WHYUNTRUSTED

Security

What we check

WhyUntrusted retrieves the certificate presented by a public server on TCP port 443 and applies deterministic checks. Windows explanations match known error codes. Neither feature is a comprehensive security assessment.

Network protections

Targets are resolved and validated before connection. Private, loopback, reserved and other non-public addresses are blocked. The connection uses the validated address to reduce DNS rebinding risk. The scanner does not fetch certificate AIA, CRL or OCSP URLs.

Bounded operation

Checks have timeouts and concurrency limits. Domain requests have per-client and global limits. Request bodies are capped at 64 KiB. Submitted content is rendered as text; displayed diagnostic commands are not executed by the service.

Trust limitations

Retrieving a certificate is different from verifying operating-system trust. The scanner does not claim trusted status unless supported by an actual check. Certificate revocation, your local Windows trust store and enterprise policy may require investigation on your device.

Responsible reporting

The planned reporting address is security@whyuntrusted.com and is not active yet. Until verified, this release must not advertise a working reporting channel. Do not send private keys, passwords or customer data. No bug-bounty reward or legal safe-harbor program has been established.