Defaults.Exposed

Whose name is on your certificate? 17,360,410 domains present someone else's

The September 2026 census completed a TLS (Transport Layer Security) handshake with 212,328,093 domains and kept the certificate each one presented. For 17,360,410 of them, 8.2%, that certificate was made out to someone else: it lists names, and none of them is the domain or a name under it. The share is 8.3% for generic TLDs (Top-Level Domains) and 8.0% for country-code TLDs.

The ten names handed out most often reach 3,731,915 of those domains, 21.5%, and all ten are defaults. Names under Shopify’s myshopify.com lead with 1,029,215, almost all of them the storefront placeholder *.myshopify.com. After them come the certificates that hosting companies such as All-Inkl.com, Namecheap and one.com fall back on when a server holds none for the name requested. Squarespace’s own certificate is there too, and so are the self-signed placeholders that server software makes for itself, Plesk’s among them. At the other end, 568,450 domains, 3.3%, were handed a name that no other domain in the census received.

Three stacked bars, for all domains, generic TLDs and country-code TLDs, splitting the domains that presented a certificate by whose name it carried. All domains: their own name and accepted 89.1%, their own name but rejected for another fault 1.9%, their own name in the wrong form or no name 0.8%, someone else's name 8.2%. Someone else's name in generic TLDs 8.3%, in country-code TLDs 8.0%.

Figure 1. Whose name was on the certificate each domain presented. Orange is someone else’s name.

A count of the scanner’s name errors would miss 6,465,876 of these domains, 37.2%. The census connects with Node.js, and Node compares a certificate’s names with the domain only after the certificate has passed its other checks. An expired or self-signed certificate is reported as expired or self-signed, and its names are never compared. Node reported all 1,029,213 domains handed Shopify’s placeholder as expired, for example. So this page compares the names on each certificate with the domain directly.

How the names were compared

The census scanner makes one TLS connection per domain, on port 443, to the first address the domain publishes, and it sends the domain’s own name in the handshake, so a server holding several sites knows which one is wanted. It keeps the certificate whatever the verdict. The names on a certificate are its subject common name and the DNS (Domain Name System) entries in its subject alternative name list, the SAN list.

Each certificate then lands in one of four groups:

The base is every domain, whatever its grade, where the handshake completed and a certificate was captured: 212,328,093 domains, 61.1% of the 347,691,016 the census scanned. A domain scanned twice counts once, with the later scan’s certificate. Generic and country-code TLDs are told apart by the type IANA (Internet Assigned Numbers Authority) gives each TLD in its root zone database.

Each column’s shares are of that column’s domains that presented a certificate: 212,328,093 in all, 144,095,797 under generic TLDs and 68,232,296 under country-code TLDs.

Whose name was on the certificateAll domainsShareGeneric TLDsCountry-code TLDs
The domain’s own name, accepted189,259,12889.1%89.1%89.2%
The domain’s own name, rejected for another fault4,107,8491.9%1.8%2.2%
The owner’s name in the wrong form539,2740.3%0.2%0.4%
No name at all1,061,4320.5%0.6%0.3%
Someone else’s name17,360,4108.2%8.3%8.0%

To rank the names, each certificate is grouped by the registered part of the name it presents, so *.example-host.net and server123.example-host.net count as one name, example-host.net. A name is printed on this page only if at least 100 domains were handed it, and each one printed is labelled with the company or software that runs it, from the name itself, the organisations on the certificate, the web server’s own header and the DNS host of the domains that received it. No customer domain is named.

What the scanner reported

Horizontal bars for the domains handed someone else's name, by the error Node.js reported: wrong name 62.8%, expired 22.2%, self-signed 10.6%, issuer could not be verified 4.1%, private root in the chain 0.3%.

Figure 2. The certificate error Node.js reported for the domains handed someone else’s name. Only the blue row is a name error.

62.8% of these domains were reported with the wrong-name error, ERR_TLS_CERT_ALTNAME_INVALID. The others reached Node with another fault first: 22.2% had an expired certificate, 10.6% a self-signed one, 4.1% one whose issuer Node couldn’t verify, and 0.3% one that chained to a private root. Counting self-signed certificates whatever error came first, the certificate signed itself on 2,887,813 of these domains, 16.6%.

The error string also picks up domains outside the group. It flagged 11,396,725 domains, 5.4% of the base. Of those, 479,141, 4.2%, carried their owner’s own name in the wrong form, most often www. plus the domain or a wildcard below it, and 23,050 carried no name at all. Counted by the names on the certificate, someone else’s name reached 17,360,410 domains.

The names handed out most

Ranked bars for the 25 names most often presented to domains they don't belong to, led by Shopify storefront (.myshopify.com) with 1,029,215 domains, All-Inkl.com (.kasserver.com) with 430,120 and Namecheap hosting (*.web-hosting.com) with 363,798. A marker beside each name shows whether it belongs to a hosting company, a site builder, server software or a parking service.

Figure 3. The 25 names most often presented to domains they don’t belong to, marked by the kind of operator behind each.

Each row is a group of certificates whose names share a registered part, shown by the commonest name in the group.

