Definition · TLS & Certificates

What is Wildcard Certificate?

A wildcard certificate is a TLS certificate issued for a name like *.example.com, covering every first-level subdomain of the domain — www.example.com, api.example.com, mail.example.com — with a single certificate. The wildcard matches exactly one label: *.example.com does not cover example.com itself (which is usually added as a separate name on the same certificate) and does not cover deeper names like a.b.example.com.

Advantages

  • One certificate and one renewal process for any number of subdomains
  • New subdomains are covered immediately, with no new issuance
  • Simpler management for platforms that create customer subdomains dynamically

Trade-offs

  • Shared private key — every server presenting the wildcard holds the same key, so compromising one host lets an attacker impersonate every subdomain
  • Wider blast radius — a leaked or mis-issued wildcard affects the whole namespace, not one hostname
  • Validation requirements — CAs issue wildcards only via DNS-based domain validation; under ACME this means the DNS-01 challenge

Domain owners can forbid wildcard issuance entirely with the issuewild tag of a CAA record.

Wildcards and attack surface visibility

Wildcard certificates appear in Certificate Transparency logs as a single *.example.com entry, hiding individual hostnames — which helps privacy but also means defenders cannot rely on CT logs alone for subdomain discovery of their own estate.

See what your business is exposing

SurfaceLoop checks every internet-facing asset you own across seven risk categories, daily.