Comparison 09 of 10 · Internet
Paper Trail, set beside crt.sh and Cert Spotter
A domain's Certificate Transparency record drawn as a timeline, one lane per authority — and a relay that would rather say “crt.sh is down” than show half the story. The source it reads searches more ways; the monitor watches while you sleep.
- Under test
- labs.llc/papertrail/
- Measured
- 27 Sep 2026, 20:00–20:11 UTC, local copy of build 537
- Rivals
- crt.sh · SSLMate Cert Spotter
- 2 labs.llc ahead
- 4 a rival ahead
- 0 level
- 2 unconfirmed
1What it is, and who it is for
Paper Trail is a certificate ledger. Name a domain and it reads the domain's record from the public Certificate Transparency logs through crt.sh, then draws every certificate as a bar from issue to expiry, one lane per certificate authority, live certificates in ink and lapsed ones washed out. Underneath, every certificate is listed with its names, issuer, serial and dates.
It is for site owners, security people and the curious who want to see which authorities have issued certificates for a domain, when, and whether anything unexpected turns up.

2How it works
crt.sh sends no cross-origin header, so papertrail/ct-proxy.php asks it on the page's behalf. The relay accepts one parameter — a bare lower-case domain, optionally with crt.sh's leading %. wildcard — validates it before any fetch, and builds exactly one kind of URL (lines 11–19, 56–70, 97). It allows thirty seconds because crt.sh is slow, caches each domain for ten minutes, keeps the newest 2,000 certificates and sets truncated: true when it cuts, and collapses crt.sh's precertificate-plus-certificate double entries on issuer and serial, counting what it collapsed (21–37, 73–81, 108).
If crt.sh fails, the relay may ask SSLMate's certspotter API — but only when the domain's entire history fits in its budget of 12 pages, 1,200 certificates and 22 seconds, because that API pages oldest first and a partial answer would hide the newest certificates. The serial column is then left empty rather than filled with something else (129–175). The page tells you when the answer came from the second log, was truncated, or is a stale copy (app.js:194–217, 263–265).
3The test
Measured on 27 September 2026 (UTC) through the local copy of build 537, which asked crt.sh live.
| UTC | What | What came back |
|---|---|---|
| 20:00:57 | example.com, cold | HTTP 200, 10,823 bytes, 0.47 s, cache miss. From crt.sh: 43 certificates, not truncated. Newest: Sectigo DV E36, 24 Sep to 21 Dec 2026, for example.com and *.example.com. |
| 20:01:00 | example.com, again | Same 10,823 bytes in 0.001 s, cache hit. |
| 20:11:05 | wikipedia.org | HTTP 200, 34,556 bytes, 5.9 s: 136 certificates, not truncated. |
| 20:00:58 | Bad input, q=http://x | HTTP 400: “q must be a bare domain name (a leading %. wildcard is the one extra allowed)”. |
| — | The example.com lanes | 43 certificates from 2010-09-02 to 2026-09-24 across Sectigo (13), SSL Corporation (10), DigiCert (10), thawte (3), Cloudflare (2), SunGard (2) and others. |
4The checklist
Eight checks. Paper Trail leads on how the record is shown and on honesty about gaps. crt.sh — its own source — leads on reach, and Cert Spotter on watching over time.
- Yes: does it
- Partly: partly — read the note
- No: does not
- Not checked: not checked: no claim either way
- Not applicable: does not apply
| Check | labs.llc · under testPaper Trail | rivalcrt.sh | rivalCert Spotter |
|---|---|---|---|
| Search by organisation, fingerprint or IDRival ahead | No1 | Yes2 | Not checked |
| Timeline, one lane per issuing authoritylabs.llc ahead | Yes | No3 | Not checked |
| Duplicate precertificate entries collapsed and countedlabs.llc ahead | Yes4 | No5 | Not checked |
| Every certificate, with no capRival ahead | Partly6 | Yes | Not checked |
| Says when the answer is partial or from a second logUnconfirmed | Yes | Not applicable | Not applicable |
| Alerts when a new certificate is issuedRival ahead | No | Not checked | Yes7 |
| Expiry warningsRival ahead | No | Not checked | Yes |
| A look at any domain with no account or trialUnconfirmed | Yes | Not checked | Not checked8 |
- 1Domain only.
- 2Identity, SHA-1 or SHA-256 fingerprint, crt.sh ID, and an advanced search.
- 3Results come as a table.
- 4ct-proxy.php:35–37.
- 5Both entries listed, each linked to its full details — which some readers will want.
- 6The newest 2,000; the cut is flagged as truncated.
- 7By email, webhook or Slack.
- 8A 30-day free trial is offered for monitoring; whether a one-off look needs an account was not checked.
Does better
crt.sh
- More ways in: organisation names, fingerprints, crt.sh IDs and advanced options.
- Every entry, precertificate and final certificate alike, each linked to its full detail.
- No 2,000-row cap.
Does better
SSLMate Cert Spotter
- Continuous monitoring with alerts by email, webhook or Slack.
- Expiry monitoring.
- You can declare legitimate certificates ahead of time to avoid false alarms.
Goes further
Paper Trail
- Draws the record by authority, so a change of issuer stands out at a glance.
- Flags truncation, a second-log answer or a stale copy instead of passing a partial record off as whole.
- Uses a second log only when it can return the entire history, and leaves unknown serials blank.
- Caches politely: 0.47 s cold, 0.001 s warm, so repeat looks do not load a donated service.
5Where Paper Trail falls short
- A lookup, not a monitor: nothing tells you when a new certificate appears. Cert Spotter does that, and watches expiry.
- Capped at the newest 2,000 certificates for very large domains. The cut is disclosed, but the older record cannot be reached from the page.
- Bound to crt.sh, which the code itself calls slow. If crt.sh is down and the domain's history is larger than 1,200 certificates, there is no answer.
- Search by domain only; crt.sh also takes organisation names, fingerprints and IDs.
6The verdict, by the checklist
Choose Paper Trail to see a domain's whole certificate history at a glance and be told plainly when any of it is missing; use crt.sh for forensic searching and Cert Spotter to be warned.
Paper Trail is a better way of looking at crt.sh's answer, not a replacement for crt.sh: it wins the rows about presentation and candour, and loses those about reach and vigilance. The length it goes to is refusing to show a slice as if it were the whole — even when that means showing nothing.
Try Paper Trail on labs.llc