Internet records
Chapter 12 / 18
Read the name in the certificate
A name in a record does not prove a working site exists there.
What date is this?
RDAP gives structured registration data over HTTPS. WHOIS is another term you will meet in registration lookups. A domain creation date is not the website’s first publication date. Hidden registrant data alone does not show bad intent.
CT is not a live-service test
CT may contain a certificate or precertificate. SAN lists names. *.example.com is not a list of all real subdomains. An SCT is a promise of inclusion; it alone does not show completed inclusion. Finding a name is not finding a live VPN.
What the record says
Enlarge ↗Read as text
- CT record
- Listed name
- Clue
Same terms in both languages
Keep these words
- WHOIS / RDAP
- Ways to query domain registration data.
- Registrant / Registrar / Registry
- Registered holder / registration service / top-level domain registry operator.
- CT
- Certificate Transparency: public certificate records.
- SAN
- Subject Alternative Name: names covered by a certificate.
- SCT
- Signed Certificate Timestamp: a signed promise of log inclusion.
A small example
Let’s do it together
A record lists vpn.example.com. Your only data is the CT record.
Keep the name, certificate date and record source.
Write ‘This name is in the CT record’. Do not write ‘The VPN is running’.
Check permission and scope before any live-service check.
Close the notes. Think first.
Your turn
Does a wildcard certificate give every subdomain name?
Read the explanation
No. It covers a name pattern. It does not alone tell you which subdomains exist.
Reading record
Only on this browser. These marks are not test results.Sources
I used my study notes and wrote new practice examples. The source PDF is not distributed here.
About the sources and rights