#Name on the certificateRun byDomainsShareNode reported, most often
1*.myshopify.comShopify, served from Cloudflare1,029,2155.9%expired
2*.kasserver.comAll-Inkl.com430,1202.5%wrong name
3*.web-hosting.comNamecheap363,7982.1%wrong name
4*.squarespace.comSquarespace342,1482.0%wrong name
5*.dadapro.comRegister.it (Dada group)325,1041.9%issuer not verified
6localhostServer software default281,2761.6%self-signed
7PleskPlesk control panel267,0111.5%expired
8*.one.comone.com237,9511.4%wrong name
9sni.dreamhost.comDreamHost237,8721.4%self-signed
10*.hostgator.comHostGator217,4201.3%wrong name

Shares are of the 17,360,410 domains handed someone else’s name. Together the 25 names in Figure 3 reach 5,640,175 domains, 32.5% of them. Of those, hosting companies’ own names account for 56.4%, site builders for 26.1%, placeholders made by server software for 15.5% and REG.RU’s parking service for 2.0%.

A shared hosting server answers for many domains at one address. When a browser asks it for a name it holds no certificate for, it presents one it does hold. For the hosting companies in the top 25, that is most often a wildcard for the company’s own domain. All-Inkl.com’s *.kasserver.com reached 430,120 domains under 441 TLDs, and Namecheap’s *.web-hosting.com 363,798. Site builders hand their own certificate to a customer domain that points at the platform without a certificate of its own there: Shopify’s *.myshopify.com placeholder, Squarespace’s *.squarespace.com and Turbify’s *.turbifysites.com all appear in the top 25.

The self-signed placeholders are made by the software itself. Plesk’s carries the organisation name Plesk, and Node found it expired on 91.4% of the domains that were handed it. Traefik, a reverse proxy, generates one called TRAEFIK DEFAULT CERT and presents it when no certificate it holds matches the name asked for. The commonest organisations on the self-signed certificates in the group are Plesk (252,070 domains), DreamHost’s company name (237,860), and placeholder text nobody replaced: SomeOrganization (164,542), MyCompany Inc. (157,954) and Internet Widgits Pty Ltd (55,885), the default organisation in OpenSSL’s sample configuration. 883,572 carry no organisation at all. These counts group by the organisation field, so they differ a little from the ranking by name.

Several of the largest names almost never appear as a name error, on fewer than one in 10,000 of their domains. Shopify’s placeholder was reported as expired, REG.RU’s parking certificate as unverifiable, DreamHost’s and domainfactory’s as self-signed, and Register.it’s *.dadapro.com as unverifiable or expired. A count by error string leaves those domains out.

Who signed them

Let’s Encrypt signed the certificate on 5,006,378 of the domains handed someone else’s name, 28.8%. Sectigo signed it on 3,550,318, 20.5%, and DigiCert on 1,832,851, 10.6%. The certificate signed itself on 2,887,813, 16.6%. Cloudflare signed it on 1,034,091, almost all of them handed Shopify’s expired placeholder. A certificate authority checks that the applicant controls the names on a certificate. It has no say in which domains a server later presents that certificate for.

Shared names and one-off names

Bars splitting the domains handed someone else's name by how many domains received the same name: one domain only 3.3%, 2 to 9 domains 5.7%, 10 to 99 7.8%, 100 to 999 8.8%, 1,000 to 9,999 14.9%, 10,000 or more 59.6%.

Figure 4. How many domains were handed the same name. Names handed to 10,000 or more domains each make up most of the total.

The names are concentrated. 199 names, each handed to 10,000 or more domains, account for 10,343,042 domains, 59.6% of the total. 6,798 names reached at least 100 domains each, and between them they cover 83.3%.

At the other end, 568,450 domains were handed a name that no other domain in the census received. Almost all of those names, 97.8%, are ordinary domain names, so none is printed here. 64,389 of them, 11.3%, carry the domain’s own first word under a different ending, which is the pattern of an owner’s second domain, though a shared word can be chance. For the rest, one handshake can’t tell another site at the same address from a server set up for one name and reached through another, or from the address’s previous user. Where the address now belongs to someone else, the certificate warning covers only HTTPS (Hypertext Transfer Protocol Secure). A plain HTTP (Hypertext Transfer Protocol) visit to the domain reaches the same server.

By top-level domain

Bars for the 20 largest TLDs showing the share of each one's domains that presented someone else's name, from 2.2% in .in to 15.2% in .ru, with a marker at 8.2% for all TLDs.

Figure 5. The share of each large TLD’s domains that presented someone else’s name. The dashed line is the figure for all TLDs.

Among the 20 largest TLDs by domains that presented a certificate, the share runs from 2.2% in .in to 15.2% in .ru. In .com, with 99,672,803 domains in the base, it is 7.9%.

What the census can’t see

Check your own

The certificate check in the free scan compares the certificate’s names with your domain on its own, separately from the trust check, and reports a certificate that doesn’t match along with the common name it found. If the name it reports is your hosting company’s, your domain reached a server that had no certificate set up for it. The wrong-hostname section of the certificate warning guide has the openssl command that lists the names a server presents.

Figures as of 5 September 2026, from the September 2026 edition of the defaults.exposed census. The Node.js and Traefik documentation was read on 4 October 2026. Census numbers move every month; the current values are on the data page.