Whose name is on your certificate? 17,360,410 domains present someone else's
The September 2026 census completed a TLS (Transport Layer Security) handshake with 212,328,093 domains and kept the certificate each one presented. For 17,360,410 of them, 8.2%, that certificate was made out to someone else: it lists names, and none of them is the domain or a name under it. The share is 8.3% for generic TLDs (Top-Level Domains) and 8.0% for country-code TLDs.
The ten names handed out most often reach 3,731,915 of those domains, 21.5%, and all ten are defaults. Names under Shopify’s myshopify.com lead with 1,029,215, almost all of them the storefront placeholder *.myshopify.com. After them come the certificates that hosting companies such as All-Inkl.com, Namecheap and one.com fall back on when a server holds none for the name requested. Squarespace’s own certificate is there too, and so are the self-signed placeholders that server software makes for itself, Plesk’s among them. At the other end, 568,450 domains, 3.3%, were handed a name that no other domain in the census received.
Figure 1. Whose name was on the certificate each domain presented. Orange is someone else’s name.
A count of the scanner’s name errors would miss 6,465,876 of these domains, 37.2%. The census connects with Node.js, and Node compares a certificate’s names with the domain only after the certificate has passed its other checks. An expired or self-signed certificate is reported as expired or self-signed, and its names are never compared. Node reported all 1,029,213 domains handed Shopify’s placeholder as expired, for example. So this page compares the names on each certificate with the domain directly.
How the names were compared
The census scanner makes one TLS connection per domain, on port 443, to the first address the domain publishes, and it sends the domain’s own name in the handshake, so a server holding several sites knows which one is wanted. It keeps the certificate whatever the verdict. The names on a certificate are its subject common name and the DNS (Domain Name System) entries in its subject alternative name list, the SAN list.
Each certificate then lands in one of four groups:
- The certificate lists the domain itself, or a wildcard that covers it under the one-label rule. That is the domain’s own name, and these certificates are split by whether the scanner accepted them.
- No name matches, but a name under the domain is on the certificate:
www.plus the domain, a wildcard for names under it, or another such asmail.plus the domain. That is the owner’s name in the wrong form. A wildcard such as*.example.orgcoversshop.example.organd leaves outexample.orgitself, so a certificate like that is the owner’s and still misses the bare domain. - The certificate lists names, and none of them is the domain or a name under it. That is someone else’s name, the group this page is about.
- The certificate carries no common name and no DNS name in its SAN list.
The base is every domain, whatever its grade, where the handshake completed and a certificate was captured: 212,328,093 domains, 61.1% of the 347,691,016 the census scanned. A domain scanned twice counts once, with the later scan’s certificate. Generic and country-code TLDs are told apart by the type IANA (Internet Assigned Numbers Authority) gives each TLD in its root zone database.
Each column’s shares are of that column’s domains that presented a certificate: 212,328,093 in all, 144,095,797 under generic TLDs and 68,232,296 under country-code TLDs.
| Whose name was on the certificate | All domains | Share | Generic TLDs | Country-code TLDs |
|---|---|---|---|---|
| The domain’s own name, accepted | 189,259,128 | 89.1% | 89.1% | 89.2% |
| The domain’s own name, rejected for another fault | 4,107,849 | 1.9% | 1.8% | 2.2% |
| The owner’s name in the wrong form | 539,274 | 0.3% | 0.2% | 0.4% |
| No name at all | 1,061,432 | 0.5% | 0.6% | 0.3% |
| Someone else’s name | 17,360,410 | 8.2% | 8.3% | 8.0% |
To rank the names, each certificate is grouped by the registered part of the name it presents, so *.example-host.net and server123.example-host.net count as one name, example-host.net. A name is printed on this page only if at least 100 domains were handed it, and each one printed is labelled with the company or software that runs it, from the name itself, the organisations on the certificate, the web server’s own header and the DNS host of the domains that received it. No customer domain is named.
What the scanner reported
Figure 2. The certificate error Node.js reported for the domains handed someone else’s name. Only the blue row is a name error.
62.8% of these domains were reported with the wrong-name error, ERR_TLS_CERT_ALTNAME_INVALID. The others reached Node with another fault first: 22.2% had an expired certificate, 10.6% a self-signed one, 4.1% one whose issuer Node couldn’t verify, and 0.3% one that chained to a private root. Counting self-signed certificates whatever error came first, the certificate signed itself on 2,887,813 of these domains, 16.6%.
The error string also picks up domains outside the group. It flagged 11,396,725 domains, 5.4% of the base. Of those, 479,141, 4.2%, carried their owner’s own name in the wrong form, most often www. plus the domain or a wildcard below it, and 23,050 carried no name at all. Counted by the names on the certificate, someone else’s name reached 17,360,410 domains.
The names handed out most
Figure 3. The 25 names most often presented to domains they don’t belong to, marked by the kind of operator behind each.
