DNS RobotDNS Propagation Checker
HomeDNS LookupWHOIS LookupIP LookupSSL Check
DNS RobotDNS Propagation Checker

Next-generation DNS propagation toolkit

Privacy PolicyTerms of ServiceAbout UsBlogContact

DNS Tools

DNS LookupDNS Speed TestDomain to IPNS LookupMX LookupView all

Email Tools

Email CheckerSPF Record CheckerDMARC CheckerDKIM CheckerSMTP Test ToolView all

Website Tools

Website Down CheckerWHOIS LookupHosting CheckerDomain AvailabilitySubdomain FinderView all

Network Tools

Ping ToolTraceroutePort CheckerHTTP Headers CheckSSL Certificate CheckView all

IP Tools

IP LookupWhat Is My IPRouter LoginIP Blacklist CheckIP to HostnameView all

Utility Tools

QR Code ScannerQR Code GeneratorUPI QR Code GeneratorWiFi QR Code GeneratorMorse Code TranslatorView all
© 2026 DNS Robot. Developed by ❤ Shaik Brothers
All systems operational
Made with
  1. Home
  2. /
  3. Security Tools
  4. /
  5. CSR Decoder

CSR Decoder and SSL Certificate Decoder

Paste a CSR or SSL certificate to see exactly what's inside: subject, Subject Alternative Names, key type and size, validity, issuer and fingerprint. Verify the CSR's signature and check that a certificate matches its CSR, all in your browser.

CSR DecoderCertificate DecoderSAN & Key CheckCSR ↔ Cert Match
Decode a CSR or certificate

Paste a PEM CSR (-----BEGIN CERTIFICATE REQUEST-----) or certificate (-----BEGIN CERTIFICATE-----). Paste a whole chain, or a CSR together with its certificate, to check them all at once.

Decoding happens in your browser. Nothing you paste is sent to our server.

Advertisement

What Is a CSR?

A certificate signing request (CSR) is the file you send to a certificate authority (CA) to get an SSL/TLS certificate. You create it on your server together with a private key. The CSR contains the matching public key, the identity you want certified (the subject: common name, organization, location) and the domain names in the Subject Alternative Names (SANs), and it is signed with the private key to prove you hold it.

The private key never leaves your server and should never be pasted anywhere. The CSR itself holds only public information, so it is safe to decode. This CSR decoder reads it directly in your browser.

CSR decoder showing the subject fields, Subject Alternative Names, RSA 2048-bit key and a valid signature
Decoding a CSR shows every field the CA will see, and checks the CSR's own signature.

How to Decode a CSR

1
Paste the CSR

Copy the whole block, including -----BEGIN CERTIFICATE REQUEST----- and -----END CERTIFICATE REQUEST-----, into the box above.

2
Check the subject and SANs

Make sure every domain you need, usually both example.com and www.example.com, appears in the Subject Alternative Names, and that the organization details are right.

3
Check the key and signature

The key should be RSA 2048-bit or larger, or ECDSA P-256 or P-384, and the signature should be valid. An invalid signature means the CSR was altered or damaged.

4
Submit it to your CA

If everything is correct, paste the CSR into your certificate authority's order form.

Advertisement

What to Check Before You Submit a CSR

A mistake in the CSR means reissuing the certificate. Check these first:

  • All domain names are in the SANs. Browsers have ignored the common name since Chrome 58 (2017), so names that aren't SANs won't be trusted. Many CAs add the CN automatically, but check.

  • The key is strong enough. CAs reject RSA keys under 2048 bits. RSA 2048–4096 and ECDSA P-256/P-384 are standard choices.

  • The signature uses SHA-256 or stronger. SHA-1 signatures are no longer accepted.

  • Organization details match your records for OV and EV certificates, which the CA verifies. Leave the organizational unit (OU) out: CAs stopped including it in public TLS certificates in 2022.

  • It's a fresh key. Generating a new private key and CSR for each renewal limits the damage if an old key ever leaks.

How to Decode an SSL Certificate

The same tool works as a certificate decoder. Paste a certificate (-----BEGIN CERTIFICATE-----) or a whole chain and each one is decoded: whether it's valid and how many days remain, the subject and issuer, the SANs, the key, key usage, serial number and SHA-256 fingerprint. CA certificates and self-signed certificates are labelled.

To check the certificate a live website actually serves, including its chain and expiry, use the SSL checker. To see whether a site is reachable at all, try the website down checker.

Advertisement

Does My Certificate Match My CSR?

A certificate only works with the private key its CSR was made from. Installing a certificate with the wrong key is a common cause of server errors after a renewal. Paste the CSR and the certificate together in the box above and the decoder compares their public keys: if they match, the certificate was issued for that CSR's key.

On the server you can compare the certificate, the CSR and the private key with OpenSSL: all three commands below must print the same hash.

Compare certificate, CSR and private key (OpenSSL)
openssl x509 -in certificate.pem -noout -pubkey | openssl sha256 openssl req -in request.csr -noout -pubkey | openssl sha256 openssl pkey -in private.key -pubout | openssl sha256

Create and Inspect CSRs with OpenSSL

The commands most people need, for OpenSSL 1.1.1 or newer:

Generate a private key and CSR with SANs
openssl req -new -newkey rsa:2048 -nodes \ -keyout example.key -out example.csr \ -subj "/CN=www.example.com" \ -addext "subjectAltName=DNS:www.example.com,DNS:example.com"
Decode and verify a CSR
openssl req -in example.csr -noout -text -verify
Decode a certificate
openssl x509 -in certificate.pem -noout -text

Advertisement

CSR and Certificate Fields Explained

Common Name (CN)

The main domain, such as www.example.com. Kept for compatibility; browsers use the SANs.

Subject Alternative Names (SAN)

Every domain (and sometimes IP address) the certificate covers. Wildcards like *.example.com cover one level of subdomains.

Organization (O), Locality (L), State (ST), Country (C)

Who owns the domain. Verified by the CA for OV and EV certificates; ignored for DV certificates.

Public key

The key the certificate binds to your domain. Its private half stays on your server.

Validity

The dates a certificate is valid between. Since March 2026 public certificates can last at most 200 days, and the limit shrinks again in 2027 and 2029.

Fingerprint

A SHA-256 hash of the whole certificate, used to identify it exactly, for example when pinning or comparing certificates.

More SSL and Security Tools

Check the rest of your HTTPS setup:

SSL Checker

Check the certificate a live site serves and its chain.

Website Down Checker

See whether a site is up and its certificate is valid.

Base64 Decode & Encode

PEM files are Base64; decode or encode any file.

HTTP Headers

Check HSTS and other security headers a site sends.

CSR Decoder FAQ

A CSR decoder reads a certificate signing request and shows what it contains: the subject (common name, organization, location), the Subject Alternative Names, the public key type and size, and the signature algorithm. It lets you catch mistakes before you send the CSR to a certificate authority.

Advertisement