crt.sh (Sectigo) has been the standard public Certificate Transparency log search since 2013. Finds every certificate issued for a domain, surfaces subdomain enumeration vectors. Pain points: frequent overload, raw UI, undocumented API rate limits, RU clients hit TLS issues. Alternatives: Enterno.io Subdomain Enumeration, CertSpotter (SSLMate), crt-search.io, Google Transparency Report.
Below: competitor overview, feature-by-feature comparison, when Enterno.io wins, FAQ.
crt.sh launched by Sectigo (ex-Comodo CA) in 2013. Free, no signup, SQL-like query syntax. Indexes CT logs from Google, Cloudflare, Let's Encrypt, Sectigo. In 2024-2026 often unreachable from Russia without VPN; response time 3-30 s.
| Feature | Enterno.io | Competitor |
|---|---|---|
| Free CT-log search | ✅ | ✅ |
| Subdomain enumeration | ✅ | ⚠️ Manual |
| No-key API | ⚠️ Pro | ✅ |
| RU reachability | ✅ | ⚠️ |
| Response time | 1-2 s | 3-30 s |
| Active certs filter | ✅ | ⚠️ manual |
| SSL chain validation | ✅ | ❌ |
| Integrated SSL checker | ✅ | ❌ |
SSL/TLS is the encryption protocol that protects data between the browser and server. Our tool analyzes the certificate, chain of trust, TLS version, and knownvulnerabilities.
Issuer, validity period, signature algorithm, covered domains (SAN), and validation type (DV/OV/EV).
Full chain verification: from leaf certificate through intermediates to root CA.
Protocol version (TLS 1.2/1.3), cipher suites, Perfect Forward Secrecy (PFS) support.
Set up a monitor — get Telegram and email alerts 30/14/7 days before expiration.
SSL certificate monitoring
TLS config audit
HTTPS as ranking factor
customer trust
www and subdomains.Strict-Transport-Security header forces browsers to always use HTTPS.SSL certificate monitoring, check history and alerts 30 days before expiry.
Sign up freeA public append-only log of every SSL certificate issued by public CAs. Chrome since 2018 requires each cert to be in a CT log for trust.
Yes, CT logs surface every certificate including for *.internal.example.com. A well-known recon vector for security testing.
Technically yes (output=json) but undocumented and unknown rate limits. Enterno.io — public API with a declared limit.
DNS shows only active A/CNAME. CT logs cover every cert ever issued, even retired. Deeper.