# Cert Recon — TLS certificate inspection

> TLS certificate inspection (iPhone/iPad app by Brian Reed.)

- Source: https://appshunter.io/ios/app/cert-recon/id6779392135 (this page in markdown: same URL + `.md`)
- Developer: [Brian Reed](https://appshunter.io/developer/6775352024)
- Category: Utilities, Developer Tools
- Price: Free
- Age rating: 4+
- Requires: iOS 17.0 · 2 MB
- Languages: American English
- Released: 2026-06-16
- Data updated: 2026-09-18
- User reviews in markdown: https://appshunter.io/ios/app/cert-recon/id6779392135/reviews.md

## What is Cert Recon?

Cert Recon reads the TLS certificate chain a server presents and explains it in plain language: who issued it, when it expires, which names it covers, and whether this device trusts it.

It also answers a question most computers cannot. Your phone holds two independent paths to the internet at once. Cert Recon asks the same host over Wi-Fi and over cellular and compares the answers, because a network that intercepts TLS has to re-sign the connection with its own certificate authority. The cellular path shows you what the certificate should have been. Hotel, airport, conference and corporate guest networks do this routinely.

On a device with one path, it still catches the common case: a certificate that this device trusts yet carries no Certificate Transparency timestamps is being vouched for by an authority installed on the device rather than a public one. That is how a filtering proxy works, and Cert Recon names the authority doing it.

WHAT YOU GET

• The full chain, leaf to root, exactly as the server presented it • Every field: subject, issuer, validity, key type and size, signature algorithm, serial, SANs with their types, key usage, extended key usage, basic constraints, certificate policies, OCSP and CRL URLs, CT timestamps • SHA-256, SHA-1 and public-key (SPKI) fingerprints • Trust evaluated against this device's store, with the reason it failed rather than a red cross • Expiry countdown, weak-key and weak-signature flags, hostname mismatch and self-signed detection • Interception check: Wi-Fi against cellular, issuer sanity, transparency timestamps, captive-portal awareness • Pin a host's key and be told if it changes • History of what you have inspected, one tap to run again • Export the chain as PEM or the finding as a text report • Configurable port and SNI • iPhone and iPad, dark-first

PRIVACY

Nothing leaves your device. No account, no analytics, no tracking, no third-party frameworks. Hostnames you inspect are not transmitted anywhere. Pinned hosts and history stay on the device.

Cert Recon is a certificate inspector: it completes the TLS handshake, reads the certificate, and closes. It sends no request body and no HTTP to the host you name.

FREE

No in-app purchases, no subscription, no gated features. Part of the 404 Tools Recon suite; hand any host straight to the other Recon apps you have installed.


## Version history (last 1 release)

### 1.0 — 2026-09-17

No release notes.

## More apps by Brian Reed

- [IP Recon](https://appshunter.io/ios/app/ip-recon/id6775352022)
- [DNS Recon](https://appshunter.io/ios/app/dns-recon/id6779392375)
- [Packet Recon](https://appshunter.io/ios/app/packet-recon/id6779393192)
- [SNMP Recon](https://appshunter.io/ios/app/snmp-recon/id6779393528)
- [Egress Recon](https://appshunter.io/ios/app/egress-recon/id6779964708)

All apps by Brian Reed: https://appshunter.io/developer/6775352024

---

*Data collected daily from the US App Store and indexed by [AppsHunter](https://appshunter.io/). User reviews are verbatim App Store reviews. Ratings, prices and chart positions refresh continuously; this snapshot is from 2026-09-18.*
