Skip to the content
ė.coCompare

Comparison 09 of 10 · Internet

Paper Trail, set beside crt.sh and Cert Spotter

A domain's Certificate Transparency record drawn as a timeline, one lane per authority — and a relay that would rather say “crt.sh is down” than show half the story. The source it reads searches more ways; the monitor watches while you sleep.

Under test
labs.llc/papertrail/
Measured
27 Sep 2026, 20:00–20:11 UTC, local copy of build 537
Rivals
crt.sh · SSLMate Cert Spotter
  • 2 labs.llc ahead
  • 4 a rival ahead
  • 0 level
  • 2 unconfirmed
  1. 1 What it is
  2. 2 How it works
  3. 3 The test
  4. 4 The checklist
  5. 5 Shortcomings
  6. 6 Verdict

1What it is, and who it is for

Paper Trail is a certificate ledger. Name a domain and it reads the domain's record from the public Certificate Transparency logs through crt.sh, then draws every certificate as a bar from issue to expiry, one lane per certificate authority, live certificates in ink and lapsed ones washed out. Underneath, every certificate is listed with its names, issuer, serial and dates.

It is for site owners, security people and the curious who want to see which authorities have issued certificates for a domain, when, and whether anything unexpected turns up.

The Paper Trail page on labs.llc: the headline “Every certificate a domain ever wore.”, paragraphs explaining Certificate Transparency and that a small relay asks crt.sh on the page's behalf, and buttons reading “Open the ledger” and “What is this?”.
Paper Trail at 1280 × 800, captured from the local copy of labs.llc build 537 that this review measured.

2How it works

crt.sh sends no cross-origin header, so papertrail/ct-proxy.php asks it on the page's behalf. The relay accepts one parameter — a bare lower-case domain, optionally with crt.sh's leading %. wildcard — validates it before any fetch, and builds exactly one kind of URL (lines 11–19, 56–70, 97). It allows thirty seconds because crt.sh is slow, caches each domain for ten minutes, keeps the newest 2,000 certificates and sets truncated: true when it cuts, and collapses crt.sh's precertificate-plus-certificate double entries on issuer and serial, counting what it collapsed (21–37, 73–81, 108).

If crt.sh fails, the relay may ask SSLMate's certspotter API — but only when the domain's entire history fits in its budget of 12 pages, 1,200 certificates and 22 seconds, because that API pages oldest first and a partial answer would hide the newest certificates. The serial column is then left empty rather than filled with something else (129–175). The page tells you when the answer came from the second log, was truncated, or is a stale copy (app.js:194–217, 263–265).

3The test

Measured on 27 September 2026 (UTC) through the local copy of build 537, which asked crt.sh live.

UTCWhatWhat came back
20:00:57example.com, coldHTTP 200, 10,823 bytes, 0.47 s, cache miss. From crt.sh: 43 certificates, not truncated. Newest: Sectigo DV E36, 24 Sep to 21 Dec 2026, for example.com and *.example.com.
20:01:00example.com, againSame 10,823 bytes in 0.001 s, cache hit.
20:11:05wikipedia.orgHTTP 200, 34,556 bytes, 5.9 s: 136 certificates, not truncated.
20:00:58Bad input, q=http://xHTTP 400: “q must be a bare domain name (a leading %. wildcard is the one extra allowed)”.
—The example.com lanes43 certificates from 2010-09-02 to 2026-09-24 across Sectigo (13), SSL Corporation (10), DigiCert (10), thawte (3), Cloudflare (2), SunGard (2) and others.

4The checklist

Eight checks. Paper Trail leads on how the record is shown and on honesty about gaps. crt.sh — its own source — leads on reach, and Cert Spotter on watching over time.

  • Yes: does it
  • Partly: partly — read the note
  • No: does not
  • Not checked: not checked: no claim either way
  • Not applicable: does not apply
The checklist · Paper Trail and 2 rivals8 checks
Marks for the rivals come only from their own pages, fetched on 27 September 2026 (about 20:10 UTC). A “?” is a question we could not settle, not a “no”.
Checklabs.llc · under testPaper Trailrivalcrt.shrivalCert Spotter
Search by organisation, fingerprint or IDRival aheadNo1Yes2Not checked
Timeline, one lane per issuing authoritylabs.llc aheadYesNo3Not checked
Duplicate precertificate entries collapsed and countedlabs.llc aheadYes4No5Not checked
Every certificate, with no capRival aheadPartly6YesNot checked
Says when the answer is partial or from a second logUnconfirmedYesNot applicableNot applicable
Alerts when a new certificate is issuedRival aheadNoNot checkedYes7
Expiry warningsRival aheadNoNot checkedYes
A look at any domain with no account or trialUnconfirmedYesNot checkedNot checked8
  1. 1Domain only.
  2. 2Identity, SHA-1 or SHA-256 fingerprint, crt.sh ID, and an advanced search.
  3. 3Results come as a table.
  4. 4ct-proxy.php:35–37.
  5. 5Both entries listed, each linked to its full details — which some readers will want.
  6. 6The newest 2,000; the cut is flagged as truncated.
  7. 7By email, webhook or Slack.
  8. 8A 30-day free trial is offered for monitoring; whether a one-off look needs an account was not checked.

Does better

crt.sh

  • More ways in: organisation names, fingerprints, crt.sh IDs and advanced options.
  • Every entry, precertificate and final certificate alike, each linked to its full detail.
  • No 2,000-row cap.

Does better

SSLMate Cert Spotter

  • Continuous monitoring with alerts by email, webhook or Slack.
  • Expiry monitoring.
  • You can declare legitimate certificates ahead of time to avoid false alarms.

Goes further

Paper Trail

  • Draws the record by authority, so a change of issuer stands out at a glance.
  • Flags truncation, a second-log answer or a stale copy instead of passing a partial record off as whole.
  • Uses a second log only when it can return the entire history, and leaves unknown serials blank.
  • Caches politely: 0.47 s cold, 0.001 s warm, so repeat looks do not load a donated service.

5Where Paper Trail falls short

  • A lookup, not a monitor: nothing tells you when a new certificate appears. Cert Spotter does that, and watches expiry.
  • Capped at the newest 2,000 certificates for very large domains. The cut is disclosed, but the older record cannot be reached from the page.
  • Bound to crt.sh, which the code itself calls slow. If crt.sh is down and the domain's history is larger than 1,200 certificates, there is no answer.
  • Search by domain only; crt.sh also takes organisation names, fingerprints and IDs.

6The verdict, by the checklist

Choose Paper Trail to see a domain's whole certificate history at a glance and be told plainly when any of it is missing; use crt.sh for forensic searching and Cert Spotter to be warned.

Paper Trail is a better way of looking at crt.sh's answer, not a replacement for crt.sh: it wins the rows about presentation and candour, and loses those about reach and vigilance. The length it goes to is refusing to show a slice as if it were the whole — even when that means showing nothing.

Try Paper Trail on labs.llc