechanicJan 25, 2026, 10:45 PM
Thank you for the kind words, I'm glad you enjoy it.
pimlottcJan 25, 2026, 11:44 PM
The subdomain search returns a lot of spurious matches for domains with the same suffix (e.g. searching for bar.com includes foobar.com in the results)
westurnerJan 25, 2026, 9:30 PM
Feature ideas:

Log Whois and now RDAP JSON

Log DNS zones

Find typo squatting

ops_mechanicJan 26, 2026, 12:19 AM
Thank you for your suggestion one more time. I've implemented Domain registration data via RDAP protocol.
ops_mechanicJan 25, 2026, 10:54 PM
Thank you, @westurner. Excellent suggestions!