Definition · TLS & Certificates
What is Wildcard Certificate?
A wildcard certificate is a TLS certificate issued for a name like *.example.com, covering every first-level subdomain of the domain — www.example.com, api.example.com, mail.example.com — with a single certificate. The wildcard matches exactly one label: *.example.com does not cover example.com itself (which is usually added as a separate name on the same certificate) and does not cover deeper names like a.b.example.com.
Advantages
- One certificate and one renewal process for any number of subdomains
- New subdomains are covered immediately, with no new issuance
- Simpler management for platforms that create customer subdomains dynamically
Trade-offs
- Shared private key — every server presenting the wildcard holds the same key, so compromising one host lets an attacker impersonate every subdomain
- Wider blast radius — a leaked or mis-issued wildcard affects the whole namespace, not one hostname
- Validation requirements — CAs issue wildcards only via DNS-based domain validation; under ACME this means the DNS-01 challenge
Domain owners can forbid wildcard issuance entirely with the issuewild tag of a CAA record.
Wildcards and attack surface visibility
Wildcard certificates appear in Certificate Transparency logs as a single *.example.com entry, hiding individual hostnames — which helps privacy but also means defenders cannot rely on CT logs alone for subdomain discovery of their own estate.