Cert Recon

Cert Recon

TLS certificate inspection

0 ratings
Free

Rating summary

Details

  • Released
  • Updated
  • June 16, 2026
  • September 17, 2026

Features

Cert Recon screenshot #1 for iPhone
Cert Recon screenshot #2 for iPhone
Cert Recon screenshot #3 for iPhone
Cert Recon screenshot #4 for iPhone
iphone
ipad
🖼️Get Icon
Icons↘︎

About

Cert Recon reads the TLS certificate chain a server presents and explains it in plain language: who issued it, when it expires, which names it covers, and whether this device trusts it. It also answers a question most computers cannot. Your phone holds two independent paths to the internet at once. Cert Recon asks the same host over Wi-Fi and over cellular and compares the answers, because a network that intercepts TLS has to re-sign the connection with its own certificate authority. The cellular path shows you what the certificate should have been. Hotel, airport, conference and corporate guest networks do this routinely. On a device with one path, it still catches the common case: a certificate that this device trusts yet carries no Certificate Transparency timestamps is being vouched for by an authority installed on the device rather than a public one. That is how a filtering proxy works, and Cert Recon names the authority doing it. WHAT YOU GET • The full chain, leaf to root, exactly as the server presented it • Every field: subject, issuer, validity, key type and size, signature algorithm, serial, SANs with their types, key usage, extended key usage, basic constraints, certificate policies, OCSP and CRL URLs, CT timestamps • SHA-256, SHA-1 and public-key (SPKI) fingerprints • Trust evaluated against this device's store, with the reason it failed rather than a red cross • Expiry countdown, weak-key and weak-signature flags, hostname mismatch and self-signed detection • Interception check: Wi-Fi against cellular, issuer sanity, transparency timestamps, captive-portal awareness • Pin a host's key and be told if it changes • History of what you have inspected, one tap to run again • Export the chain as PEM or the finding as a text report • Configurable port and SNI • iPhone and iPad, dark-first PRIVACY Nothing leaves your device. No account, no analytics, no tracking, no third-party frameworks. Hostnames you inspect are not transmitted anywhere. Pinned hosts and history stay on the device. Cert Recon is a certificate inspector: it completes the TLS handshake, reads the certificate, and closes. It sends no request body and no HTTP to the host you name. FREE No in-app purchases, no subscription, no gated features. Part of the 404 Tools Recon suite; hand any host straight to the other Recon apps you have installed.
Show more
+1

What's New in Cert Recon

1.0

September 17, 2026

Developer apps