← All tools

Certificate Hostname Matcher

Compare candidate ASCII hostnames and IP addresses with certificate identity entries without making network requests.

Identity-name check only: a name match does not establish certificate chain trust, signature validity, issuer authorization, revocation status, policy, key usage, validity time, CT compliance, or server possession of the private key. No DNS, TLS, OCSP, CT, or other network lookup is performed.

Common Name is displayed for context only and is never used as a fallback identity.

Input policy: Unicode U-labels are rejected; convert them to IDNA ASCII A-labels (xn--…) with a trusted IDNA implementation first. A trailing dot and ASCII letter case are normalized. This tool has no Public Suffix List; obvious patterns such as *.com and a small public-suffix-like heuristic set are rejected, but the heuristic is not authoritative.

Results

Certificate identity matching results
CandidateTypeResultEvidenceRule

Extracted identity material

Run a comparison.