Each row is a group of certificates whose names share a registered part, shown by the commonest name in the group.
| # | Name on the certificate | Run by | Domains | Share | Node reported, most often |
|---|---|---|---|---|---|
| 1 | *.myshopify.com | Shopify, served from Cloudflare | 1,029,215 | 5.9% | expired |
| 2 | *.kasserver.com | All-Inkl.com | 430,120 | 2.5% | wrong name |
| 3 | *.web-hosting.com | Namecheap | 363,798 | 2.1% | wrong name |
| 4 | *.squarespace.com | Squarespace | 342,148 | 2.0% | wrong name |
| 5 | *.dadapro.com | Register.it (Dada group) | 325,104 | 1.9% | issuer not verified |
| 6 | localhost | Server software default | 281,276 | 1.6% | self-signed |
| 7 | Plesk | Plesk control panel | 267,011 | 1.5% | expired |
| 8 | *.one.com | one.com | 237,951 | 1.4% | wrong name |
| 9 | sni.dreamhost.com | DreamHost | 237,872 | 1.4% | self-signed |
| 10 | *.hostgator.com | HostGator | 217,420 | 1.3% | wrong name |
Shares are of the 17,360,410 domains handed someone else’s name. Together the 25 names in Figure 3 reach 5,640,175 domains, 32.5% of them. Of those, hosting companies’ own names account for 56.4%, site builders for 26.1%, placeholders made by server software for 15.5% and REG.RU’s parking service for 2.0%.
A shared hosting server answers for many domains at one address. When a browser asks it for a name it holds no certificate for, it presents one it does hold. For the hosting companies in the top 25, that is most often a wildcard for the company’s own domain. All-Inkl.com’s *.kasserver.com reached 430,120 domains under 441 TLDs, and Namecheap’s *.web-hosting.com 363,798. Site builders hand their own certificate to a customer domain that points at the platform without a certificate of its own there: Shopify’s *.myshopify.com placeholder, Squarespace’s *.squarespace.com and Turbify’s *.turbifysites.com all appear in the top 25.
The self-signed placeholders are made by the software itself. Plesk’s carries the organisation name Plesk, and Node found it expired on 91.4% of the domains that were handed it. Traefik, a reverse proxy, generates one called TRAEFIK DEFAULT CERT and presents it when no certificate it holds matches the name asked for. The commonest organisations on the self-signed certificates in the group are Plesk (252,070 domains), DreamHost’s company name (237,860), and placeholder text nobody replaced: SomeOrganization (164,542), MyCompany Inc. (157,954) and Internet Widgits Pty Ltd (55,885), the default organisation in OpenSSL’s sample configuration. 883,572 carry no organisation at all. These counts group by the organisation field, so they differ a little from the ranking by name.
Several of the largest names almost never appear as a name error, on fewer than one in 10,000 of their domains. Shopify’s placeholder was reported as expired, REG.RU’s parking certificate as unverifiable, DreamHost’s and domainfactory’s as self-signed, and Register.it’s *.dadapro.com as unverifiable or expired. A count by error string leaves those domains out.
Who signed them
Let’s Encrypt signed the certificate on 5,006,378 of the domains handed someone else’s name, 28.8%. Sectigo signed it on 3,550,318, 20.5%, and DigiCert on 1,832,851, 10.6%. The certificate signed itself on 2,887,813, 16.6%. Cloudflare signed it on 1,034,091, almost all of them handed Shopify’s expired placeholder. A certificate authority checks that the applicant controls the names on a certificate. It has no say in which domains a server later presents that certificate for.
Shared names and one-off names
Figure 4. How many domains were handed the same name. Names handed to 10,000 or more domains each make up most of the total.
The names are concentrated. 199 names, each handed to 10,000 or more domains, account for 10,343,042 domains, 59.6% of the total. 6,798 names reached at least 100 domains each, and between them they cover 83.3%.
At the other end, 568,450 domains were handed a name that no other domain in the census received. Almost all of those names, 97.8%, are ordinary domain names, so none is printed here. 64,389 of them, 11.3%, carry the domain’s own first word under a different ending, which is the pattern of an owner’s second domain, though a shared word can be chance. For the rest, one handshake can’t tell another site at the same address from a server set up for one name and reached through another, or from the address’s previous user. Where the address now belongs to someone else, the certificate warning covers only HTTPS (Hypertext Transfer Protocol Secure). A plain HTTP (Hypertext Transfer Protocol) visit to the domain reaches the same server.
By top-level domain
Figure 5. The share of each large TLD’s domains that presented someone else’s name. The dashed line is the figure for all TLDs.
Among the 20 largest TLDs by domains that presented a certificate, the share runs from 2.2% in .in to 15.2% in .ru. In .com, with 99,672,803 domains in the base, it is 7.9%.
What the census can’t see
- The scanner connects to one address. A domain that publishes several can present a different certificate at each, and only the first was seen.
- One handshake can’t say why a name was served, or who owns it. The labels here name the company or software that runs a name, read from the certificate, the server’s header and the DNS host.
- Browsers check certificates in their own order and can show a different warning first. The error codes on this page are the ones Node.js reported.
- Some of these domains may not be meant to serve a website at all, such as a name kept for email that points at a shared server. The census can’t tell those apart from sites.
- The grouping takes the last two labels of a name, or three under endings such as
.co.uk, without the full public suffix list, so a few platforms that give each customer their own name under a shared ending are grouped as one.
Check your own
The certificate check in the free scan compares the certificate’s names with your domain on its own, separately from the trust check, and reports a certificate that doesn’t match along with the common name it found. If the name it reports is your hosting company’s, your domain reached a server that had no certificate set up for it. The wrong-hostname section of the certificate warning guide has the openssl command that lists the names a server presents.
Figures as of 5 September 2026, from the September 2026 edition of the defaults.exposed census. The Node.js and Traefik documentation was read on 4 October 2026. Census numbers move every month; the current values are on the data page.