Certificate tools

Security-minded utilities for certificate and brand workflows

Explore the specialised helpers that sit alongside DNS diagnostics: certificate parsers, BIMI validation helpers, and upcoming automation around trust chains.

CSR parser

Decode certificate signing requests, extract subject attributes and fingerprints before you sign.

VMC inspector

Audit a Verified Mark Certificate to confirm issuer, validity window, and certified domains before publishing BIMI records.

Why focus on certificate workflows

Inspect CSR payloads before signing

Uploading a CSR to your CA without double-checking its attributes often leads to rejected certificates. The CSR parser reveals the subject data, SAN entries, and fingerprints before submission so that the change ticket can be validated in one pass.

Validate BIMI certificates in minutes

Brand Indicators for Message Identification rely on Verified Mark Certificates. The inspector confirms that the PEM or hosted certificate matches your legal entity, that the SAN entries list the correct domains, and that the chain is still valid.

What comes next

Additional helpers will join this space soon: automated CSR linting, trust-store comparisons, and diff tools to check renewals. Each utility keeps the processing within the CaptainDNS perimeter to preserve confidentiality by default.