ADVERT
CERT Record Checker
Display CERT records that embed public key certificates in DNS for experimental or legacy deployments.
How to use this tool
- Query CERT records for the target domain or hostname.
- Review certificate type, key tag, algorithm, payload, and TTL fields.
- Export output for validation workflows and deployment documentation.
What to validate
- Certificate type codes and algorithm compatibility with consumers.
- Payload integrity and expected key identifiers before rollout.
- Propagation behavior using TTL timing during certificate rotations.
Operational guidance
- Some clients and resolvers have limited CERT record support.
- Rotate published certificate material and clear stale DNS caches where needed.
- Treat DNS-published cert data as distribution, not automatic trust.
FAQ
- Which certificate formats can appear in CERT records?
- CERT responses include a type code with payload data, commonly covering formats such as PKIX, SPKI, and PGP.
- Does publishing CERT in DNS establish trust automatically?
- No. Applications still need to validate signatures, policy, and trust chains independently.
ADVERT
ADVERT