0 characters · 0 words · 0 bytes (UTF-8)
Output will appear here
Click in the output to select all text
0 characters · 0 words · 0 bytes (UTF-8)
Output will appear here
Click in the output to select all text
Generate standard BIND-style DNS zone records for A, AAAA, CNAME, MX, TXT, and SPF.
Validate MAC addresses and reformat between colon, hyphen, and dot-separated notation.
Find MIME types by file extension or file extensions by Content-Type header.
Look up HTTP response status codes (1xx, 2xx, 3xx, 4xx, 5xx) with descriptions and specs.
Parse and format SNMP and ASN.1 Object Identifiers (OID dot notation).
This SSL certificate decoder parses a PEM-encoded X.509 certificate and displays its subject, issuer, validity period, serial number, and Subject Alternative Names in a readable format. It's an essential x509 decoder for developers troubleshooting TLS handshake failures, sysadmins verifying an expiring certificate before it takes down a production service, and security engineers auditing which domains a certificate actually covers. Instead of piping a cert through OpenSSL command-line flags you have to look up every time, this pem decoder lets you simply paste the certificate text and instantly see a structured breakdown of every important field. It's especially useful for double-checking that a renewed certificate includes all the expected SANs, or confirming exactly when a certificate expires before scheduling a renewal. Decoding happens entirely in your browser - certificate data, which is often sensitive infrastructure information, is never uploaded anywhere. Paste a PEM certificate below to see its full decoded details.
It accepts standard PEM-encoded certificates, the base64 text format beginning with '-----BEGIN CERTIFICATE-----'.
Paste the PEM certificate into the decoder and check the 'not-after' date in the validity period section, which shows the exact expiration timestamp.
SANs are additional hostnames a certificate is valid for beyond its primary common name, allowing a single certificate to secure multiple domains or subdomains.
This tool focuses on decoding and displaying the fields of a single certificate; full chain validation against trusted root CAs requires additional verification steps outside this tool's scope.
This decoder is designed for PEM (base64 text) format; a DER-format certificate would need to be converted to PEM first.
The issuer field identifies the Certificate Authority (CA) that signed and issued the certificate.
Yes, decoding happens entirely client-side in your browser, so the certificate content is never transmitted to a server - though you should still avoid pasting private keys anywhere.