Checking whether an SSL certificate was issued to a fake organization
When a domain's name suggests one thing but its certificate tells a different story, the result is often confusion that breeds risk. Mismatched identifiers are not rare in Australia, where small businesses, freelancers, and side projects sometimes secure certificates with placeholder details or borrowed credentials. Learning how to read what a certificate actually says helps separate trustworthy sites from those that have dressed up an empty storefront.
The good news is that modern browsers expose most of this information without special software, and a handful of free services fill in the gaps. A methodical look at the issuing authority, the registered organisation, and the certificate's chain of trust usually reveals whether the document was issued to a real business or simply to a string of words that means nothing.
Reading the certificate fields in your browser
Chrome, Edge, Safari, and Firefox all expose the same underlying certificate data, so the workflow is similar regardless of which one a user in Sydney or Perth opens. Click the padlock icon next to the URL, choose "Connection is secure," then open the certificate viewer. From there, the "Issued to" and "Issued by" panels reveal the Common Name, Organisation (O), and Organisational Unit (OU) fields that a Certificate Authority (CA) verified before signing.
For legitimate certificates, the Organisation field usually matches a registered business name, an educational body, or a government department. The Organisational Unit might say "IT Services" or "Marketing." For a fake or low-effort certificate, these fields are often blank, populated with terms like "Personal" or "N/A," or contain text that no real company would use. A practical habit is to copy the Organisation string into ABN Lookup; the absence of a matching record is a strong warning.
Inspecting certificate transparency logs
Every certificate issued by a publicly trusted CA after 2018 must appear in Certificate Transparency (CT) logs. Services such as crt.sh provide free access to those logs and let anyone search by domain. Typing a domain into the search box returns a list of every certificate ever issued for it, including the Organisation field at the time of issuance and the issuing CA.
CT logs preserve a historical record. A pattern of multiple short-lived certificates from different free providers points to a project with no stable organisational identity. A long-running business tends to renew with the same trusted CA. A practical example is this domain analysis overview, which shows how analysts treat certificate data when the underlying site is suspect.
Verifying the chain of trust
Even a certificate with a plausible Organisation field can be worthless if the CA itself is not trusted. DigiCert, Let's Encrypt, Sectigo, and GlobalSign are included by default in devices sold in Melbourne and Brisbane. Let's Encrypt is legitimate but typically contains only the domain name, not the Organisation field, because domain validation alone does not establish legal identity.
To verify the chain, click through to the "Certification Path" tab. The root certificate must be one the local trust store recognises. If it is unknown, self-signed, or linked to an obscure provider, the certificate offers encryption but no real accountability. The Australian Cyber Security Centre (ACSC) recommends rejecting certificates from CAs not on trusted root programs and treating unknown issuers as a reason to leave the site.
| Field | Legitimate expectation | Suspicious pattern |
|---|---|---|
| Organisation (O) | Matches a registered Australian business or recognised entity | Generic wording, "N/A," "Personal," or string of random characters |
| Organisational Unit (OU) | Real department such as "IT" or "Finance" | Blank, repeated, or containing filler like "Test" |
| Issuer | Trusted root CA included in browsers and OS trust stores | Unknown, self-signed, or recently created root |
| Validity period | One to two years for Extended Validation, ninety days for typical automation | Extremely short repeated cycles across different CAs |
| Subject Alternative Names | Few, related domains owned by the same entity | Long list of unrelated or look-alike domains |
Cross-referencing with Australian business records
Once the certificate has been examined, verify whether the claimed entity exists. The Australian Securities and Investments Commission (ASIC) maintains a free register of companies and business names, and the Australian Business Register allows ABN lookups across Australia. A certificate naming an Organisation absent from both registers is almost certainly issued to a non-existent or impersonated entity.
For .com.au, .net.au, .org.au, or .gov.au domains, the Australian Domain Authority (auDA) requires a real Australian presence. A .com.au certificate that names an Organisation without an auDA licence or a matching ABN fails two verification layers at once. Analysts in Adelaide or Hobart often rely on this combined check, because it converts a technical detail into a question official registries can answer.
Red flags and response steps
Signs that suggest a certificate was issued to a fake organization:
- Organisation field that reads "None," "Personal," "Individual," or a random string
- Organisational Unit field that is blank across multiple certificates
- Issuer is a free provider but the certificate still claims extended organisational validation
- Domain name references one country while the Organisation field references another
- No record of the named entity in ABN Lookup, ASIC registers, or auDA's published licence data
- Certificate history shows the Organisation field changing between renewals without a corresponding rebrand
When these signs appear, avoid entering any personal or financial information and report the URL through Scamwatch, the ACCC-run service that tracks fraudulent activity. A certificate claiming to belong to a local news outlet but resolving to a cPanel login or gaming pages is a strong indicator that the domain's home page deserves a careful second look.
Actions to take once a fake certificate is confirmed:
- Take screenshots of the certificate details, including the Organisation and Issuer fields
- Report the URL to Scamwatch, the ACCC service that logs scam activity across Australia
- Notify the impersonated organisation directly using contact details from their official website, not from the suspicious certificate
- If personal or financial information was entered, contact the relevant bank and consider a credit report check through Equifax, illion, or Experian
- For Australian businesses, log the incident and review whether the Notifiable Data Breaches scheme applies under the Privacy Act 1988
Two regulatory frameworks shape what happens next. The Notifiable Data Breaches scheme under the Privacy Act 1988 requires organisations with turnover above three million dollars, or those that trade in personal data, to notify affected individuals and the Office of the Australian Information Commissioner (OAIC) when a breach involving personal information occurs. A phishing site harvesting credentials with a fake certificate can trigger this obligation if the impersonated organisation loses control of its data.
The Australian Signals Directorate's Essential Eight strategy recommends treating unexpected certificate changes as an incident worth investigating, because attackers rely on look-alike certificates to support social engineering. The practical memory aid is short: a padlock icon is necessary but never sufficient. Real proof a certificate was issued to a genuine organisation sits one click away, in fields matching a real business and an issuer the browser recognises.